peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,708 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-9129 EXP The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (larg… Patch early 5.5 medium 2.5% 2017-06-21
CVE-2005-1118 EXP Cross-site scripting (XSS) vulnerability in IISWebAgentIF.dll in the RSA Authentication Agent for Web 5.2 allows remote attackers to inject arbitrary… Patch early 4.3 medium 2.5% 2005-04-14
CVE-2012-5917 EXP SnackAmp 3.1.3 allows remote attackers to cause a denial of service (application crash) via a long string in an aiff file. Patch early 4.3 medium 2.5% 2012-11-17
CVE-2017-17649 EXP Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter. Patch early 6.1 medium 2.5% 2017-12-18
CVE-2021-3186 EXP A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_multi allows remote attackers t… Patch early 5.4 medium 2.5% 2021-01-26
CVE-2003-1409 EXP TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter to (1) in.php or (2) out.php, w… Patch early 5.0 medium 2.5% 2003-12-31
CVE-2014-5101 EXP Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) TPL_name,… Patch early 4.3 medium 2.5% 2014-07-25
CVE-2004-1754 EXP The DNS proxy (DNSd) for multiple Symantec Gateway Security products allows remote attackers to poison the DNS cache via a malicious DNS server query… Patch early 5.0 medium 2.5% 2004-06-15
CVE-2012-2436 EXP Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary web script or HTML via (1) an… Patch early 4.3 medium 2.5% 2012-05-27
CVE-2014-2089 EXP ILIAS 4.4.1 allows remote attackers to execute arbitrary PHP code via an e-mail attachment that leads to creation of a .php file with a certain client… Patch early 6.8 medium 2.5% 2014-03-02
CVE-2012-2995 EXP Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allow remote attackers to i… Patch early 4.3 medium 2.5% 2012-09-17
CVE-2007-3096 EXP Directory traversal vulnerability in login.php in PBLang (PBL) 4.67.16.a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to in… Patch early 6.8 medium 2.5% 2007-06-06
CVE-2007-1478 EXP download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter. Patch early 5.0 medium 2.5% 2007-03-16
CVE-2007-1698 EXP download.php in Philex 0.2.3 and earlier allows remote attackers to read arbitrary files and source code, and obtain sensitive information via the fil… Patch early 5.0 medium 2.5% 2007-03-27
CVE-2009-2134 EXP pivot/tb.php in Pivot 1.40.4 and 1.40.7 allows remote attackers to obtain sensitive information via an invalid url parameter, which reveals the instal… Patch early 5.0 medium 2.5% 2009-06-19
CVE-2010-1888 EXP Race condition in the kernel in Microsoft Windows XP SP3 allows local users to gain privileges via vectors involving thread creation, aka "Windows Ker… Patch early 6.8 medium 2.5% 2010-08-11
CVE-2006-1223 EXP Cross-site scripting (XSS) vulnerability in Jupiter Content Manager 1.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 2.5% 2006-03-14
CVE-2007-3982 EXP Absolute path traversal vulnerability in the Data Dynamics ActiveReport (ActiveReports) ActiveX control in actrpt2.dll 2.5 and earlier allows remote a… Patch early 5.0 medium 2.5% 2007-07-25
CVE-2010-4608 EXP Habari 0.6.5 allows remote attackers to obtain sensitive information via a direct request to (1) header.php and (2) comments_items.php in system/admin… Patch early 5.0 medium 2.5% 2010-12-29
CVE-2010-4611 EXP Html-edit CMS 3.1.8 allows remote attackers to obtain sensitive information via a direct request to (1) pages.php and (2) menu.php in includes/core_fi… Patch early 5.0 medium 2.5% 2010-12-29
CVE-2012-3848 EXP Multiple cross-site scripting (XSS) vulnerabilities in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allow remot… Patch early 4.3 medium 2.5% 2012-07-31
CVE-2006-0470 EXP Cross-site scripting (XSS) vulnerability in search.php in MyBulletinBoard (MyBB) 1.02 allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 2.5% 2006-01-31
CVE-2016-3670 EXP Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1 allows remote attackers to in… Patch early 6.1 medium 2.5% 2016-06-13
CVE-2000-0075 EXP Super Mail Transfer Package (SMTP), later called MsgCore, has a memory leak which allows remote attackers to cause a denial of service by repeating mu… Patch early 5.0 medium 2.5% 2000-01-13
CVE-2010-1735 EXP The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service… Patch early 4.9 medium 2.5% 2010-05-06
CVE-2006-1661 EXP Multiple cross-site scripting (XSS) vulnerabilities in SKForum 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (… Patch early 6.8 medium 2.5% 2006-04-07
CVE-2017-7950 EXP Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX file. Patch early 5.5 medium 2.5% 2017-07-07
CVE-2010-1065 EXP Lebisoft Ziyaretci Defteri 7.4 and 7.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers… Patch early 5.0 medium 2.5% 2010-03-23
CVE-2010-1067 EXP E-membres 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database v… Patch early 5.0 medium 2.5% 2010-03-23
CVE-2002-2349 EXP phpinfo.php in phpBBmod 1.3.3 executes the phpinfo function, which allows remote attackers to obtain sensitive environment information. Patch early 5.0 medium 2.5% 2002-12-31
← previous page 207 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt