peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,829 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-1470 EXP CRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTTP Response Splitting attacks t… Patch early 5.0 medium 2.4% 2004-12-31
CVE-2004-1687 EXP CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks to modify exp… Patch early 5.0 medium 2.4% 2004-09-16
CVE-2005-0795 EXP HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified v… Patch early 5.0 medium 2.4% 2005-03-14
CVE-2006-1326 EXP Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board 2.0.4 allow remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 2.4% 2006-03-21
CVE-2013-1471 EXP Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (I… Patch early 4.3 medium 2.4% 2013-02-04
CVE-2008-4662 EXP Directory traversal vulnerability in admin.php in LokiCMS 0.3.4, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arb… Patch early 6.8 medium 2.4% 2008-10-22
CVE-2006-2682 EXP PHP remote file inclusion vulnerability in BE_config.php in Back-End CMS 0.7.2.1 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 6.4 medium 2.4% 2006-05-31
CVE-2006-5703 EXP Cross-site scripting (XSS) vulnerability in tiki-featured_link.php in Tikiwiki 1.9.5 allows remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 2.4% 2006-11-04
CVE-2006-5115 EXP Directory traversal vulnerability in kgcall.php in KGB 1.87 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in… Patch early 5.1 medium 2.4% 2006-10-03
CVE-2007-1105 EXP PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka phpBB Extreme) 3.0.1 allows remote attackers to execute arbitrary PHP c… Patch early 5.0 medium 2.4% 2007-02-26
CVE-2012-2437 EXP cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via t… Patch early 5.0 medium 2.4% 2012-11-26
CVE-2009-4108 EXP XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (crash) by uploading or creating a large number of fi… Patch early 4.0 medium 2.4% 2009-11-29
CVE-2006-6888 EXP P-News 1.16 and 1.17 store sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admi… Patch early 5.0 medium 2.4% 2006-12-31
CVE-2006-6891 EXP Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the adm… Patch early 5.0 medium 2.4% 2006-12-31
CVE-2006-5728 EXP XM Easy Personal FTP Server 5.2.1 and earlier allows remote authenticated users to cause a denial of service via a long argument to the NLST command,… Patch early 4.0 medium 2.4% 2006-11-06
CVE-2008-1711 EXP Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which allows context-dependent attack… Patch early 5.0 medium 2.4% 2008-04-09
CVE-2017-14618 EXP Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.8 medium 2.4% 2017-09-20
CVE-2007-4640 EXP Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload and execute arbitrary PHP files… Patch early 6.4 medium 2.4% 2007-08-31
CVE-2012-1308 EXP Cross-site request forgery (CSRF) vulnerability in redpass.cgi in D-Link DSL-2640B Firmware EU_4.00 allows remote attackers to hijack the authenticati… Patch early 6.8 medium 2.4% 2012-10-08
CVE-2004-0615 EXP Cross-site scripting (XSS) vulnerability in D-Link DI-614+ SOHO router running firmware 2.30, and DI-704 SOHO router running firmware 2.60B2, and DI-6… Patch early 5.1 medium 2.4% 2004-12-06
CVE-2003-1512 EXP Buffer overflow in mIRC 6.1 and 6.11 allows remote attackers to cause a denial of service (crash) via a long DCC SEND request. Patch early 5.0 medium 2.4% 2003-12-31
CVE-2007-2574 EXP Directory traversal vulnerability in index.php in Archangel Weblog 0.90.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the i… Patch early 5.0 medium 2.4% 2007-05-09
CVE-2008-6765 EXP ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a modified cart_name parameter. Patch early 5.0 medium 2.4% 2009-04-28
CVE-2009-2332 EXP CMS Chainuk 1.2 and earlier allows remote attackers to obtain sensitive information via (1) a crafted id parameter to index.php or (2) a nonexistent f… Patch early 5.0 medium 2.4% 2009-07-05
CVE-2009-4466 EXP DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a crafted page parameter to misc.php, which reveals the installation path in… Patch early 5.0 medium 2.4% 2009-12-30
CVE-2015-6944 EXP Cross-site request forgery (CSRF) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to hijack the authentication of users for req… Patch early 6.8 medium 2.4% 2015-09-15
CVE-2018-10366 EXP An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the name field. Patch early 6.1 medium 2.4% 2018-04-25
CVE-2016-1596 EXP Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary… Patch early 5.4 medium 2.4% 2016-04-22
CVE-2009-2161 EXP Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remot… Patch early 5.1 medium 2.4% 2009-06-22
CVE-1999-0393 EXP Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers. Patch early 5.0 medium 2.4% 1999-01-01
← previous page 211 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt