peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,964 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-2275 EXP Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary we… Patch early 4.3 medium 2.9% 2010-06-15
CVE-2020-12706 EXP Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter… Patch early 5.4 medium 2.9% 2020-05-07
CVE-2003-0763 EXP Cross-site scripting (XSS) vulnerability in Escapade Scripting Engine (ESP) allows remote attackers to inject arbitrary script via the method paramete… Patch early 4.3 medium 2.9% 2003-09-17
CVE-2006-7133 EXP Directory traversal vulnerability in upload/bin/download.php in Upload Tool for PHP 1.0 allows remote attackers to read arbitrary files via (1) ".." s… Patch early 5.0 medium 2.9% 2007-03-06
CVE-2007-1124 EXP Directory traversal vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to read arbitrary files via a .. (dot dot)… Patch early 5.0 medium 2.9% 2007-02-27
CVE-2007-5484 EXP Directory traversal vulnerability in wxis.exe in WWWISIS 7.1 allows local users to read arbitrary files via a .. (dot dot) in the IsisScript parameter… Patch early 5.0 medium 2.9% 2007-10-16
CVE-2006-4215 EXP PHP remote file inclusion vulnerability in index.php in Zen Cart 1.3.0.2 and earlier, when register_globals is enabled, allows remote attackers to exe… Patch early 5.1 medium 2.9% 2006-08-17
CVE-2006-0735 EXP Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom HTML::BBCode 1.04 and earlier, as used in products such as My Blog before 1.65, allow… Patch early 4.3 medium 2.9% 2006-02-16
CVE-2004-1235 EXP Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10… Patch early 6.2 medium 2.9% 2005-04-14
CVE-2003-1550 EXP XOOPS 2.0, and possibly earlier versions, allows remote attackers to obtain sensitive information via an invalid xoopsOption parameter, which reveals… Patch early 5.0 medium 2.9% 2003-12-31
CVE-2008-6126 EXP Multiple directory traversal vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the… Patch early 5.0 medium 2.9% 2009-02-13
CVE-2009-3828 EXP The web interface for Everfocus EDR1600 DVR allows remote attackers to bypass authentication and access live cams via certain vectors. Patch early 5.0 medium 2.9% 2009-10-30
CVE-1999-0700 EXP Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file. Patch early 6.2 medium 2.9% 1999-07-29
CVE-2013-6043 EXP The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on whether the u… Patch early 5.0 medium 2.9% 2014-12-27
CVE-2007-6055 EXP Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Portal 4.1.0 and 4.1.1 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 2.9% 2007-11-20
CVE-2009-1624 EXP Directory traversal vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the show p… Patch early 5.0 medium 2.9% 2009-05-12
CVE-2013-6797 EXP Cross-site request forgery (CSRF) vulnerability in bluewrench-video-widget.php in the Blue Wrench Video Widget plugin before 2.0.0 for WordPress allow… Patch early 6.8 medium 2.9% 2013-11-19
CVE-2010-2631 EXP LibTIFF 3.9.0 ignores tags in certain situations during the first stage of TIFF file processing and does not properly handle this during the second st… Patch early 4.3 medium 2.9% 2010-07-06
CVE-2017-2516 EXP An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" component. It allows attackers to… Patch early 5.0 medium 2.9% 2017-05-22
CVE-2006-2490 EXP Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other versions before 2.2.3.18 for M… Patch early 4.3 medium 2.9% 2006-05-19
CVE-2008-5335 EXP SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows remote attackers to execute ar… Patch early 6.8 medium 2.9% 2008-12-05
CVE-2007-3459 EXP A certain ActiveX control in Avaxswf.dll 1.0.0.1 in Civitech Avax Vector 1.3 allows remote attackers to create or overwrite arbitrary files via a full… Patch early 6.4 medium 2.9% 2007-06-27
CVE-2006-2002 EXP PHP remote file inclusion vulnerability in stats.php in MyGamingLadder 7.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir[… Patch early 5.0 medium 2.9% 2006-04-25
CVE-2009-1615 EXP Unrestricted file upload vulnerability in Leap CMS 0.1.4 allows remote attackers to execute arbitrary code by uploading a file with an executable exte… Patch early 6.8 medium 2.9% 2009-05-11
CVE-2007-0118 EXP Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an absolute pathname in the file pa… Patch early 4.3 medium 2.9% 2007-01-09
CVE-2008-1537 EXP Directory traversal vulnerability in pb_inc/admincenter/index.php in PowerScripts PowerBook 1.21 allows remote attackers to include and execute arbitr… Patch early 6.8 medium 2.9% 2008-03-28
CVE-2007-3633 EXP Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to creat… Patch early 6.4 medium 2.9% 2007-07-10
CVE-2007-6133 EXP PHP remote file inclusion vulnerability in admin/kfm/initialise.php in DevMass Shopping Cart 1.0 and earlier allows remote attackers to execute arbitr… Patch early 5.8 medium 2.9% 2007-11-27
CVE-2008-1478 EXP Home FTP Server 1.4.5.89 allows remote attackers to cause a denial of service (crash) by opening a FTP passive mode connection, then closing the origi… Patch early 5.0 medium 2.9% 2008-03-24
CVE-2009-0828 EXP QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain sensitive database informatio… Patch early 5.0 medium 2.9% 2009-03-05
← previous page 184 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt