peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,893 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-4115 EXP Multiple cross-site scripting (XSS) vulnerabilities in IT!CMS (itcms) 0.2 allow remote attackers to inject arbitrary web script or HTML via the wndtit… Patch early 4.3 medium 2.4% 2007-07-31
CVE-2010-1497 EXP Cross-site scripting (XSS) vulnerability in download_proc.php in dl_stats before 2.0 allows remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 2.4% 2010-04-23
CVE-2006-5830 EXP Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to inject arbitrary… Patch early 6.8 medium 2.4% 2006-11-10
CVE-2025-54589 EXP Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results usin… Patch early 6.3 medium 2.4% 2025-07-31
CVE-2002-2134 EXP haut.php in PEEL 1.0b allows remote attackers to execute arbitrary PHP code by modifying the dirroot parameter to reference a URL on a remote web serv… Patch early 5.0 medium 2.4% 2002-12-31
CVE-2002-2169 EXP Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activ… Patch early 5.0 medium 2.4% 2002-12-31
CVE-2007-5314 EXP PHP remote file inclusion vulnerability in system/funcs/xkurl.php in xKiosk WEB 3.0.1i, when register_globals is enabled, allows remote attackers to e… Patch early 6.8 medium 2.4% 2007-10-09
CVE-2010-1216 EXP PHP remote file inclusion vulnerability in templates/template.php in notsoPureEdit 1.4.1 and earlier, when register_globals is enabled, allows remote… Patch early 6.8 medium 2.4% 2010-03-30
CVE-2007-3681 EXP The IOCTL 9031 (BIOCGSTATS) handler in the NPF.SYS device driver in WinPcap before 4.0.1 allows local users to overwrite memory and execute arbitrary… Patch early 6.6 medium 2.4% 2007-07-11
CVE-2006-5625 EXP PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Management System (WCMS) 4.1 and earli… Patch early 5.1 medium 2.4% 2006-10-31
CVE-2005-1597 EXP Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers… Patch early 4.3 medium 2.4% 2005-05-16
CVE-2012-5350 EXP SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with certain permissions to execut… Patch early 6.0 medium 2.4% 2012-10-09
CVE-2003-0376 EXP Buffer overflow in Eudora 5.2.1 allows remote attackers to cause a denial of service (crash and failed restart) and possibly execute arbitrary code vi… Patch early 5.0 medium 2.4% 2003-06-16
CVE-2006-6756 EXP The code function in install.fct.php in Ixprim 1.2 produces a guessable value of the confidential IXP_CODE in mainfile.php, which might allow remote a… Patch early 5.1 medium 2.4% 2006-12-27
CVE-2003-1535 EXP Justice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the path in an er… Patch early 5.0 medium 2.4% 2003-12-31
CVE-2007-1475 EXP Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-… Patch early 5.4 medium 2.4% 2007-03-16
CVE-2008-0840 EXP Directory traversal vulnerability in view_member.php in Public Warehouse LightBlog 9.6 allows remote attackers to include and execute arbitrary local… Patch early 4.4 medium 2.4% 2008-02-20
CVE-2005-0477 EXP Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script v… Patch early 4.3 medium 2.4% 2005-03-30
CVE-2007-1515 EXP Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP H3 4.1.3, and possibly earlier, allow remote attackers to inject arbitrary web script… Patch early 4.3 medium 2.4% 2007-03-20
CVE-2010-3480 EXP Directory traversal vulnerability in index.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include and… Patch early 6.8 medium 2.4% 2010-09-22
CVE-2011-4519 EXP Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a craft… Patch early 4.3 medium 2.4% 2013-05-23
CVE-2011-4520 EXP Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafte… Patch early 4.3 medium 2.4% 2013-05-23
CVE-2007-6475 EXP Multiple directory traversal vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot)… Patch early 6.4 medium 2.4% 2007-12-20
CVE-2007-6621 EXP Directory traversal vulnerability in joovili.images.php in Joovili 3.0.0 through 3.0.6 allows remote attackers to read arbitrary files via a .. (dot d… Patch early 6.4 medium 2.4% 2008-01-04
CVE-2002-2399 EXP Directory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file… Patch early 6.4 medium 2.4% 2002-12-31
CVE-2007-1104 EXP PHP remote file inclusion vulnerability in top.php in PHP Module Implementation (PHP-MIP) 0.1 allows remote attackers to execute arbitrary PHP code vi… Patch early 4.3 medium 2.4% 2007-02-26
CVE-2007-5140 EXP PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in IntegraMOD Nederland 1.4.2 allows remote attackers to execute arbitra… Patch early 6.8 medium 2.4% 2007-09-28
CVE-2007-5157 EXP PHP remote file inclusion vulnerability in phfito-post.php in Alex Kocharin PHP Fidonet Tosser (PhFiTo) 1.3.0 in phpFidoNode allows remote attackers t… Patch early 6.8 medium 2.4% 2007-10-01
CVE-2007-5780 EXP PHP remote file inclusion vulnerability in pub/pub08_comments.php in teatro 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 6.8 medium 2.4% 2007-11-01
CVE-2009-0853 EXP login.php in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allows remote attackers to bypass authentication and obtain administrative access via s… Patch early 6.8 medium 2.4% 2009-03-09
← previous page 214 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt