peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,941 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-6771 EXP Multiple PHP remote file inclusion vulnerabilities in Irokez CMS 0.7.1 and earlier, when register_globals is enabled, allow remote attackers to execut… Patch early 6.8 medium 2.3% 2006-12-27
CVE-2006-2363 EXP SQL injection vulnerability in the weblinks option (weblinks.html.php) in Limbo CMS allows remote attackers to execute arbitrary SQL commands via the… Patch early 5.1 medium 2.3% 2006-05-15
CVE-2008-2279 EXP Freelance Auction Script 1.0 stores user passwords in plaintext in the tbl_users table, which allows attackers to gain privileges by reading the table… Patch early 5.0 medium 2.3% 2008-05-16
CVE-2003-1468 EXP The Web_Links module in PHP-Nuke 6.0 through 6.5 final allows remote attackers to obtain the full web server path via an invalid cid parameter that is… Patch early 4.3 medium 2.3% 2003-12-31
CVE-2014-1459 EXP SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administrators to execute arbitrary SQL… Patch early 6.5 medium 2.3% 2014-02-11
CVE-2013-5316 EXP Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for requests t… Patch early 6.8 medium 2.3% 2013-08-20
CVE-2014-4155 EXP Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the au… Patch early 6.8 medium 2.3% 2014-06-19
CVE-2014-6409 EXP Cross-site request forgery (CSRF) vulnerability in M/Monit 3.3.2 and earlier allows remote attackers to hijack the authentication of administrators fo… Patch early 6.8 medium 2.3% 2014-10-06
CVE-2014-7190 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Openfiler 2.99.1 allow remote attackers to hijack the authentication of administrators f… Patch early 6.8 medium 2.3% 2014-09-30
CVE-2014-8953 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Php Scriptlerim Who's Who script allow remote attackers to hijack the authentication of… Patch early 6.8 medium 2.3% 2014-11-17
CVE-2011-5284 EXP Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothwall Express 3.1 and 3.0 SP3 an… Patch early 6.8 medium 2.3% 2014-12-31
CVE-2012-1978 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Simple PHP Agenda 2.2.8 and earlier allow remote attackers to hijack the authentication… Patch early 6.8 medium 2.3% 2015-05-21
CVE-2008-1783 EXP Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/DeleteUser.php… Patch early 6.4 medium 2.3% 2008-04-15
CVE-2000-1069 EXP pollit.cgi in Poll It 2.01 and earlier allows remote attackers to access administrative functions without knowing the real password by specifying the… Patch early 6.4 medium 2.3% 2000-12-11
CVE-2005-2157 EXP PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path paramete… Patch early 5.0 medium 2.3% 2005-07-06
CVE-2008-1760 EXP Multiple PHP remote file inclusion vulnerabilities in Blogator-script before 1.01 allow remote attackers to execute arbitrary PHP code via a URL in th… Patch early 6.8 medium 2.3% 2008-04-12
CVE-2023-0943 EXP A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0. This issue affects the function… Patch early 4.7 medium 2.3% 2023-02-21
CVE-2008-4454 EXP Directory traversal vulnerability in EKINdesigns MySQL Quick Admin 1.5.5 allows remote attackers to read and execute arbitrary files via a .. (dot dot… Patch early 6.8 medium 2.3% 2008-10-06
CVE-2014-10001 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication… Patch early 6.8 medium 2.3% 2015-01-13
CVE-2003-1410 EXP PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary… Patch early 6.8 medium 2.3% 2003-12-31
CVE-2017-7472 EXP The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumption) via a series of KEY_REQKEY_… Patch early 5.5 medium 2.3% 2017-05-11
CVE-2007-6653 EXP Directory traversal vulnerability in download.php in Mihalism Multi Host 2.0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in t… Patch early 5.0 medium 2.3% 2008-01-04
CVE-2009-2733 EXP Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the… Patch early 4.3 medium 2.3% 2009-10-16
CVE-2018-15596 EXP An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://local… Patch early 6.1 medium 2.3% 2018-08-28
CVE-2019-10685 EXP A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0. Patch early 6.1 medium 2.3% 2019-05-24
CVE-2019-9647 EXP Gila CMS 1.9.1 has XSS. Patch early 6.1 medium 2.3% 2019-06-05
CVE-2007-5312 EXP Cross-site scripting (XSS) vulnerability in TorrentTrader Classic 1.07 allows remote attackers to inject arbitrary web script or HTML via the (1) colo… Patch early 4.3 medium 2.3% 2007-10-09
CVE-2018-11404 EXP DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter. Patch early 6.1 medium 2.3% 2018-05-24
CVE-2009-2587 EXP Multiple cross-site scripting (XSS) vulnerabilities in DragDropCart allow remote attackers to inject arbitrary web script or HTML via the (1) sid para… Patch early 4.3 medium 2.3% 2009-07-24
CVE-2009-4548 EXP Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the catego… Patch early 4.3 medium 2.3% 2010-01-04
← previous page 222 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt