peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,488 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-1221 EXP Directory traversal vulnerability in the telnet server in RabidHamster R2/Extreme 1.65 and earlier allows remote attackers to read arbitrary files via… Patch early 5.0 medium 3.3% 2012-02-21
CVE-2016-8021 EXP Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote a… Patch early 5.0 medium 3.3% 2017-03-14
CVE-2006-0857 EXP Cross-site scripting (XSS) vulnerability in Chatbox Plugin 1.0 in e107 0.7.2 allows remote attackers to inject arbitrary HTML or web script via a Chat… Patch early 4.3 medium 3.3% 2006-02-23
CVE-2018-7736 EXP In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the software maintainer disputes tha… Patch early 6.1 medium 3.3% 2018-03-06
CVE-2022-0967 EXP Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.10.4. Patch early 5.4 medium 3.3% 2022-03-15
CVE-2012-1556 EXP Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3.2-1955 allows remote attackers to inject arbitrar… Patch early 4.3 medium 3.3% 2014-09-12
CVE-2012-2274 EXP Cross-site scripting (XSS) vulnerability in pivotx/ajaxhelper.php in PivotX 2.3.2 and earlier allows remote attackers to inject arbitrary web script o… Patch early 4.3 medium 3.3% 2012-08-13
CVE-2010-2018 EXP Directory traversal vulnerability in downlot.php in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in… Patch early 5.0 medium 3.3% 2010-05-24
CVE-2008-4510 EXP Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page fault and system crash) via mu… Patch early 4.9 medium 3.3% 2008-10-09
CVE-2015-7901 EXP Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execute arbitrary OS commands via un… Patch early 6.5 medium 3.3% 2015-10-28
CVE-2000-0332 EXP UltraBoard.pl or UltraBoard.cgi CGI scripts in UltraBoard 1.6 allows remote attackers to read arbitrary files via a pathname string that includes a do… Patch early 5.0 medium 3.3% 2000-05-03
CVE-2001-1107 EXP SnapStream PVS 1.2a stores its passwords in plaintext in the file SSD.ini, which could allow a remote attacker to gain privileges on the server. Patch early 5.0 medium 3.3% 2001-07-26
CVE-2001-1194 EXP Zyxel Prestige 681 and 1600 SDSL Routers allow remote attackers to cause a denial of service via malformed packets with (1) an IP length less than act… Patch early 5.0 medium 3.3% 2001-12-14
CVE-2008-0298 EXP KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a crafted web page, possibly involvi… Patch early 4.3 medium 3.3% 2008-01-16
CVE-2006-4586 EXP The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticated users to perform unauthoriz… Patch early 5.5 medium 3.3% 2006-09-06
CVE-2008-3117 EXP Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated users to execute arbitrary code… Patch early 6.5 medium 3.3% 2008-07-10
CVE-2008-7088 EXP Unrestricted file upload vulnerability in upload.php in PhotoPost vBGallery 2.4.2 allows remote authenticated users to execute arbitrary code by uploa… Patch early 6.5 medium 3.3% 2009-08-26
CVE-2013-1938 EXP Zimbra 2013 has XSS in aspell.php Patch early 6.1 medium 3.3% 2020-02-12
CVE-2000-1230 EXP Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set… Patch early 5.0 medium 3.3% 2000-12-31
CVE-2014-10078 EXP Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerc… Patch early 6.1 medium 3.3% 2019-02-23
CVE-2012-2919 EXP Directory traversal vulnerability in Upload/engine.php in Chevereto 1.9.1 allows remote attackers to determine the existence of arbitrary files via a… Patch early 5.0 medium 3.3% 2012-05-21
CVE-2021-24308 EXP The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugi… Patch early 5.4 medium 3.2% 2021-05-24
CVE-2005-0370 EXP Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (network disconnection)… Patch early 5.0 medium 3.2% 2005-05-02
CVE-2013-5092 EXP Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attackers to inject arbitrary web scr… Patch early 4.3 medium 3.2% 2014-01-29
CVE-2014-100030 EXP Cross-site scripting (XSS) vulnerability in module/search/function.php in Ganesha Digital Library (GDL) 4.2 allows remote attackers to inject arbitrar… Patch early 4.3 medium 3.2% 2015-01-13
CVE-2014-4965 EXP Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 3.2% 2014-07-15
CVE-2013-3538 EXP Multiple cross-site scripting (XSS) vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 3.2% 2013-05-13
CVE-2010-0553 EXP Geo++ GNCASTER 1.4.0.7 and earlier allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary c… Patch early 6.5 medium 3.2% 2010-02-04
CVE-2016-1609 EXP Multiple cross-site scripting (XSS) vulnerabilities in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allow remote authenti… Patch early 5.4 medium 3.2% 2016-08-01
CVE-2006-4596 EXP PHP remote file inclusion in MyBace Light Skrip, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the (1) h… Patch early 5.1 medium 3.2% 2006-09-07
← previous page 164 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt