peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,069 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-1826 EXP A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of t… Patch early 6.3 medium 4.4% 2023-04-04
CVE-2018-17784 EXP Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to condu… Patch early 6.1 medium 4.4% 2018-10-10
CVE-2006-7147 EXP PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier allows remote attackers to exec… Patch early 6.8 medium 4.4% 2007-03-07
CVE-2005-3995 EXP Format string vulnerability in the dosyslog function in the OBEX server (obexsrv.c) for Sobexsrv before 1.0.0-pre4, when the syslog (-S) function is e… Patch early 5.1 medium 4.4% 2005-12-05
CVE-2007-0883 EXP Directory traversal vulnerability in portalgroups/portalgroups/getfile.cgi in IP3 NetAccess before firmware 4.1.9.6 allows remote attackers to read ar… Patch early 5.0 medium 4.3% 2007-02-12
CVE-2007-5464 EXP Stack-based buffer overflow in Live for Speed 0.5X10 and earlier allows remote authenticated users to cause a denial of service (client crash) and pos… Patch early 6.5 medium 4.3% 2007-10-15
CVE-2006-3036 EXP Multiple cross-site scripting (XSS) vulnerabilities in 35mmslidegallery 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 5.8 medium 4.3% 2006-06-15
CVE-2009-0496 EXP Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 4.3% 2009-02-10
CVE-2005-4402 EXP Buffer overflow in MailEnable Professional 1.71 and earlier, and Enterprise 1.1 and earlier, allows remote authenticated users to execute arbitrary co… Patch early 6.5 medium 4.3% 2005-12-20
CVE-2008-4795 EXP The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which allows remote attackers to inje… Patch early 4.3 medium 4.3% 2008-10-30
CVE-2007-5111 EXP A certain ActiveX control in EBCRYPT.DLL 2.0 in EB Design ebCrypt allows remote attackers to cause a denial of service (crash) via a string argument t… Patch early 4.3 medium 4.3% 2007-09-26
CVE-2015-8724 EXP The AirPDcapDecryptWPABroadcastKey function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1… Patch early 5.5 medium 4.3% 2016-01-04
CVE-2015-8731 EXP The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 doe… Patch early 5.5 medium 4.3% 2016-01-04
CVE-2006-7026 EXP PHP remote file inclusion vulnerability in sources/join.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows remot… Patch early 6.8 medium 4.3% 2007-02-23
CVE-2017-16884 EXP Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web script or HTML via vectors related… Patch early 6.1 medium 4.3% 2017-12-07
CVE-2016-5348 EXP The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows man-in-… Patch early 5.9 medium 4.3% 2016-10-10
CVE-2001-1097 EXP Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets. Patch early 5.0 medium 4.3% 2001-07-24
CVE-2012-6290 EXP SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL commands via the q parameter to… Patch early 6.5 medium 4.3% 2014-03-11
CVE-2013-1408 EXP Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execut… Patch early 6.5 medium 4.3% 2014-03-24
CVE-2017-2480 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affect… Patch early 6.5 medium 4.3% 2017-04-02
CVE-2019-2861 EXP Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported version that is affected is 11.1.2.… Patch early 4.2 medium 4.3% 2019-07-23
CVE-2002-1434 EXP Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML script as ot… Patch early 6.8 medium 4.3% 2003-04-11
CVE-2006-2955 EXP Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice 7.5 and earlier allow remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 4.3% 2006-06-12
CVE-2007-0827 EXP The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that invokes the R… Patch early 6.8 medium 4.3% 2007-02-07
CVE-2004-0725 EXP Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbitrary web script or HTML via th… Patch early 6.8 medium 4.3% 2004-07-27
CVE-2010-2544 EXP Cross-site scripting (XSS) vulnerability in utilities.php in Cacti before 0.8.7g, as used in Red Hat High Performance Computing (HPC) Solution and oth… Patch early 4.3 medium 4.3% 2010-08-23
CVE-2013-2637 EXP A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorde… Patch early 6.1 medium 4.3% 2020-02-12
CVE-2009-1938 EXP Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecifie… Patch early 4.3 medium 4.3% 2009-06-05
CVE-2006-6719 EXP The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause a denial of service (applicati… Patch early 5.0 medium 4.3% 2006-12-23
CVE-2006-2122 EXP PHP remote file inclusion vulnerability in index.php in CoolMenus allows remote attackers to execute arbitrary code via a URL in the page parameter.… Patch early 6.8 medium 4.3% 2006-05-01
← previous page 125 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt