peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,084 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-5225 EXP Multiple cross-site scripting (XSS) vulnerabilities in Xerox DocuShare 6 and earlier allow remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 4.1% 2008-11-25
CVE-2012-2614 EXP Buffer overflow in programmer.exe in Lattice Diamond Programmer 1.4.2 allows user-assisted remote attackers to cause a denial of service (application… Patch early 6.8 medium 4.1% 2012-07-12
CVE-2009-1467 EXP Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary… Patch early 4.3 medium 4.1% 2009-05-05
CVE-2012-2572 EXP Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote attackers to inject arbitrary w… Patch early 4.3 medium 4.1% 2014-06-19
CVE-2005-2460 EXP Multiple cross-site scripting (XSS) vulnerabilities in Kayako liveResponse 2.x allow remote attackers to inject arbitrary web script or HTML via the (… Patch early 5.8 medium 4.1% 2005-12-31
CVE-2005-4676 EXP Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function, which allows remote attackers t… Patch early 5.0 medium 4.1% 2005-12-31
CVE-2006-1590 EXP Cross-site scripting (XSS) vulnerability in the PrintFreshPage function in (1) Basic Analysis and Security Engine (BASE) 1.2.4 and (2) Analysis Consol… Patch early 4.3 medium 4.1% 2006-04-03
CVE-2007-1371 EXP Multiple buffer overflows in Conquest 8.2a and earlier (1) allow local users to gain privileges by querying a metaserver that sends a long server entr… Patch early 6.9 medium 4.1% 2007-03-10
CVE-2010-1466 EXP Directory traversal vulnerability in scr/soustab.php in openUrgence Vaccin 1.03 allows remote attackers to read arbitrary files via the dsn[phptype] p… Patch early 6.8 medium 4.1% 2010-04-16
CVE-2007-6646 EXP Multiple cross-site scripting (XSS) vulnerabilities in LiveCart 1.0.1, and possibly other versions before 1.1.0, allow remote attackers to inject arbi… Patch early 4.3 medium 4.1% 2008-01-04
CVE-2006-0659 EXP Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote attackers… Patch early 6.8 medium 4.1% 2006-02-13
CVE-2009-2133 EXP Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4 and 1.40.7 allow remote attackers to inject arbitrary web script or HTML via the (… Patch early 4.3 medium 4.1% 2009-06-19
CVE-2004-2720 EXP Cross-site scripting (XSS) vulnerability in register.asp in Snitz Forums 2000 3.4.04 and earlier allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 4.1% 2004-12-31
CVE-2004-2162 EXP Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the search fiel… Patch early 4.3 medium 4.1% 2004-12-31
CVE-2022-28598 EXP Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is plac… Patch early 6.1 medium 4.1% 2022-08-22
CVE-2013-5978 EXP Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allow remote attackers to… Patch early 6.1 medium 4.1% 2019-12-11
CVE-2007-3339 EXP Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow… Patch early 4.3 medium 4.1% 2007-06-21
CVE-2008-1751 EXP Multiple directory traversal vulnerabilities in index.php in Ksemail allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1… Patch early 6.8 medium 4.1% 2008-04-11
CVE-2008-7163 EXP Directory traversal vulnerability in mods/Integrated/index.php in SineCMS 2.3.5 and earlier, when register_globals is enabled, allows remote attackers… Patch early 6.8 medium 4.1% 2009-09-04
CVE-2007-2732 EXP Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML via the (1) path param… Patch early 6.8 medium 4.1% 2007-05-16
CVE-2011-4530 EXP Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 does not properly copy fields obtained from clients, which allows remote attackers t… Patch early 5.0 medium 4.1% 2012-01-08
CVE-2007-2668 EXP Buffer overflow in webdesproxy 0.0.1 allows remote attackers to execute arbitrary code via a long URL, possibly involving the process_connection_reque… Patch early 6.8 medium 4.1% 2007-05-14
CVE-2006-0103 EXP TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access con… Patch early 5.0 medium 4.1% 2006-01-06
CVE-2008-6061 EXP Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) controller files created by Techsmith Camtasia Studio befo… Patch early 4.3 medium 4.1% 2009-02-05
CVE-2015-1422 EXP Multiple cross-site scripting (XSS) vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 4.3 medium 4.1% 2015-01-29
CVE-2008-6018 EXP Directory traversal vulnerability in index.php in MyPHPSite, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a… Patch early 6.8 medium 4.1% 2009-02-02
CVE-2018-0746 EXP The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows… Patch early 4.7 medium 4.1% 2018-01-04
CVE-2012-1208 EXP Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allow r… Patch early 4.3 medium 4.1% 2012-02-24
CVE-2008-1885 EXP Directory traversal vulnerability in the NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download allows remote attac… Patch early 6.8 medium 4.1% 2008-04-18
CVE-2017-6339 EXP Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation,… Patch early 6.5 medium 4.1% 2017-04-05
← previous page 131 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt