peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,573 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2011-1038 EXP Multiple cross-site scripting (XSS) vulnerabilities in stconf.nsf in the server in IBM Lotus Sametime 8.0.1 allow remote attackers to inject arbitrary… Patch early 4.3 medium 3.1% 2011-02-22
CVE-2006-5306 EXP Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow remote attackers to execute a… Patch early 6.8 medium 3.1% 2006-10-17
CVE-2020-25988 EXP UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' which leaks the credentials of '… Patch early 6.5 medium 3.1% 2020-11-17
CVE-2004-2121 EXP Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files… Patch early 5.0 medium 3.1% 2004-12-31
CVE-2005-3947 EXP Directory traversal vulnerability in index.php in PHP Upload Center allows remote attackers to read arbitrary files via "../" sequences in the filenam… Patch early 5.0 medium 3.1% 2005-12-01
CVE-2008-1862 EXP ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which allows remote attackers to bypas… Patch early 6.8 medium 3.1% 2008-04-17
CVE-2006-4669 EXP PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals is enabled, allows remote attac… Patch early 5.1 medium 3.1% 2006-09-09
CVE-2006-5427 EXP PHP remote file inclusion vulnerability in plugins/main.php in Php AMX 0.9.0, when register_globals is enabled or magic_quotes_gpc is disabled, allows… Patch early 5.1 medium 3.1% 2006-10-20
CVE-2021-42750 EXP A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrar… Patch early 4.8 medium 3.1% 2022-08-12
CVE-2021-42751 EXP A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrar… Patch early 4.8 medium 3.1% 2022-08-12
CVE-2010-3841 EXP Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 3.1% 2010-10-18
CVE-2006-0444 EXP SQL injection vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.1 allows remote attackers to execute arbitrary SQL commands via the (1) par… Patch early 6.8 medium 3% 2006-01-26
CVE-2005-3493 EXP Battle Carry .005 and earlier allows remote attackers to cause a denial of service (inaccessible port) via a large packet, which triggers a socket err… Patch early 5.0 medium 3% 2005-11-04
CVE-2021-3111 EXP The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/v… Patch early 4.8 medium 3% 2021-01-08
CVE-2008-3265 EXP SQL injection vulnerability in the DT Register (com_dtregister) 2.2.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands… Patch early 6.8 medium 3% 2008-07-24
CVE-2017-8685 EXP Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows information disclosure by the way it discloses kernel memory ad… Patch early 5.5 medium 3% 2017-09-13
CVE-2009-4610 EXP Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 3% 2010-01-13
CVE-2007-4812 EXP Buffer overflow in Apple Safari 3.0.3 522.15.5, and other versions before Beta Update 3.0.4, allows remote attackers to cause a denial of service (cra… Patch early 5.0 medium 3% 2007-09-11
CVE-2003-1207 EXP Crob FTP Server 3.5.1 allows remote authenticated users to cause a denial of service (crash) via a dir command with a large number of "." characters f… Patch early 5.0 medium 3% 2004-02-01
CVE-2013-2504 EXP Cross-site scripting (XSS) vulnerability in SPS/Portal/default.aspx in Service Desk in Matrix42 Service Store 5.3 SP3 (aka 5.33.946.0) allows remote a… Patch early 4.3 medium 3% 2013-12-29
CVE-2008-3569 EXP Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.6.7, when register_globals is enabled, allow remote attackers to inject arbitrary web s… Patch early 4.3 medium 3% 2008-08-10
CVE-2017-14096 EXP A stored cross site scripting (XSS) vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker t… Patch early 6.1 medium 3% 2018-01-19
CVE-2019-1345 EXP An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosur… Patch early 5.5 medium 3% 2019-10-10
CVE-2006-4427 EXP index.php in eFiction before 2.0.7 allows remote attackers to bypass authentication and gain privileges by setting the (1) adminloggedin, (2) loggedin… Patch early 5.1 medium 3% 2006-08-29
CVE-2008-6676 EXP QuickerSite 1.8.5 allows remote attackers to obtain sensitive information via a request to showThumb.aspx without any parameters, which reveals the in… Patch early 5.0 medium 3% 2009-04-08
CVE-2005-0796 EXP Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot d… Patch early 5.0 medium 3% 2005-05-02
CVE-1999-1083 EXP Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack. Patch early 5.0 medium 3% 1999-10-08
CVE-2003-0338 EXP Directory traversal vulnerability in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allows remote attackers to read and execute arbitrary files via .. (dot… Patch early 5.0 medium 3% 2003-05-21
CVE-2006-4270 EXP PHP remote file inclusion vulnerability in mambelfish.class.php in the mambelfish component (com_mambelfish) 1.1 and earlier for Mambo allows remote a… Patch early 6.8 medium 3% 2006-08-21
CVE-2007-3127 EXP content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to obtain sensitive information via a "';" (quote semicolon) s… Patch early 5.0 medium 3% 2007-06-19
← previous page 176 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt