peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,178 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-6628 EXP Integer overflow in OpenOffice.org (OOo) 2.1 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted DOC… Patch early 4.3 medium 3.6% 2006-12-18
CVE-2004-2297 EXP The Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large, out-of-range… Patch early 5.0 medium 3.6% 2004-12-31
CVE-2008-1979 EXP The Discovery Service (casdscvc) in CA ARCserve Backup 12.0.5454.0 and earlier allows remote attackers to cause a denial of service (crash) via a pack… Patch early 5.0 medium 3.6% 2008-04-27
CVE-2009-4729 EXP Multiple cross-site scripting (XSS) vulnerabilities in x10 Adult Media Script 1.7 allow remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 3.6% 2010-03-18
CVE-2006-1412 EXP TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin… Patch early 5.0 medium 3.6% 2006-03-28
CVE-2005-2952 EXP Directory traversal vulnerability in s.pl in Subscribe Me Pro 2.044.09P and earlier allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 5.0 medium 3.6% 2005-09-16
CVE-2005-3026 EXP Directory traversal vulnerability in index.php in Alstrasoft Epay Pro 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot do… Patch early 5.0 medium 3.6% 2005-09-21
CVE-2003-1511 EXP Cross-site scripting (XSS) vulnerability in Bajie Java HTTP Server 0.95 through 0.95zxv4 allows remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 3.6% 2003-12-31
CVE-2005-0782 EXP Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitr… Patch early 4.3 medium 3.6% 2005-05-02
CVE-2007-6316 EXP Cross-site scripting (XSS) vulnerability in BarracudaDrive Web Server before 3.8 allows remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 3.6% 2007-12-12
CVE-2006-1909 EXP Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read arbitrary files via a .//./ (modified dot dot slash… Patch early 5.0 medium 3.6% 2006-04-20
CVE-2023-2246 EXP A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code… Patch early 6.3 medium 3.6% 2023-04-23
CVE-2007-6604 EXP Multiple directory traversal vulnerabilities in index.php in XCMS 1.82 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) i… Patch early 5.0 medium 3.6% 2007-12-31
CVE-2008-3128 EXP Directory traversal vulnerability in search.php in Pivot 1.40.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the t parameter. Patch early 5.0 medium 3.6% 2008-07-10
CVE-2004-2127 EXP Directory traversal vulnerability in Web Blog 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file variable. Patch early 5.0 medium 3.6% 2004-01-20
CVE-2006-1333 EXP Multiple SQL injection vulnerabilities in BetaParticle Blog 6.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id pa… Patch early 6.4 medium 3.6% 2006-03-21
CVE-2004-2628 EXP Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a UR… Patch early 5.0 medium 3.6% 2004-12-31
CVE-2005-2648 EXP Directory traversal vulnerability in index.php in W-Agora 4.2.0 and earlier allows remote attackers to read arbitrary files via the site parameter. Patch early 5.0 medium 3.6% 2005-08-23
CVE-2004-1467 EXP Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.0.00.003 and earlier allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 3.6% 2004-12-31
CVE-2004-2171 EXP Cross-site scripting (XSS) vulnerability in Cherokee before 0.4.8 allows remote attackers to inject arbitrary web script or HTML via the URL, which is… Patch early 4.3 medium 3.6% 2004-12-31
CVE-2005-1188 EXP Cross-site scripting (XSS) vulnerability in comersus_searchItem.asp in Comersus 3.90 to 4.51 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 3.6% 2005-05-02
CVE-2009-1609 EXP Unrestricted file upload vulnerability in admin/uploadform.asp in Battle Blog 1.25 allows remote attackers to execute arbitrary code by uploading a fi… Patch early 6.8 medium 3.6% 2009-05-11
CVE-2011-4280 EXP Cross-site scripting (XSS) vulnerability in the Spike PHPCoverage (aka spikephpcoverage) library, as used in Moodle 2.0.x before 2.0.2 and other produ… Patch early 4.3 medium 3.6% 2012-07-16
CVE-2004-2646 EXP The addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (uncaught NullPointerException) via… Patch early 5.0 medium 3.6% 2004-12-31
CVE-2004-2647 EXP Free Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from the same user. Patch early 5.0 medium 3.6% 2004-12-31
CVE-2018-4090 EXP An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. wa… Patch early 5.5 medium 3.6% 2018-04-03
CVE-2004-0620 EXP Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote attackers to inject arbitrary HTML… Patch early 4.3 medium 3.6% 2004-12-06
CVE-2005-2010 EXP Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 3.6% 2005-06-20
CVE-2006-3528 EXP Multiple PHP remote file inclusion vulnerabilities in Simpleboard Mambo module 1.1.0 and earlier allow remote attackers to execute arbitrary PHP code… Patch early 6.8 medium 3.6% 2006-07-12
CVE-2006-3749 EXP PHP remote file inclusion vulnerability in sitemap.xml.php in Sitemap component (com_sitemap) 2.0.0 for Mambo 4.5.1 CMS, when register_globals is enab… Patch early 6.8 medium 3.6% 2006-07-21
← previous page 146 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt