peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,095 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-4316 EXP Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) set… Patch early 6.1 medium 4% 2017-02-17
CVE-2005-1053 EXP Multiple cross-site scripting (XSS) vulnerabilities in orderwiz.php in ModernBill 4.3.0 and earlier allow remote attackers to inject arbitrary web scr… Patch early 4.3 medium 4% 2005-05-02
CVE-2005-1486 EXP Multiple cross-site scripting vulnerabilities in FishCart 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) trackingnum, (… Patch early 5.0 medium 4% 2005-05-11
CVE-2014-3441 EXP codec\libpng_plugin.dll in VideoLAN VLC Media Player 2.1.3 allows remote attackers to cause a denial of service (crash) via a crafted .png file, as de… Patch early 4.3 medium 4% 2014-05-14
CVE-2019-7438 EXP cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter. Patch early 6.1 medium 4% 2019-03-21
CVE-2005-0928 EXP Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 5.x allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 4.3 medium 4% 2005-05-02
CVE-2007-2632 EXP Multiple cross-site scripting (XSS) vulnerabilities in PHP Multi User Randomizer (phpMUR) 2006.09.13 allow remote attackers to inject arbitrary web sc… Patch early 6.8 medium 4% 2007-05-13
CVE-2006-5186 EXP PHP remote file inclusion vulnerability in functions.php in phpMyProfiler 0.9.6 and earlier, when register_globals is enabled, allows remote attackers… Patch early 5.1 medium 4% 2006-10-10
CVE-2002-1663 EXP The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a POST reque… Patch early 5.0 medium 4% 2002-12-31
CVE-2018-16134 EXP Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI. Patch early 6.1 medium 4% 2018-08-29
CVE-2015-5520 EXP Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allows remote attackers to inject a… Patch early 4.3 medium 4% 2015-07-14
CVE-2012-1039 EXP Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 4.3 medium 4% 2012-03-19
CVE-2014-9143 EXP Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect users to arbitrary web sites and… Patch early 4.3 medium 4% 2014-12-05
CVE-2003-1317 EXP Cross-site scripting (XSS) vulnerability in mod.php in eNdonesia 8.2 allows remote attackers to inject arbitrary web script or HTML via the mod parame… Patch early 6.8 medium 4% 2003-12-31
CVE-2006-1921 EXP nettools.php in PHP Net Tools 2.7.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter. Patch early 6.4 medium 4% 2006-04-20
CVE-2005-1004 EXP Cross-site scripting (XSS) vulnerability in usrdetails.php in ProfitCode PayProCart 3.0 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 4% 2005-05-02
CVE-2017-9126 EXP The quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflo… Patch early 6.5 medium 4% 2017-06-12
CVE-2006-2740 EXP Multiple SQL injection vulnerabilities in Epicdesigns tinyBB 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) q parameter in (… Patch early 6.8 medium 4% 2006-06-01
CVE-2007-3189 EXP Cross-site scripting (XSS) vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to inject arbitr… Patch early 4.3 medium 4% 2007-06-12
CVE-2010-4875 EXP Cross-site scripting (XSS) vulnerability in vodpod-video-gallery/vodpod_gallery_thumbs.php in the Vodpod Video Gallery Plugin 3.1.5 for WordPress allo… Patch early 4.3 medium 4% 2011-10-07
CVE-2008-0193 EXP Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows remote attacker… Patch early 4.3 medium 4% 2008-01-10
CVE-2017-9412 EXP The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid memory read and… Patch early 5.5 medium 4% 2017-07-27
CVE-2003-0283 EXP Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message wit… Patch early 6.8 medium 4% 2003-06-16
CVE-2005-0543 EXP Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cf… Patch early 4.3 medium 4% 2005-02-24
CVE-2008-0851 EXP Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username… Patch early 4.3 medium 4% 2008-02-21
CVE-2005-1561 EXP Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 4% 2005-05-11
CVE-2023-34834 EXP A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attackers to gain sensitive informatio… Patch early 5.3 medium 4% 2023-06-29
CVE-2005-1752 EXP viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name… Patch early 6.4 medium 4% 2005-12-31
CVE-2013-2294 EXP Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbitrary web script or HTML via a… Patch early 6.1 medium 4% 2020-01-30
CVE-2008-6944 EXP Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file… Patch early 6.5 medium 4% 2009-08-12
← previous page 134 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt