peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,585 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2000-0397 EXP The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's ema… Patch early 5.0 medium 2.7% 2000-05-15
CVE-2005-2021 EXP Cross-site scripting (XSS) vulnerability in cPanel 9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the user paramet… Patch early 4.3 medium 2.7% 2005-06-20
CVE-2005-2326 EXP Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the yr paramet… Patch early 4.3 medium 2.7% 2005-07-19
CVE-2002-1943 EXP SafeTP 1.46, when network address translation (NAT) is being used, leaks the internal IP address of the FTP server in a response to a passive mode (PA… Patch early 5.0 medium 2.7% 2002-12-31
CVE-2005-1620 EXP Cross-site scripting (XSS) vulnerability in Skull-Splitter Guestbook 1.0, 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 2.7% 2005-05-16
CVE-2006-6340 EXP keystone.exe in nVIDIA nView allows attackers to cause a denial of service via a long command line argument. NOTE: it is not clear whether this issue… Patch early 5.0 medium 2.7% 2006-12-07
CVE-2007-1106 EXP PHP remote file inclusion vulnerability in includes/functions_nomoketos_rules.php in the NoMoKeTos Rules 0.0.1 module for phpBB allows remote attacker… Patch early 6.8 medium 2.7% 2007-02-26
CVE-2006-3361 EXP PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary… Patch early 5.1 medium 2.7% 2006-07-06
CVE-2009-1975 EXP Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality, integrity, and… Patch early 6.8 medium 2.7% 2009-07-14
CVE-2008-1557 EXP BolinOS 4.6.1 allows remote attackers to obtain sensitive information via a direct request to system/actionspages/_b/contentFiles/gBphpInfo.php, which… Patch early 5.0 medium 2.7% 2008-03-31
CVE-2008-5218 EXP ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext p… Patch early 5.0 medium 2.7% 2008-11-25
CVE-2008-5560 EXP PostEcards stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database fi… Patch early 5.0 medium 2.7% 2008-12-15
CVE-2007-3714 EXP Directory traversal vulnerability in Ada Image Server (ImgSvr) 0.6.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the templat… Patch early 5.0 medium 2.7% 2007-07-11
CVE-1999-0975 EXP The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and m… Patch early 4.6 medium 2.7% 1999-12-10
CVE-2006-1367 EXP The Motorola PEBL U6 08.83.76R, the Motorola V600, and possibly the Motorola E398 and other Motorola P2K-based phones does not require pairing for a c… Patch early 6.8 medium 2.7% 2006-03-23
CVE-2014-9099 EXP Cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to hijack the authentication… Patch early 6.8 medium 2.7% 2014-11-26
CVE-2007-4092 EXP Directory traversal vulnerability in index.php in iFoto 1.0.1 and earlier allows remote attackers to list arbitrary directories, and possibly download… Patch early 5.0 medium 2.7% 2007-07-30
CVE-2006-0894 EXP Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the html… Patch early 4.3 medium 2.7% 2006-02-25
CVE-2005-3514 EXP Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Forum script allow remote attackers to inject arbitrary web script or HTML via the for… Patch early 4.3 medium 2.7% 2005-11-06
CVE-2003-1412 EXP PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code… Patch early 6.8 medium 2.7% 2003-12-31
CVE-2020-28092 EXP PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&m=Task&a=m… Patch early 6.1 medium 2.7% 2020-11-17
CVE-2023-26692 EXP ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Management System (ZBBS) 4.14k is vuln… Patch early 6.1 medium 2.7% 2023-03-30
CVE-2004-2246 EXP Cross-site scripting (XSS) vulnerability in Goollery before 0.04b allows remote attackers to inject arbitrary HTML or web script via the conversation_… Patch early 4.3 medium 2.7% 2004-12-31
CVE-2007-2647 EXP Static code injection vulnerability in admin/admin_configuration.php in Monalbum 0.8.7 allows remote authenticated users to inject arbitrary PHP code… Patch early 6.5 medium 2.7% 2007-05-14
CVE-2014-3991 EXP Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1… Patch early 4.3 medium 2.7% 2014-07-11
CVE-2010-0799 EXP Directory traversal vulnerability in misc/tell_a_friend/tell.php in phpunity.newsmanager allows remote attackers to read arbitrary files via a .. (dot… Patch early 5.0 medium 2.7% 2010-03-02
CVE-2008-2215 EXP Multiple directory traversal vulnerabilities in Project-Based Calendaring System (PBCS) 0.7.1-1 allow remote attackers to read arbitrary files via a .… Patch early 5.0 medium 2.7% 2008-05-14
CVE-2008-2350 EXP Directory traversal vulnerability in highlight.php in bcoos 1.0.9 through 1.0.13 allows remote attackers to read arbitrary files via (1) .. (dot dot)… Patch early 5.0 medium 2.7% 2008-05-20
CVE-2008-5861 EXP Directory traversal vulnerability in source.php in FreeLyrics 1.0 allows remote attackers to read arbitrary files via directory traversal sequences in… Patch early 5.0 medium 2.7% 2009-01-06
CVE-2018-9137 EXP Open-AudIT before 2.2 has CSV Injection. Patch early 6.8 medium 2.7% 2018-04-19
← previous page 195 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt