peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,590 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2003-1232 EXP Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted att… Patch early 5.1 medium 3% 2003-12-31
CVE-2005-1870 EXP PHP remote file inclusion vulnerability in childwindow.inc.php in Popper 1.41-r2 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 5.0 medium 3% 2005-06-09
CVE-2006-4637 EXP Multiple PHP remote file inclusion vulnerabilities in ACGV News 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the PathNews p… Patch early 5.1 medium 3% 2006-09-08
CVE-2007-4127 EXP PHP remote file inclusion vulnerability in check_entry.php in Ralf Image Gallery (RIG), aka Raphael Moll RIG Image Gallery, 1.0 allows remote attacker… Patch early 6.8 medium 3% 2007-08-01
CVE-2018-17996 EXP LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content vi… Patch early 6.5 medium 3% 2019-03-21
CVE-2021-27695 EXP Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via an… Patch early 6.1 medium 3% 2021-03-15
CVE-2007-5149 EXP PHP remote file inclusion vulnerability in NewsCMS/news/newstopic_inc.php in North Country Public Radio Public Media Manager (PMM) 1.3 allows remote a… Patch early 6.8 medium 3% 2007-10-01
CVE-2007-5178 EXP contrib/mx_glance_sdesc.php in the mx_glance 2.3.3 module for mxBB places a critical security check within a comment because of a missing comment deli… Patch early 6.8 medium 3% 2007-10-03
CVE-2006-6673 EXP WinFtp Server 2.0.2 allows remote attackers to cause a denial of service (crash) via long (1) PASV, (2) LIST, (3) USER, (4) PORT, and possibly other c… Patch early 5.0 medium 3% 2006-12-21
CVE-2009-4542 EXP Cross-site scripting (XSS) vulnerability in newticket.php in IsolSoft Support Center 2.5 allows remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 3% 2010-01-04
CVE-2009-1749 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 3% 2009-05-22
CVE-2009-2325 EXP Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the side para… Patch early 5.0 medium 3% 2009-07-05
CVE-2006-5832 EXP All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to obtain the full path of the web server via certain requests to (1) pub… Patch early 5.0 medium 3% 2006-11-10
CVE-2006-2431 EXP Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 a… Patch early 4.3 medium 3% 2006-05-17
CVE-2007-1190 EXP Unspecified vulnerability in the EmbeddedWB Web Browser ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors. NO… Patch early 6.8 medium 3% 2007-03-02
CVE-2006-5730 EXP PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS 0.9.2.1 and earlier allows re… Patch early 5.1 medium 3% 2006-11-06
CVE-2011-5040 EXP Multiple cross-site scripting (XSS) vulnerabilities in Infoproject Biznis Heroj allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 3% 2011-12-30
CVE-2006-4977 EXP Multiple unrestricted file upload vulnerabilities in (1) back/upload_img.php and (2) admin/upload_img.php in Walter Beschmout PhpQuiz 1.2 and earlier… Patch early 5.0 medium 3% 2006-09-25
CVE-2005-2030 EXP Ultimate PHP Board (UPB) 1.9.6 GOLD uses weak encryption for passwords in the users.dat file, which allows attackers to easily decrypt the passwords a… Patch early 5.0 medium 3% 2005-06-16
CVE-2012-1467 EXP Multiple directory traversal vulnerabilities in the iBrowser plugin library, as used in Open Journal Systems before 2.3.7, allow remote authenticated… Patch early 6.5 medium 3% 2012-09-06
CVE-2008-5787 EXP Directory traversal vulnerability in mod.php in Arab Portal 2.1 on Windows allows remote attackers to read arbitrary files via a .. (dot dot) in the f… Patch early 5.4 medium 3% 2008-12-31
CVE-2003-1017 EXP Macromedia Flash Player before 7,0,19,0 stores a Flash data file in a predictable location that is accessible to web browsers such as Internet Explore… Patch early 5.0 medium 3% 2004-01-05
CVE-2005-1325 EXP set_lang.php in phpMyVisites 1.3 allows remote attackers to read and include arbitrary files via the mylang parameter. Patch early 5.0 medium 3% 2005-05-02
CVE-2005-3018 EXP Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted data:// URL. Patch early 5.0 medium 3% 2005-09-21
CVE-2006-1922 EXP PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a… Patch early 6.4 medium 3% 2006-04-20
CVE-2006-5866 EXP Directory traversal vulnerability in Mdoc/view-sourcecode.php for phpManta 1.0.2 and earlier allows remote attackers to read and include arbitrary fil… Patch early 6.4 medium 3% 2006-11-11
CVE-2006-2723 EXP Unspecified versions of Mozilla Firefox allow remote attackers to cause a denial of service (crash) via a web page that contains a large number of nes… Patch early 5.0 medium 3% 2006-06-01
CVE-2006-5661 EXP Cross-site scripting (XSS) vulnerability in nquser.php in VIRtech Netquery allows remote attackers to inject arbitrary web script or HTML via the User… Patch early 6.8 medium 3% 2006-11-03
CVE-2006-6715 EXP PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabled, allows remote attackers to… Patch early 5.1 medium 3% 2006-12-23
CVE-2006-6938 EXP Directory traversal vulnerability in includes/common.php in NitroTech 0.0.3a, as distributed before 2006, allows remote attackers to include arbitrary… Patch early 5.0 medium 3% 2007-01-17
← previous page 178 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt