peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,200 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-2242 EXP Cross-site scripting (XSS) vulnerability in search.php in Phorum, possibly 5.0.7 beta and earlier, allows remote attackers to inject arbitrary HTML or… Patch early 4.3 medium 3.6% 2004-12-31
CVE-2005-2649 EXP Cross-site scripting (XSS) vulnerability in ATutor 1.5.1 allows remote attackers to inject arbitrary web script or HTML via (1) course parameter in lo… Patch early 4.3 medium 3.6% 2005-08-23
CVE-2005-4167 EXP Cross-site scripting (XSS) vulnerability in eFiction 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the let parameter… Patch early 4.3 medium 3.6% 2005-12-11
CVE-2007-6037 EXP Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject arbitrary web… Patch early 4.3 medium 3.6% 2007-11-20
CVE-2004-1691 EXP The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of data. Patch early 5.0 medium 3.6% 2004-09-18
CVE-2007-4231 EXP PHP remote file inclusion vulnerability in order/login.php in IDevSpot PhpHostBot 1.06 and earlier allows remote attackers to execute arbitrary PHP co… Patch early 6.8 medium 3.6% 2007-08-08
CVE-2004-1688 EXP Pigeon Server 3.02.0143 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a long login name sen… Patch early 5.0 medium 3.6% 2004-09-16
CVE-2002-1829 EXP Cross-site scripting (XSS) vulnerability in codeparse.php in Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to inject arbitrary web sc… Patch early 4.3 medium 3.6% 2002-12-31
CVE-2003-1203 EXP Cross-site scripting (XSS) vulnerability in index.php for Mambo Site Server 4.0.10 allows remote attackers to execute script on other clients via the… Patch early 4.3 medium 3.6% 2003-03-18
CVE-2012-2234 EXP Cross-site scripting (XSS) vulnerability in sources/users.queries.php in TeamPass before 2.1.6 allows remote authenticated users to inject arbitrary w… Patch early 4.3 medium 3.6% 2012-04-22
CVE-1999-1481 EXP Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair. Patch early 5.0 medium 3.6% 1999-12-31
CVE-2022-30076 EXP ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000… Patch early 5.3 medium 3.6% 2023-04-16
CVE-2004-2727 EXP Buffer overflow in MEHTTPS (HTTPMail) of MailEnable Professional 1.5 through 1.7 allows remote attackers to cause a denial of service (application cra… Patch early 4.3 medium 3.6% 2004-12-31
CVE-2009-3716 EXP Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file… Patch early 6.5 medium 3.6% 2009-10-16
CVE-2007-1905 EXP Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary… Patch early 4.3 medium 3.6% 2007-04-10
CVE-2017-8840 EXP Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3… Patch early 5.3 medium 3.6% 2017-06-05
CVE-2008-0406 EXP HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a denial of service (daemon crash)… Patch early 5.0 medium 3.6% 2008-01-29
CVE-2020-9038 EXP Joplin through 1.0.184 allows Arbitrary File Read via XSS. Patch early 5.4 medium 3.6% 2020-02-17
CVE-2006-5033 EXP Unspecified vulnerability in StoresAndCalendarsList.cgi in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to cause a… Patch early 5.0 medium 3.6% 2006-09-27
CVE-2007-3098 EXP The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a denial of service (crash) via a… Patch early 5.0 medium 3.6% 2007-06-06
CVE-2020-27533 EXP A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, an… Patch early 5.4 medium 3.6% 2020-10-22
CVE-2011-4545 EXP CRLF injection vulnerability in admin/displayImage.php in Prestashop 1.4.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP… Patch early 5.0 medium 3.6% 2011-12-02
CVE-2001-0228 EXP Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in an HTTP GET… Patch early 5.0 medium 3.6% 2001-05-03
CVE-2005-3813 EXP IMAP service (meimaps.exe) of MailEnable Professional 1.7 and Enterprise 1.1 allows remote authenticated attackers to cause a denial of service (appli… Patch early 4.0 medium 3.6% 2005-11-26
CVE-2000-0239 EXP Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mail_user parameter in the GET re… Patch early 5.0 medium 3.6% 2000-03-15
CVE-2021-33570 EXP Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files… Patch early 5.4 medium 3.6% 2021-05-25
CVE-2007-2964 EXP The fsmsh.dll host module in F-Secure Policy Manager Server 7.00 and earlier allows remote attackers to cause a denial of service (application crash)… Patch early 5.0 medium 3.6% 2007-05-31
CVE-2006-5319 EXP Directory traversal vulnerability in redir.php in Foafgen 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the foaf parameter… Patch early 5.0 medium 3.6% 2006-10-17
CVE-2003-1032 EXP Pi3Web web server 2.0.2 Beta 1, when the Directory Index is configured to use the "Name" column and sort using the column title as a hyperlink, allows… Patch early 5.0 medium 3.6% 2004-02-17
CVE-2008-6420 EXP Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.php, (2) webadmin/download.php… Patch early 5.0 medium 3.6% 2009-03-06
← previous page 149 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt