peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,212 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-3948 EXP Directory traversal vulnerability in main.php in PHPAlbum 0.2.3 and earlier allows remote attackers to read arbitrary files via the (1) cmd and (2) va… Patch early 5.0 medium 3.5% 2005-12-01
CVE-2007-0357 EXP Directory traversal vulnerability in the AVM IGD CTRL Service in Fritz!DSL 02.02.29 allows remote attackers to read arbitrary files via ..%5C (URL-enc… Patch early 5.0 medium 3.5% 2007-01-19
CVE-2009-2229 EXP Directory traversal vulnerability in engine.php in Kasseler CMS 1.3.5 lite allows remote attackers to read arbitrary files via a .. (dot dot) in the f… Patch early 5.0 medium 3.5% 2009-06-26
CVE-2011-3856 EXP Cross-site scripting (XSS) vulnerability in the Elegant Grunge theme before 1.0.4 for WordPress allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 3.5% 2011-09-28
CVE-2011-3858 EXP Cross-site scripting (XSS) vulnerability in the Pixiv Custom theme before 2.1.6 for WordPress allows remote attackers to inject arbitrary web script o… Patch early 4.3 medium 3.5% 2011-09-28
CVE-2011-3861 EXP Cross-site scripting (XSS) vulnerability in the Web Minimalist 200901 theme before 1.2 for WordPress allows remote attackers to inject arbitrary web s… Patch early 4.3 medium 3.5% 2011-09-28
CVE-2011-3865 EXP Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 3.5% 2011-09-28
CVE-2013-1604 EXP Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to read arbitrary files via a… Patch early 5.0 medium 3.5% 2014-03-25
CVE-2006-2012 EXP Format string vulnerability in Skulltag 0.96f and earlier allows remote attackers to cause a denial of service via the version string. Patch early 5.0 medium 3.5% 2006-04-25
CVE-2005-0853 EXP betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a direct request… Patch early 5.0 medium 3.5% 2005-05-02
CVE-2015-6518 EXP Multiple cross-site scripting (XSS) vulnerabilities in phpLiteAdmin 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH… Patch early 4.3 medium 3.5% 2015-08-18
CVE-2004-2077 EXP Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed d… Patch early 5.0 medium 3.5% 2004-02-08
CVE-2011-1569 EXP download.aspx in Douran Portal 3.9.7.8 allows remote attackers to obtain source code of arbitrary files under the web root via (1) a trailing ".", (2)… Patch early 5.0 medium 3.5% 2011-04-05
CVE-2006-1275 EXP GGZ Gaming Zone 0.0.12 allows remote attackers to cause a denial of service (client disconnect) via inputs that produce malformed XML, including (1) t… Patch early 5.0 medium 3.5% 2006-03-19
CVE-2010-4518 EXP Cross-site scripting (XSS) vulnerability in wp-safe-search/wp-safe-search-jx.php in the Safe Search plugin 0.7 for WordPress allows remote attackers t… Patch early 4.3 medium 3.5% 2010-12-09
CVE-2012-0974 EXP Multiple cross-site scripting (XSS) vulnerabilities in the getParam function in oc-includes/osclass/core/Params.php in OSClass before 2.3.5 allow remo… Patch early 4.3 medium 3.5% 2012-09-25
CVE-2014-3080 EXP Multiple cross-site scripting (XSS) vulnerabilities on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allow re… Patch early 4.3 medium 3.5% 2014-08-17
CVE-2006-4525 EXP Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary… Patch early 4.3 medium 3.5% 2006-09-01
CVE-2004-1792 EXP swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a long packet with two CRLF se… Patch early 5.0 medium 3.5% 2004-12-31
CVE-2004-2151 EXP Chatman 1.1.1 RC1 and earlier allows remote attackers to cause a denial of service (memory consumption or application crash) via a very large data siz… Patch early 5.0 medium 3.5% 2004-12-31
CVE-2012-1669 EXP Directory traversal vulnerability in index.php in phpMoneyBooks before 1.0.3 allows remote attackers to include and execute arbitrary local files via… Patch early 4.3 medium 3.5% 2014-11-17
CVE-2013-4759 EXP Multiple cross-site scripting (XSS) vulnerabilities in the Magnolia Form module 1.x before 1.4.7 and 2.x before 2.0.2 for Magnolia CMS allow remote at… Patch early 4.3 medium 3.5% 2013-08-09
CVE-2010-0714 EXP Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Con… Patch early 4.3 medium 3.5% 2010-02-26
CVE-2004-1912 EXP The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke… Patch early 5.0 medium 3.5% 2004-12-31
CVE-2007-2268 EXP Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a… Patch early 5.0 medium 3.5% 2007-04-25
CVE-2007-2747 EXP Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in t… Patch early 5.0 medium 3.5% 2007-05-17
CVE-2006-7086 EXP The (1) dlback.php and (2) dlback.cgi scripts in Hot Links allow remote attackers to obtain sensitive information and download the database via a dire… Patch early 4.3 medium 3.5% 2007-03-02
CVE-2002-2055 EXP Cross-site scripting (XSS) vulnerability in userlog.php in TeeKai Tracking Online 1.0 allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 3.5% 2002-12-31
CVE-2004-2028 EXP Cross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or HTML via the referer parameter… Patch early 4.3 medium 3.5% 2004-05-21
CVE-2005-0881 EXP Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 3.5% 2005-03-23
← previous page 151 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt