peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,957 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2001-0306 EXP Directory traversal vulnerability in ITAfrica WEBactive HTTP Server 1.00 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL. Patch early 5.0 medium 3% 2001-05-03
CVE-2021-24719 EXP The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions… Patch early 6.1 medium 3% 2021-10-11
CVE-2009-0383 EXP delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog posts via a direct request. Patch early 6.4 medium 3% 2009-02-02
CVE-2008-2820 EXP Directory traversal vulnerability in lang/lang-system.php in Open Azimyt CMS 0.22 minimal and 0.21 stable allows remote attackers to include and execu… Patch early 6.4 medium 3% 2008-06-23
CVE-2006-3194 EXP Directory traversal vulnerability in index.php in singapore 0.10.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) sequ… Patch early 6.4 medium 3% 2006-06-23
CVE-2007-3555 EXP Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expre… Patch early 4.3 medium 3% 2007-07-04
CVE-2006-0725 EXP PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remote attackers to include arbitr… Patch early 6.8 medium 2.9% 2006-02-16
CVE-2006-1022 EXP PHP remote file include vulnerability in sol_menu.php in PeHePe Uyelik Sistemi (aka PeHePe MemberShip Management System) 3 allows remote attackers to… Patch early 5.0 medium 2.9% 2006-03-07
CVE-2018-1002001 EXP There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileg… Patch early 4.8 medium 2.9% 2018-12-03
CVE-2018-12234 EXP A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied input containing JavaScript is… Patch early 6.1 medium 2.9% 2018-09-06
CVE-2006-2402 EXP Buffer overflow in the changeRegistration function in servernet.cpp for Outgun 1.0.3 bot 2 and earlier allows remote attackers to change the registrat… Patch early 5.0 medium 2.9% 2006-05-16
CVE-2015-7900 EXP Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote attackers to obtain sensitive debugging information by enter… Patch early 4.3 medium 2.9% 2015-10-28
CVE-2006-0875 EXP Cross-site scripting vulnerability in ratefile.php in RunCMS 1.3a5 allows remote attackers to inject arbitrary web script or HTML via the lid paramete… Patch early 5.0 medium 2.9% 2006-02-24
CVE-2009-4154 EXP Directory traversal vulnerability in includes/feedcreator.class.php in Elxis CMS allows remote attackers to read arbitrary files via a .. (dot dot) in… Patch early 5.0 medium 2.9% 2009-12-02
CVE-2010-4120 EXP Multiple cross-site scripting (XSS) vulnerabilities in the TAM console in IBM Tivoli Access Manager for e-business 6.1.0 before 6.1.0-TIV-TAM-FP0006 a… Patch early 4.3 medium 2.9% 2010-10-28
CVE-2006-4004 EXP Directory traversal vulnerability in index.php in vbPortal 3.0.2 through 3.6.0 Beta 1, when magic_quotes_gpc is disabled, allows remote attackers to i… Patch early 6.4 medium 2.9% 2006-08-07
CVE-2006-5390 EXP PHP remote file inclusion vulnerability in includes/functions_mod_user.php in the ACP User Registration (MMW) 1.00 module for phpBB allows remote atta… Patch early 6.8 medium 2.9% 2006-10-18
CVE-2018-1513 EXP IBM Sterling B2B Integrator Standard Edition 5.2.0 through 5.2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit… Patch early 5.4 medium 2.9% 2018-07-23
CVE-2002-1837 EXP The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary dir… Patch early 5.0 medium 2.9% 2002-12-31
CVE-2004-0665 EXP csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the web server i… Patch early 5.0 medium 2.9% 2004-08-06
CVE-2004-1223 EXP The Management Agent in F-Secure Policy Manager 5.11.2810 allows remote attackers to gain sensitive information, such as the absolute path for the web… Patch early 5.0 medium 2.9% 2005-01-10
CVE-2004-1968 EXP The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by modifying the… Patch early 5.0 medium 2.9% 2004-04-26
CVE-2005-4371 EXP Acidcat 2.1.13 and earlier stores the database under the web root with insufficient access control, which allows remote attackers to obtain sensitive… Patch early 5.0 medium 2.9% 2005-12-20
CVE-2011-3501 EXP Integer overflow in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to cause a denial of service (crash) via a negative or large Content-L… Patch early 5.0 medium 2.9% 2011-09-16
CVE-2013-0126 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.19.36 allo… Patch early 6.8 medium 2.9% 2013-03-21
CVE-2011-0545 EXP Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to hijack… Patch early 6.8 medium 2.9% 2011-03-28
CVE-2023-32751 EXP Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are generated using the Amazon AWS SDK f… Patch early 5.4 medium 2.9% 2023-06-08
CVE-2017-9130 EXP The faacEncOpen function in libfaac/frame.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (invalid… Patch early 5.5 medium 2.9% 2017-06-21
CVE-2002-2191 EXP Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obtain potential sensitive inform… Patch early 5.0 medium 2.9% 2002-12-31
CVE-2006-0312 EXP create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1. Patch early 5.0 medium 2.9% 2006-01-19
← previous page 181 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt