peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,620 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-2422 EXP Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remote attackers to inject arbitrar… Patch early 4.3 medium 3% 2002-12-31
CVE-2010-2154 EXP Cross-site scripting (XSS) vulnerability in the Search Site in CMScout 2.09, and possibly other versions, allows remote attackers to inject arbitrary… Patch early 4.3 medium 3% 2010-06-03
CVE-2009-2923 EXP Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1)… Patch early 5.0 medium 3% 2009-08-21
CVE-2009-3124 EXP Directory traversal vulnerability in get_message.cgi in QuarkMail allows remote attackers to read arbitrary files via a .. (dot dot) in the tf paramet… Patch early 5.0 medium 3% 2009-09-09
CVE-2006-7235 EXP Teamtek Universal FTP Server 1.0.50 allows remote attackers to cause a denial of service (daemon crash or hang) via (1) multiple STOR (aka PUT) comman… Patch early 5.0 medium 3% 2008-12-11
CVE-2012-5387 EXP Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordPress allows remote attackers t… Patch early 6.8 medium 3% 2012-10-24
CVE-2019-1262 EXP A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an af… Patch early 5.4 medium 3% 2019-09-11
CVE-2006-3298 EXP Yahoo! Messenger 7.5.0.814 and 7.0.438 allows remote attackers to cause a denial of service (crash) via messages that contain non-ASCII characters, wh… Patch early 5.0 medium 3% 2006-06-29
CVE-2007-0497 EXP PHP remote file inclusion vulnerability in upload/top.php in Upload-Service 1.0, when register_globals is enabled, allows remote attackers to execute… Patch early 6.8 medium 3% 2007-01-25
CVE-2007-5646 EXP SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows remote attackers to execute arbit… Patch early 6.8 medium 3% 2007-10-23
CVE-2002-2357 EXP MailEnable 1.5 015 through 1.5 018 allows remote attackers to cause a denial of service (crash) via a long USER string, possibly due to a buffer overf… Patch early 5.0 medium 3% 2002-12-31
CVE-2018-8814 EXP Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that mod… Patch early 6.5 medium 3% 2018-04-04
CVE-2019-16197 EXP In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, le… Patch early 6.1 medium 3% 2019-09-16
CVE-2009-2163 EXP Cross-site scripting (XSS) vulnerability in login/default.aspx in Sitecore CMS before 6.0.2 Update-1 090507 allows remote attackers to inject arbitrar… Patch early 4.3 medium 3% 2009-06-22
CVE-2005-3812 EXP freeFTPd 1.0.10 allows remote authenticated users to cause a denial of service (null dereference and crash) via a PORT command with missing arguments. Patch early 6.8 medium 3% 2005-11-26
CVE-2011-4807 EXP Directory traversal vulnerability in main.php in phpAlbum 0.4.1.16 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in t… Patch early 5.0 medium 3% 2011-12-14
CVE-2010-1453 EXP Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 3% 2010-05-07
CVE-2008-4532 EXP Cross-site scripting (XSS) vulnerability in index.php in MaxiScript Website Directory allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 3% 2008-10-09
CVE-2008-5584 EXP Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (… Patch early 4.3 medium 3% 2008-12-15
CVE-2010-5052 EXP Cross-site scripting (XSS) vulnerability in admin/components.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 3% 2011-11-23
CVE-2008-1127 EXP Format string vulnerability in the cryactio function in Crysis 1.1.1.5879 allows remote authenticated users to execute arbitrary code via format strin… Patch early 6.0 medium 3% 2008-03-03
CVE-2001-0264 EXP Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a… Patch early 5.0 medium 3% 2001-06-18
CVE-2019-14430 EXP plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection. Patch early 5.3 medium 3% 2019-08-20
CVE-2014-1401 EXP Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) searc… Patch early 6.5 medium 3% 2014-02-11
CVE-2016-5845 EXP SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to cause a denial of service (progr… Patch early 5.5 medium 3% 2016-08-13
CVE-2006-2528 EXP PHP remote file inclusion vulnerability in classified_right.php in phpBazar 2.1.0 and earlier allows remote attackers to execute arbitrary PHP code vi… Patch early 6.4 medium 3% 2006-05-22
CVE-2008-3508 EXP LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to bypass authentication and gain administrative access by setting the ad… Patch early 5.0 medium 3% 2008-08-07
CVE-2008-6660 EXP Unrestricted file upload vulnerability in bigdump.php in Alexey Ozerov BigDump 0.29b allows remote attackers to execute arbitrary code by uploading a… Patch early 6.8 medium 3% 2009-04-07
CVE-2019-6146 EXP It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Me… Patch early 6.1 medium 3% 2020-01-22
CVE-2017-9767 EXP Multiple cross-site scripting (XSS) vulnerabilities in Quali CloudShell before 8 allow remote authenticated users to inject arbitrary web script or HT… Patch early 5.4 medium 3% 2017-08-18
← previous page 179 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt