peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,371 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-1923 EXP Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (2… Patch early 5.0 medium 3.3% 2004-04-11
CVE-2007-5386 EXP Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allo… Patch early 4.3 medium 3.3% 2007-10-12
CVE-2007-5589 EXP Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.11.1.2 allow remote attackers to inject arbitrary web script or HTML via ce… Patch early 4.3 medium 3.3% 2007-10-19
CVE-2007-1968 EXP PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP co… Patch early 6.8 medium 3.3% 2007-04-11
CVE-2014-7177 EXP XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a crafted xml docume… Patch early 4.0 medium 3.3% 2014-10-31
CVE-2006-6899 EXP hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a… Patch early 5.4 medium 3.3% 2006-12-31
CVE-2008-0464 EXP Directory traversal vulnerability in archiv.cgi in absofort aconon Mail 2007 Enterprise SQL 11.7.0 and Mail 2004 Enterprise SQL 11.5.1 allows remote a… Patch early 5.0 medium 3.3% 2008-01-25
CVE-2008-0790 EXP Directory traversal vulnerability in ipdsserver.exe in Intermate WinIPDS 3.3 G52-33-021 allows remote attackers to read arbitrary files via a .. (dot… Patch early 5.0 medium 3.3% 2008-02-15
CVE-2006-1114 EXP Multiple directory traversal vulnerabilities in Loudblog before 0.42 allow remote attackers to read or include arbitrary files via a .. (dot dot) and… Patch early 6.4 medium 3.3% 2006-03-09
CVE-2012-3551 EXP Cross-site scripting (XSS) vulnerability in crowbar_framework/app/views/support/index.html.haml in the Crowbar barclamp in Crowbar, possibly 1.4 and e… Patch early 4.3 medium 3.3% 2012-09-05
CVE-2003-1371 EXP Nuked-Klan 1.3b, and possibly earlier versions, allows remote attackers to obtain sensitive server information via an op parameter set to phpinfo for… Patch early 4.3 medium 3.3% 2003-12-31
CVE-2007-0335 EXP Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .… Patch early 6.8 medium 3.3% 2007-01-18
CVE-2002-0209 EXP Nortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled, allows remote attackers to de… Patch early 5.0 medium 3.3% 2002-05-16
CVE-2008-0760 EXP Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.0.4.0 and earlier, allows remo… Patch early 5.0 medium 3.3% 2008-02-13
CVE-2000-0897 EXP Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL that references a directory tha… Patch early 5.0 medium 3.3% 2001-01-09
CVE-2001-0122 EXP Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote atta… Patch early 5.0 medium 3.3% 2001-03-13
CVE-2001-0386 EXP AnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory. Patch early 5.0 medium 3.3% 2001-07-02
CVE-2002-0894 EXP NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to cause a denial of service (crash) via (1) a request for a long .jsp file, or (2) a long UR… Patch early 5.0 medium 3.3% 2002-10-04
CVE-2002-1071 EXP ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the… Patch early 5.0 medium 3.3% 2002-10-04
CVE-2008-4087 EXP Stack-based buffer overflow in Acoustica Beatcraft 1.02 Build 19 allows user-assisted attackers to cause a denial of service or execute arbitrary code… Patch early 6.8 medium 3.3% 2008-09-15
CVE-2018-19749 EXP DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field. Patch early 4.8 medium 3.3% 2018-11-29
CVE-2018-19751 EXP DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields. Patch early 4.8 medium 3.3% 2018-11-29
CVE-2018-19752 EXP DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar. Patch early 4.8 medium 3.3% 2018-11-29
CVE-2018-19914 EXP DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field. Patch early 4.8 medium 3.3% 2018-12-06
CVE-2003-1219 EXP Cross-site scripting (XSS) vulnerability in the tep_href_link function in html_output.php for osCommerce before 2.2-MS3 allows remote attackers to inj… Patch early 4.3 medium 3.3% 2003-12-31
CVE-2006-3363 EXP PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via a… Patch early 5.1 medium 3.3% 2006-07-06
CVE-2005-4723 EXP D-Link DI-524 Wireless Router, DI-624 Wireless Router, and DI-784 allow remote attackers to cause a denial of service (device reboot) via a series of… Patch early 5.0 medium 3.3% 2005-12-31
CVE-2012-5967 EXP SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote authenticated users to execut… Patch early 6.5 medium 3.3% 2012-12-19
CVE-2007-4911 EXP JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a long .mp3 URI to TCP port 8000.… Patch early 5.0 medium 3.3% 2007-09-17
CVE-2009-3856 EXP Cross-site scripting (XSS) vulnerability in the default URI in news/ in Twilight CMS before 4.1 allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 3.3% 2009-11-04
← previous page 161 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt