peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,098 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-8690 EXP Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, and 2.3.x before 2.3.1 patch 4 a… Patch early 4.3 medium 4% 2015-02-19
CVE-2012-2511 EXP The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote… Patch early 5.0 medium 4% 2012-05-15
CVE-2009-1512 EXP Static code injection vulnerability in X-Forum 0.6.2 allows remote authenticated administrators to inject arbitrary PHP code into Config.php via the a… Patch early 6.5 medium 4% 2009-05-01
CVE-2008-3280 EXP It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Random Number… Patch early 5.9 medium 4% 2021-05-21
CVE-2016-1915 EXP Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to inje… Patch early 6.1 medium 4% 2017-04-13
CVE-2004-2033 EXP Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request. Patch early 5.0 medium 4% 2004-05-26
CVE-2008-6942 EXP Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows remote authenticated users to ex… Patch early 6.5 medium 3.9% 2009-08-12
CVE-2008-6943 EXP Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading… Patch early 6.5 medium 3.9% 2009-08-12
CVE-2021-31674 EXP Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code v… Patch early 6.1 medium 3.9% 2022-05-02
CVE-2008-0123 EXP Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject… Patch early 4.3 medium 3.9% 2008-01-12
CVE-2008-3233 EXP Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 3.9% 2008-07-18
CVE-2002-1845 EXP Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary w… Patch early 4.3 medium 3.9% 2002-12-31
CVE-2004-0660 EXP Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in CuteNews 1.3.1 allows remote att… Patch early 6.8 medium 3.9% 2004-08-06
CVE-2007-0183 EXP Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the N… Patch early 6.8 medium 3.9% 2007-01-12
CVE-2013-4900 EXP Directory traversal vulnerability in DeWeS web server 0.4.2 and possibly earlier, as used in Twilight CMS, allows remote attackers to read arbitrary f… Patch early 5.0 medium 3.9% 2013-09-09
CVE-2009-2704 EXP CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing a %00 (encoded n… Patch early 4.3 medium 3.9% 2009-08-11
CVE-2003-1266 EXP The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of ser… Patch early 5.0 medium 3.9% 2003-12-31
CVE-2002-1455 EXP Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2)… Patch early 4.3 medium 3.9% 2003-06-09
CVE-2006-5412 EXP admin.php in PHP Outburst Easynews 4.4.1 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication, and gain the… Patch early 5.1 medium 3.9% 2006-10-20
CVE-2003-0614 EXP Cross-site scripting (XSS) vulnerability in search.php of Gallery 1.1 through 1.3.4 allows remote attackers to insert arbitrary web script via the sea… Patch early 4.3 medium 3.9% 2003-08-27
CVE-2009-1827 EXP The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Rad… Patch early 5.0 medium 3.9% 2009-05-29
CVE-2012-4891 EXP Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 3.9% 2012-09-10
CVE-2018-11242 EXP An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that migh… Patch early 6.5 medium 3.9% 2018-05-20
CVE-2018-7703 EXP Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 6.1 medium 3.9% 2018-03-15
CVE-2017-13849 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issu… Patch early 5.5 medium 3.9% 2017-11-13
CVE-2009-5098 EXP The LunaSysMgr process in Palm Pre WebOS 1.1 and earlier, when not viewing web pages in landscape mode, allows remote attackers to cause a denial of s… Patch early 5.4 medium 3.9% 2011-09-13
CVE-2015-2248 EXP Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-… Patch early 6.8 medium 3.9% 2015-05-01
CVE-2015-1479 EXP SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authentic… Patch early 6.5 medium 3.9% 2015-02-04
CVE-2010-2370 EXP Unspecified vulnerability in the Oracle Business Process Management component in Oracle Fusion Middleware 5.7 MP3, 6.0 MP5, and 10.3 MP2 allows remote… Patch early 4.3 medium 3.9% 2010-07-13
CVE-2008-3723 EXP Directory traversal vulnerability in index.php in PHPizabi 0.848b C1 HFP3 allows remote authenticated administrators to read arbitrary files via (1) a… Patch early 6.3 medium 3.9% 2008-08-20
← previous page 135 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt