peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,212 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-1001 EXP Multiple cross-site scripting (XSS) vulnerabilities in Chyrp before 2.1.2 and before 2.5 Beta 2 allow remote attackers to inject arbitrary web script… Patch early 6.1 medium 3.6% 2019-11-21
CVE-2006-6827 EXP Flash8b.ocx in Macromedia Flash 8 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the Flash8b.Al… Patch early 5.0 medium 3.6% 2006-12-31
CVE-2012-4267 EXP Cross-site scripting (XSS) vulnerability in user/register in Sockso 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 3.6% 2012-08-13
CVE-2008-0631 EXP Multiple ActiveX controls in MailBee.dll in MailBee Objects 5.5 allow remote attackers to (1) overwrite arbitrary files via the SaveToDisk method, or… Patch early 4.3 medium 3.6% 2008-02-06
CVE-2013-2760 EXP Buffer overflow in Groovy Media Player 3.2.0 allows remote attackers to execute arbitrary code via a long string in a .m3u file. Patch early 6.8 medium 3.6% 2013-04-16
CVE-2006-5034 EXP Directory traversal vulnerability in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to read arbitrary files via a ..… Patch early 5.0 medium 3.6% 2006-09-27
CVE-2014-4944 EXP Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress allow remote authenticated users… Patch early 6.5 medium 3.6% 2014-07-14
CVE-2007-2423 EXP Cross-site scripting (XSS) vulnerability in index.php in MoinMoin 1.5.7 allows remote attackers to inject arbitrary web script or HTML via the do para… Patch early 5.8 medium 3.6% 2007-05-02
CVE-2007-1110 EXP Directory traversal vulnerability in data/showcode.php in ActiveCalendar 1.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in t… Patch early 5.0 medium 3.6% 2007-02-26
CVE-2001-0462 EXP Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. Patch early 5.0 medium 3.6% 2001-06-27
CVE-2002-1033 EXP Directory traversal vulnerability in none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via a "..:" sequence (dot-dot v… Patch early 5.0 medium 3.6% 2002-10-04
CVE-2003-1450 EXP BitchX 75p3 and 1.0c16 through 1.0c20cvs allows remote attackers to cause a denial of service (segmentation fault) via a malformed RPL_NAMREPLY numeri… Patch early 5.0 medium 3.6% 2003-12-31
CVE-2018-0968 EXP An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel… Patch early 5.5 medium 3.6% 2018-04-12
CVE-2008-4874 EXP The web component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 has a back door "service" account with "service" as it… Patch early 5.0 medium 3.5% 2008-11-01
CVE-2005-0369 EXP Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a… Patch early 5.3 medium 3.5% 2005-05-02
CVE-2012-0782 EXP Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow re… Patch early 4.3 medium 3.5% 2012-01-30
CVE-2009-4053 EXP Multiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) create arbitrary directories via di… Patch early 6.5 medium 3.5% 2009-11-23
CVE-2012-6276 EXP Directory traversal vulnerability in the web-based management interface on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n a… Patch early 4.3 medium 3.5% 2013-01-26
CVE-2007-6581 EXP Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrary local files via a .. (dot do… Patch early 6.4 medium 3.5% 2007-12-28
CVE-2002-1494 EXP Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script by inserting the script after… Patch early 4.3 medium 3.5% 2003-04-02
CVE-2002-1806 EXP Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. Patch early 4.3 medium 3.5% 2002-12-31
CVE-2002-1995 EXP Cross-site scripting (XSS) vulnerability in phptonuke.php for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the filnavn… Patch early 4.3 medium 3.5% 2002-12-31
CVE-2002-2193 EXP Cross-site scripting (XSS) vulnerability in mojo.cgi for Mojo Mail 2.7 allows remote attackers to inject arbitrary web script via the email parameter. Patch early 4.3 medium 3.5% 2002-12-31
CVE-2003-1243 EXP Cross-site scripting vulnerability (XSS) in Sage 1.0 b3 allows remote attackers to insert arbitrary HTML or web script via the mod parameter. Patch early 4.3 medium 3.5% 2003-12-31
CVE-2020-22841 EXP Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input fie… Patch early 4.8 medium 3.5% 2021-02-09
CVE-2009-1583 EXP Multiple cross-site scripting (XSS) vulnerabilities in TemaTres 1.0.3 and 1.031 allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 3.5% 2009-05-07
CVE-2010-0366 EXP Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta all… Patch early 6.8 medium 3.5% 2010-01-21
CVE-2009-3902 EXP Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read arbitrary files via a /\.. (sla… Patch early 5.0 medium 3.5% 2009-11-06
CVE-2000-1027 EXP Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requ… Patch early 5.0 medium 3.5% 2000-12-11
CVE-2002-1028 EXP Multiple buffer overflows in the CGI programs for Oddsock Song Requester WinAmp plugin 2.1 allow remote attackers to cause a denial of service (crash)… Patch early 5.0 medium 3.5% 2002-10-04
← previous page 150 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt