peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,075 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-8733 EXP The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does… Patch early 5.5 medium 4.2% 2016-01-04
CVE-2007-3364 EXP Cross-site scripting (XSS) vulnerability in the cgi-bin/post.mscgi sample page in MyServer 0.8.9 allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 4.2% 2007-06-22
CVE-2005-0647 EXP admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove] parameters… Patch early 5.0 medium 4.2% 2005-05-02
CVE-2004-1940 EXP sipclient.cpp in KPhone 4.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a STUN response packet with a large attrLen… Patch early 5.0 medium 4.1% 2004-12-31
CVE-2009-1483 EXP Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable from index2.php, allows remot… Patch early 6.8 medium 4.1% 2009-04-29
CVE-2016-7216 EXP The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandles permissions, which allows local users… Patch early 5.5 medium 4.1% 2016-11-10
CVE-2007-6307 EXP Multiple cross-site scripting (XSS) vulnerabilities in clickstats.php in wwwstats 3.21 allow remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 4.1% 2007-12-11
CVE-2011-4449 EXP actions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically abse… Patch early 6.8 medium 4.1% 2012-09-05
CVE-2006-4610 EXP PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, allows remote attackers to exec… Patch early 5.1 medium 4.1% 2006-09-07
CVE-2006-5240 EXP PHP remote file inclusion vulnerability in engine/require.php in Docmint 2.0 and earlier, when register_globals is enabled, allows remote attackers to… Patch early 5.1 medium 4.1% 2006-10-12
CVE-2006-2285 EXP PHP remote file inclusion vulnerability in authldap.php in Dokeos 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the include… Patch early 5.1 medium 4.1% 2006-05-10
CVE-2014-3081 EXP prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbit… Patch early 6.3 medium 4.1% 2014-08-17
CVE-2007-6218 EXP Multiple PHP remote file inclusion vulnerabilities in Ossigeno CMS 2.2 pre1 allow remote attackers to execute arbitrary PHP code via a URL in the (1)… Patch early 5.0 medium 4.1% 2007-12-04
CVE-2023-36163 EXP Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the m… Patch early 6.1 medium 4.1% 2023-07-11
CVE-2009-4587 EXP Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as demonstrated by… Patch early 5.0 medium 4.1% 2010-01-07
CVE-2017-7064 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 5.5 medium 4.1% 2017-07-20
CVE-2016-5304 EXP Open redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticat… Patch early 6.8 medium 4.1% 2016-06-30
CVE-2005-3770 EXP Multiple cross-site scripting (XSS) vulnerabilities in PHP-Post (PHPp) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the s… Patch early 4.3 medium 4.1% 2005-11-23
CVE-2015-7984 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition b… Patch early 6.8 medium 4.1% 2015-11-19
CVE-2015-8729 EXP The ascend_seek function in wiretap/ascendtext.c in the Ascend file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not ensure th… Patch early 5.5 medium 4.1% 2016-01-04
CVE-2002-2011 EXP Cross-site scripting (XSS) vulnerability in the fom CGI program (fom.cgi) in Faq-O-Matic 2.711 and 2.712 allows remote attackers to inject arbitrary w… Patch early 4.3 medium 4.1% 2002-12-31
CVE-2007-6545 EXP Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) the s… Patch early 4.3 medium 4.1% 2007-12-28
CVE-2025-52367 EXP Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the subtitle field. Patch early 5.4 medium 4.1% 2025-09-22
CVE-2016-7224 EXP Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Serve… Patch early 6.1 medium 4.1% 2016-11-10
CVE-2016-7225 EXP Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local use… Patch early 6.1 medium 4.1% 2016-11-10
CVE-2016-7226 EXP Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local use… Patch early 6.1 medium 4.1% 2016-11-10
CVE-2006-5202 EXP Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary confi… Patch early 5.0 medium 4.1% 2006-10-10
CVE-2007-3593 EXP Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 4.1% 2007-07-06
CVE-2010-1724 EXP Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to inject arbi… Patch early 4.3 medium 4.1% 2010-05-06
CVE-2008-3700 EXP Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and earlier allow remote attackers to inject arbitrary web script o… Patch early 4.3 medium 4.1% 2008-08-15
← previous page 130 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt