peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,074 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-2316 EXP Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows remote atta… Patch early 6.8 medium 4.3% 2012-09-09
CVE-2012-0873 EXP Multiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via t… Patch early 4.3 medium 4.3% 2012-02-23
CVE-2011-3850 EXP Cross-site scripting (XSS) vulnerability in the Atahualpa theme before 3.6.8 for WordPress allows remote attackers to inject arbitrary web script or H… Patch early 4.3 medium 4.3% 2011-09-28
CVE-2008-0616 EXP SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote authenticated administrators to e… Patch early 6.5 medium 4.3% 2008-02-06
CVE-2004-1442 EXP Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 4.3% 2004-12-31
CVE-2006-4425 EXP Multiple PHP remote file inclusion vulnerabilities in phpCOIN 1.2.3 allow remote attackers to execute arbitrary PHP code via the _CCFG[_PKG_PATH_INCL]… Patch early 5.1 medium 4.3% 2006-08-29
CVE-2005-0984 EXP Buffer overflow in the G_Printf function in Star Wars Jedi Knight: Jedi Academy 1.011 and earlier allows remote attackers to execute arbitrary code vi… Patch early 5.0 medium 4.3% 2005-05-02
CVE-2012-4000 EXP Cross-site scripting (XSS) vulnerability in the print_textinputs_var function in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellcheck… Patch early 4.3 medium 4.3% 2012-07-12
CVE-2013-4884 EXP Cross-site scripting (XSS) vulnerability in McAfee SuperScan 4.0 allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded sequ… Patch early 4.3 medium 4.3% 2014-01-21
CVE-2014-8577 EXP Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) d… Patch early 4.3 medium 4.3% 2014-10-31
CVE-2017-13865 EXP An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchO… Patch early 5.5 medium 4.2% 2017-12-25
CVE-2008-4133 EXP The web proxy service on the D-Link DIR-100 with firmware 1.12 and earlier does not properly filter web requests with large URLs, which allows remote… Patch early 4.3 medium 4.2% 2008-09-19
CVE-2004-0675 EXP Cross-site scripting (XSS) vulnerability in (1) cart32.exe or (2) c32web.exe in Cart32 shopping cart allows remote attackers to execute arbitrary web… Patch early 6.8 medium 4.2% 2004-08-06
CVE-2005-2095 EXP options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which allows remote attackers to mo… Patch early 4.3 medium 4.2% 2005-07-13
CVE-2012-2209 EXP Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Piwigo before 2.3.4 allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 4.2% 2012-08-14
CVE-2019-0796 EXP An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privil… Patch early 5.5 medium 4.2% 2019-04-09
CVE-2015-4066 EXP Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow remote authenticated users to exe… Patch early 6.5 medium 4.2% 2015-05-27
CVE-2017-9258 EXP The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (in… Patch early 5.5 medium 4.2% 2017-07-27
CVE-2008-7136 EXP toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the (1) Reque… Patch early 4.3 medium 4.2% 2009-09-01
CVE-2006-3421 EXP PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrar… Patch early 5.1 medium 4.2% 2006-07-07
CVE-2008-1042 EXP Directory traversal vulnerability in include/body.inc.php in Linux Web Shop (LWS) php Download Manager 1.0 and 1.1 allows remote attackers to include… Patch early 6.8 medium 4.2% 2008-02-27
CVE-2017-8678 EXP The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT… Patch early 5.5 medium 4.2% 2017-09-13
CVE-2017-8680 EXP The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows… Patch early 5.5 medium 4.2% 2017-09-13
CVE-2017-8681 EXP The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT… Patch early 5.5 medium 4.2% 2017-09-13
CVE-2017-8687 EXP The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT… Patch early 5.5 medium 4.2% 2017-09-13
CVE-2005-1593 EXP Cross-site scripting (XSS) vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to inject arbitrary web script or HTML… Patch early 6.8 medium 4.2% 2005-05-16
CVE-2008-4049 EXP A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to execute arbitra… Patch early 6.8 medium 4.2% 2008-09-11
CVE-2008-6918 EXP Unrestricted file upload vulnerability in admin/galeria.php in ThePortal2 2.2 allows remote attackers to execute arbitrary PHP code by uploading a fil… Patch early 6.8 medium 4.2% 2009-08-10
CVE-2006-2398 EXP Directory traversal vulnerability in index.php in GPhotos 1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the re… Patch early 5.0 medium 4.2% 2006-05-16
CVE-2013-3515 EXP Multiple cross-site scripting (XSS) vulnerabilities in OpenX Source 2.8.10 and earlier allow remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 4.2% 2013-07-29
← previous page 127 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt