peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,317 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-6751 EXP Format string vulnerability in XM Easy Personal FTP Server 5.2.1 allows remote attackers to cause a denial of service (application crash) via format s… Patch early 5.0 medium 3.4% 2006-12-27
CVE-2009-1561 EXP Cross-site request forgery (CSRF) vulnerability in administration.cgi on the Cisco Linksys WRT54GC router with firmware 1.05.7 allows remote attackers… Patch early 6.8 medium 3.4% 2009-05-06
CVE-2001-0593 EXP Anaconda Partners Clipper 3.3 and earlier allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the template parameter. Patch early 5.0 medium 3.4% 2001-08-22
CVE-2002-1852 EXP Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) a param… Patch early 4.3 medium 3.4% 2002-12-31
CVE-2005-1201 EXP Multiple directory traversal vulnerabilities in AZ Bulletin board (AZbb) before 1.0.08 allow (1) remote authenticated users with administrative privil… Patch early 6.4 medium 3.4% 2005-05-02
CVE-2004-2360 EXP Targem Battle Mages 1.0 allows remote attackers to cause a denial of service (infinite loop) via a UDP packet with incomplete data, which causes the s… Patch early 5.0 medium 3.4% 2004-12-31
CVE-2007-4366 EXP WengoPhone 2.1 allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Content-Type header. Patch early 5.0 medium 3.4% 2007-08-15
CVE-2014-5023 EXP Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in… Patch early 6.8 medium 3.4% 2014-07-22
CVE-2006-4664 EXP PHP remote file inclusion vulnerability in includes/functions_portal.php in Premod Shadow 2.7.1 and earlier allows remote attackers to execute arbitra… Patch early 5.1 medium 3.4% 2006-09-09
CVE-2006-5636 EXP PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote attackers to execute arbitrary P… Patch early 5.1 medium 3.4% 2006-11-01
CVE-2006-5727 EXP PHP remote file inclusion vulnerability in admin/controls/cart.php in sazcart 1.5 allows remote attackers to execute arbitrary PHP code via the (1) _s… Patch early 5.1 medium 3.4% 2006-11-06
CVE-2008-5566 EXP Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote attackers to inject arbitrary w… Patch early 4.3 medium 3.4% 2008-12-15
CVE-2010-2032 EXP Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possib… Patch early 4.3 medium 3.4% 2010-05-24
CVE-2010-2130 EXP Cross-site scripting (XSS) vulnerability in wflogin.jsp in Aris Global ARISg 5.0 allows remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 3.4% 2010-06-02
CVE-2006-3546 EXP Patrice Freydiere ImgSvr (aka ADA Image Server) allows remote attackers to cause a denial of service (daemon crash) via a long HTTP POST request. NOT… Patch early 5.0 medium 3.4% 2006-07-13
CVE-2007-0986 EXP PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remote attackers to execute arbitra… Patch early 5.1 medium 3.4% 2007-02-16
CVE-2010-2856 EXP Cross-site scripting (XSS) vulnerability in admin/currencies.php in osCSS 1.2.2, and probably earlier versions, allows remote attackers to inject arbi… Patch early 4.3 medium 3.4% 2010-07-25
CVE-2005-1718 EXP Buffer overflow in LS Games War Times 1.03 and earlier allows remote attackers to cause a denial of service (server crash) via a long nickname. Patch early 5.0 medium 3.4% 2005-05-24
CVE-2018-7543 EXP Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attac… Patch early 6.1 medium 3.3% 2018-03-26
CVE-2017-2504 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. Th… Patch early 6.1 medium 3.3% 2017-05-22
CVE-2021-43701 EXP CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS[] and ord… Patch early 6.5 medium 3.3% 2022-03-29
CVE-2006-5711 EXP ECI Telecom B-FOCuS Wireless 802.11b/g ADSL2+ Router allows remote attackers to read arbitrary files via a certain HTTP request, as demonstrated by a… Patch early 5.0 medium 3.3% 2006-11-04
CVE-2011-0167 EXP The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Policy, and force the upload of arb… Patch early 4.3 medium 3.3% 2011-03-11
CVE-2007-1843 EXP PHP remote file inclusion vulnerability in gmapfactory/params.php in MapLab 2.2.1, when register_globals is enabled, allows remote attackers to execut… Patch early 6.8 medium 3.3% 2007-04-03
CVE-2019-8391 EXP qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter. Patch early 6.1 medium 3.3% 2019-05-14
CVE-2004-2371 EXP Multiple Red Storm web-based games, including Ghost Recon 1.4 and earlier, Desert Siege, and The Sum of all Fears 1.1.1.0 and earlier, do not properly… Patch early 5.0 medium 3.3% 2004-12-31
CVE-2005-1667 EXP DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request. Patch early 5.0 medium 3.3% 2005-05-18
CVE-2006-6028 EXP Directory traversal vulnerability in textview.php in Anton Vlasov DoSePa 1.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) sequ… Patch early 5.0 medium 3.3% 2006-11-21
CVE-2007-2195 EXP aMSN (aka Alvaro's Messenger) 0.96 and earlier allows remote attackers to cause a denial of service (application crash) by sending invalid data to TCP… Patch early 5.0 medium 3.3% 2007-04-24
CVE-2007-6000 EXP KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a denial of service (crash) via large HTTP cookie parameters. Patch early 5.0 medium 3.3% 2007-11-15
← previous page 159 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt