peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,590 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2003-1541 EXP PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain t… Patch early 5.0 medium 3% 2003-12-31
CVE-2004-2480 EXP Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via "@@" sequences in a URL within… Patch early 5.0 medium 3% 2004-12-31
CVE-2009-3601 EXP Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 3% 2009-10-08
CVE-2015-2805 EXP Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lucent OmniS… Patch early 6.8 medium 3% 2015-06-16
CVE-2014-1665 EXP Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the fil… Patch early 5.4 medium 3% 2018-03-20
CVE-2002-1862 EXP SmartMail Server 2.0 allows remote attackers to cause a denial of service (crash) by sending data and closing the connection before all the data has b… Patch early 5.0 medium 3% 2002-12-31
CVE-2004-2344 EXP Unknown vulnerability in the ASN.1/H.323/H.225 stack of VocalTec VGW120 and VGW480 allows remote attackers to cause a denial of service. Patch early 5.0 medium 3% 2004-12-31
CVE-2005-1033 EXP CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to… Patch early 5.0 medium 3% 2005-05-02
CVE-2006-4609 EXP Multiple PHP remote file inclusion vulnerabilities in the Content Management module ("Content manager") for PHProjekt 0.6.1, when register_globals is… Patch early 5.1 medium 3% 2006-09-07
CVE-2006-4638 EXP PHP remote file inclusion vulnerability in article.php in ACGV News 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL… Patch early 5.1 medium 3% 2006-09-08
CVE-2006-4719 EXP Multiple PHP remote file inclusion vulnerabilities in MyABraCaDaWeb 1.0.3, when register_globals is enabled, allow remote attackers to execute arbitra… Patch early 5.1 medium 3% 2006-09-12
CVE-2006-4750 EXP PHP remote file inclusion vulnerability in openi-admin/base/fileloader.php in OPENi-CMS 1.0.1, and possibly earlier, allows remote attackers to execut… Patch early 5.1 medium 3% 2006-09-13
CVE-2006-5070 EXP PHP remote file inclusion vulnerability in fsl2/objects/fs_form_links.php in faceStones Personal 2.0.42 and earlier allows remote attackers to execute… Patch early 5.1 medium 3% 2006-09-28
CVE-2006-5167 EXP Multiple PHP remote file inclusion vulnerabilities in BasiliX 1.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 5.1 medium 3% 2006-10-05
CVE-2006-5207 EXP PHP remote file inclusion vulnerability in images/smileys/smileys_packs.php in phpMyTeam 2.0, when register_globals is enabled, allows remote attacker… Patch early 5.1 medium 3% 2006-10-10
CVE-2006-4631 EXP Direct static code injection vulnerability in admin/save_opt.php in SoftBB 0.1, and possibly earlier, allows remote authenticated users to upload and… Patch early 6.5 medium 3% 2006-09-08
CVE-2006-6330 EXP index.php for TorrentFlux 2.2 allows remote registered users to execute arbitrary commands via shell metacharacters in the kill parameter. Patch early 6.0 medium 3% 2006-12-06
CVE-2008-6112 EXP Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a .. (dot dot) in the id parame… Patch early 5.0 medium 3% 2009-02-11
CVE-2010-4781 EXP index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attackers to obtain sensitive informa… Patch early 5.0 medium 3% 2011-04-07
CVE-2015-6965 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for WordPress allow remote attackers… Patch early 6.8 medium 3% 2015-09-16
CVE-2006-4766 EXP Directory traversal vulnerability in print.php in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allows remote attackers to read arbitrary files via a… Patch early 5.0 medium 3% 2006-09-13
CVE-2007-0055 EXP Directory traversal vulnerability in formbankcgi.exe/AbfrageForm in Formbankserver 1.9 allows remote attackers to read arbitrary files via directory t… Patch early 5.0 medium 3% 2007-01-04
CVE-2005-3520 EXP Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web script or HTML via (1) the targe… Patch early 4.3 medium 3% 2005-11-06
CVE-2017-11785 EXP The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, W… Patch early 5.5 medium 3% 2017-10-13
CVE-2017-8564 EXP Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 1… Patch early 5.5 medium 3% 2017-07-11
CVE-2007-3790 EXP The com_print_typeinfo function in the bz2 extension in PHP 5.2.3 allows context-dependent attackers to cause a denial of service via a long argument. Patch early 5.8 medium 3% 2007-07-15
CVE-2007-2780 EXP PsychoStats 3.0.6b and earlier allows remote attackers to obtain sensitive information via a request for server.php with a missing or invalid newtheme… Patch early 5.0 medium 3% 2007-05-21
CVE-2007-3556 EXP Liesbeth base CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an inclu… Patch early 5.0 medium 3% 2007-07-04
CVE-2017-2508 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" co… Patch early 6.1 medium 3% 2017-05-22
CVE-2001-0286 EXP Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request. Patch early 5.0 medium 3% 2001-05-03
← previous page 177 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt