peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,573 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-1621 EXP NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier… Patch early 4.3 medium 3.1% 2004-10-18
CVE-2010-5099 EXP The fileDenyPattern functionality in the PHP file inclusion protection API in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 do… Patch early 6.8 medium 3.1% 2012-05-30
CVE-2006-4444 EXP Multiple SQL injection vulnerabilities in Cybozu Garoon 2.1.0 for Windows allow remote authenticated users to execute arbitrary SQL commands via the (… Patch early 6.5 medium 3.1% 2006-08-29
CVE-2006-3269 EXP PHP remote file inclusion vulnerability in includes/functions_cms.php in THoRCMS 1.3.1 allows remote attackers to execute arbitrary PHP code via the p… Patch early 5.1 medium 3.1% 2006-06-28
CVE-2006-3294 EXP PHP remote file inclusion vulnerability in mod_cbsms_messages.php in CBSMS Mambo Module 1.0 and earlier, when register_globals is enabled, allows remo… Patch early 5.1 medium 3.1% 2006-06-29
CVE-2006-4113 EXP PHP remote file inclusion vulnerability in genpage-cgi.php in Brian Fraval hitweb 4.2 and possibly earlier versions allows remote attackers to execute… Patch early 5.1 medium 3.1% 2006-08-14
CVE-2006-4158 EXP PHP remote file inclusion vulnerability in Login.php in Spaminator 1.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 5.1 medium 3.1% 2006-08-16
CVE-2006-4291 EXP PHP remote file inclusion vulnerability in handlers/email/mod.listmail.php in PHlyMail Lite 3.4.4 and earlier (Build 3.04.04) allows remote attackers… Patch early 5.1 medium 3.1% 2006-08-22
CVE-2006-4426 EXP PHP remote file inclusion vulnerability in AES/modules/auth/phpsecurityadmin/include/logout.php in AlberT-EasySite (AES) 1.0a5 and earlier allows remo… Patch early 5.1 medium 3.1% 2006-08-29
CVE-2009-2600 EXP Multiple directory traversal vulnerabilities in view.php in Webboard 2.90 beta and earlier allow remote attackers to read arbitrary files via a .. (do… Patch early 5.0 medium 3.1% 2009-07-27
CVE-2011-4716 EXP Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read arbitrary files via the file p… Patch early 5.0 medium 3.1% 2011-12-08
CVE-2006-5400 EXP PHP remote file inclusion vulnerability in forum/track.php in CyberBrau 0.9.4, when register_globals is enabled, allows remote attackers to execute ar… Patch early 5.1 medium 3.1% 2006-10-18
CVE-2006-6065 EXP PHP remote file inclusion vulnerability in includes/mx_common.php in the CalSnails Module for MxBB Portal 1.06 allows remote attackers to execute arbi… Patch early 5.1 medium 3.1% 2006-11-22
CVE-2004-1751 EXP Ground Control II: Operation Exodus 1.0.0.7 and earlier allows remote servers to cause a denial of service (client or server crash) via a large packet… Patch early 5.0 medium 3.1% 2004-08-26
CVE-2012-2905 EXP Artiphp CMS 5.5.0 Neo (r422) stores database backups with predictable names under the web root with insufficient access control, which allows remote a… Patch early 5.0 medium 3.1% 2012-05-21
CVE-2012-1469 EXP Multiple cross-site scripting (XSS) vulnerabilities in Open Journal Systems before 2.3.7 allow remote attackers and remote authenticated users to inje… Patch early 4.3 medium 3.1% 2012-09-06
CVE-2007-4385 EXP OWASP Stinger before 2.5 allows remote attackers to bypass input validation routines by using multipart encoded requests instead of form-urlencoded re… Patch early 6.8 medium 3.1% 2007-08-17
CVE-2020-13228 EXP An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter. Patch early 6.1 medium 3.1% 2020-06-02
CVE-2008-0155 EXP Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 3.1% 2008-01-09
CVE-2023-0916 EXP A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. Affected by this vulnerability is an unknown fun… Patch early 6.3 medium 3.1% 2023-02-19
CVE-2010-3486 EXP Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbitrary files via a (1) ../ (dot… Patch early 5.0 medium 3.1% 2010-09-22
CVE-2008-3181 EXP Unrestricted file upload vulnerability in upload.php in ContentNow CMS 1.4.1 allows remote authenticated users to execute arbitrary code by uploading… Patch early 6.5 medium 3.1% 2008-07-15
CVE-2006-0877 EXP Cross-site scripting vulnerability in Easy Forum 2.5 allows remote attackers to inject arbitrary web script or HTML via the image variable. Patch early 5.0 medium 3.1% 2006-02-24
CVE-1999-1518 EXP Operating systems with shared memory implementations based on BSD 4.4 code allow a user to conduct a denial of service and bypass memory limits (e.g.,… Patch early 5.0 medium 3.1% 1999-07-15
CVE-2005-1061 EXP The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure fi… Patch early 5.0 medium 3.1% 2005-05-02
CVE-2017-12951 EXP The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (stack-based bu… Patch early 6.5 medium 3.1% 2017-08-28
CVE-2018-9172 EXP The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes. Patch early 5.4 medium 3.1% 2018-04-01
CVE-2000-0601 EXP LeafChat 1.7 IRC client allows a remote IRC server to cause a denial of service by rapidly sending a large amount of error messages. Patch early 5.0 medium 3.1% 2000-06-25
CVE-2005-0283 EXP Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of… Patch early 5.0 medium 3.1% 2005-01-04
CVE-2005-1998 EXP Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang paramet… Patch early 5.0 medium 3.1% 2005-06-15
← previous page 174 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt