peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,371 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-4665 EXP Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 3.3% 2015-08-13
CVE-2012-3845 EXP Buffer overflow in LAN Messenger 1.2.28 and earlier allows remote attackers to cause a denial of service (crash) via a long string in an initiation re… Patch early 5.0 medium 3.3% 2012-07-03
CVE-2000-0569 EXP Sybergen Sygate allows remote attackers to cause a denial of service by sending a malformed DNS UDP packet to its internal interface. Patch early 5.0 medium 3.3% 2000-06-30
CVE-2000-1193 EXP Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhausti… Patch early 5.0 medium 3.3% 2001-08-31
CVE-2014-4014 EXP The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows… Patch early 6.2 medium 3.3% 2014-06-23
CVE-2020-9371 EXP Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input… Patch early 4.8 medium 3.3% 2020-03-04
CVE-2004-1953 EXP phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error… Patch early 5.0 medium 3.3% 2004-12-31
CVE-2005-1552 EXP GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0, when set to create JPEG images, does not properly protect an image even when a password… Patch early 5.0 medium 3.3% 2005-05-14
CVE-2003-0523 EXP Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the… Patch early 6.8 medium 3.3% 2003-08-18
CVE-2007-0143 EXP Multiple PHP remote file inclusion vulnerabilities in NUNE News Script 2.0pre2 allow remote attackers to execute arbitrary PHP code via a URL in the c… Patch early 6.8 medium 3.3% 2007-01-09
CVE-2007-1118 EXP Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 6.8 medium 3.3% 2007-02-27
CVE-2007-3161 EXP Buffer overflow in Ace-FTP Client 1.24a allows user-assisted, remote FTP servers to execute arbitrary code via a long response. Patch early 6.8 medium 3.3% 2007-06-11
CVE-2008-6659 EXP Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated users… Patch early 5.5 medium 3.3% 2009-04-07
CVE-2014-4033 EXP Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to inject arb… Patch early 4.3 medium 3.3% 2014-06-11
CVE-2009-0290 EXP Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files via a ..… Patch early 6.8 medium 3.3% 2009-01-27
CVE-2008-1958 EXP Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to execute arbi… Patch early 6.5 medium 3.3% 2008-04-25
CVE-2008-6518 EXP Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users to execute arbitrary code by… Patch early 6.5 medium 3.3% 2009-03-25
CVE-2007-1287 EXP A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct cross-site scripting (XSS) at… Patch early 4.3 medium 3.3% 2007-03-06
CVE-2006-6942 EXP Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1)… Patch early 6.8 medium 3.3% 2007-01-19
CVE-2011-2260 EXP Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Products Suite 2.1.1 allows remote attackers to affect confidentialit… Patch early 5.8 medium 3.3% 2011-07-20
CVE-2006-4962 EXP Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read and execute arbitrary local f… Patch early 6.4 medium 3.3% 2006-09-23
CVE-2011-4882 EXP The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to cause a denial of service (application exit) via an unsp… Patch early 5.0 medium 3.3% 2012-04-13
CVE-2012-4739 EXP Multiple cross-site scripting (XSS) vulnerabilities in Barracuda SSL VPN before 2.2.2.203 (2012-07-05) allow remote attackers to inject arbitrary web… Patch early 4.3 medium 3.3% 2012-08-31
CVE-2008-3823 EXP Cross-site scripting (XSS) vulnerability in MIME/MIME/Contents.php in the MIME library in Horde 3.2.x before 3.2.2 allows remote attackers to inject a… Patch early 4.3 medium 3.3% 2008-09-12
CVE-2011-0506 EXP Directory traversal vulnerability in modules/profile/user.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers to execute arbitrary code via… Patch early 6.8 medium 3.3% 2011-01-20
CVE-2008-6913 EXP Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated users to execute arbitrary code by… Patch early 6.5 medium 3.3% 2009-08-07
CVE-2008-6928 EXP Unrestricted file upload vulnerability in PHPStore Complete Classifieds allows remote authenticated users to execute arbitrary code by uploading a fil… Patch early 6.5 medium 3.3% 2009-08-11
CVE-2008-7052 EXP Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticated users to execute arbitrary… Patch early 6.5 medium 3.3% 2009-08-24
CVE-2000-0660 EXP The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack. Patch early 5.0 medium 3.3% 2000-07-12
CVE-2009-3182 EXP Unrestricted file upload vulnerability in admin/editor/filemanager/browser.html in Anantasoft Gazelle CMS 1.0 allows remote attackers to execute arbit… Patch early 6.8 medium 3.3% 2009-09-11
← previous page 162 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt