peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,098 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-9301 EXP Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows remote attackers to trigger ou… Patch early 6.4 medium 3.9% 2014-12-07
CVE-2006-6810 EXP Unspecified vulnerability in the clear_user_list function in src/main.c in DB Hub 0.3 allows remote attackers to cause a denial of service (applicatio… Patch early 5.0 medium 3.9% 2006-12-29
CVE-2009-0441 EXP PHP remote file inclusion vulnerability in skin_shop/standard/2_view_body/body_default.php in TECHNOTE 7.2, when register_globals is enabled, allows r… Patch early 6.8 medium 3.9% 2009-02-10
CVE-2009-0527 EXP PHP remote file inclusion vulnerability in plugins/rss_importer_functions.php in AdaptCMS Lite 1.4 allows remote attackers to execute arbitrary PHP co… Patch early 6.8 medium 3.9% 2009-02-11
CVE-2008-5102 EXP PythonScripts in Zope 2 2.11.2 and earlier, as used in Conga and other products, allows remote authenticated users to cause a denial of service (resou… Patch early 4.0 medium 3.9% 2008-11-17
CVE-2003-0483 EXP Cross-site scripting (XSS) vulnerabilities in XMB Forum 1.8 Partagium allow remote attackers to insert arbitrary script via (1) the member parameter t… Patch early 6.8 medium 3.9% 2003-08-07
CVE-2014-3438 EXP Multiple cross-site scripting (XSS) vulnerabilities in console interface scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allow… Patch early 4.3 medium 3.9% 2014-11-07
CVE-2004-1797 EXP Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 3.9% 2004-12-31
CVE-2004-2510 EXP Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to inject arbitrary web script or H… Patch early 4.3 medium 3.9% 2004-12-31
CVE-2003-0278 EXP Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web scri… Patch early 6.8 medium 3.9% 2003-06-16
CVE-2017-6338 EXP Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user… Patch early 6.5 medium 3.9% 2017-04-05
CVE-2017-2510 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" co… Patch early 6.1 medium 3.9% 2017-05-22
CVE-2008-5821 EXP Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause a denial of service (memory co… Patch early 5.0 medium 3.9% 2009-01-02
CVE-2002-1526 EXP Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary HTML or script via the email a… Patch early 4.3 medium 3.9% 2003-04-02
CVE-2017-9260 EXP The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of servi… Patch early 5.5 medium 3.9% 2017-07-27
CVE-2017-10046 EXP Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Sup… Patch early 5.4 medium 3.9% 2017-08-08
CVE-2006-5609 EXP Directory traversal vulnerability in dir.php in TorrentFlux 2.1 allows remote attackers to list arbitrary directories via "\.\./" sequences in the dir… Patch early 5.0 medium 3.9% 2006-10-30
CVE-2006-6084 EXP Directory traversal vulnerability in abitwhizzy.php in aBitWhizzy allows remote attackers to read arbitrary files via a .. (dot dot) in the f paramete… Patch early 5.0 medium 3.9% 2006-11-24
CVE-2006-1431 EXP Cross-site scripting (XSS) vulnerability in local.cfm in fusionZONE couponZONE 4.2 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 3.9% 2006-03-28
CVE-2004-1985 EXP Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web sc… Patch early 4.3 medium 3.9% 2004-04-30
CVE-2013-1765 EXP Multiple cross-site scripting (XSS) vulnerabilities in jwplayer.swf in the smart-flv plugin for WordPress allow remote attackers to inject arbitrary w… Patch early 4.3 medium 3.9% 2014-05-14
CVE-2005-2242 EXP Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to cause a de… Patch early 5.0 medium 3.9% 2005-07-12
CVE-2002-1453 EXP Cross-site scripting (XSS) vulnerability in MyWebServer 1.0.2 allows remote attackers to insert script and HTML via a long request followed by the mal… Patch early 4.3 medium 3.9% 2002-08-14
CVE-2018-6225 EXP An XML external entity injection (XXE) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an authenticated user to expose a normall… Patch early 4.3 medium 3.9% 2018-03-15
CVE-2012-5451 EXP Multiple stack-based buffer overflows in HttpUtils.dll in TVMOBiLi before 2.1.0.3974 allow remote attackers to cause a denial of service (tvMobiliServ… Patch early 5.0 medium 3.9% 2015-04-24
CVE-2012-6430 EXP Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded before December 19, 2012, allows re… Patch early 4.3 medium 3.9% 2014-03-24
CVE-2008-6513 EXP Unrestricted file upload vulnerability in saa.php in Andy's PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to execute arbitrary code by upl… Patch early 6.8 medium 3.9% 2009-03-24
CVE-2015-2680 EXP Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack the authentication of administra… Patch early 6.8 medium 3.9% 2015-03-23
CVE-2009-4093 EXP Multiple cross-site scripting (XSS) vulnerabilities in comments.php in Simplog 0.9.3.2, and possibly earlier, allow remote attackers to inject arbitra… Patch early 4.3 medium 3.9% 2009-11-29
CVE-2006-0518 EXP Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to injec… Patch early 4.3 medium 3.9% 2006-02-02
← previous page 136 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt