peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,984 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-2542 EXP Invision Power Board (IPB) 1.0.3 allows remote attackers to inject arbitrary web script or HTML via an attachment, which is automatically downloaded a… Patch early 5.0 medium 2.2% 2005-08-10
CVE-2008-6539 EXP Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitrary administrators and inject a… Patch early 6.5 medium 2.2% 2009-03-30
CVE-2009-2780 EXP Multiple cross-site scripting (XSS) vulnerabilities in 68 Classifieds 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) ca… Patch early 4.3 medium 2.2% 2009-08-17
CVE-2009-4433 EXP Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 and earlier allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 2.2% 2009-12-28
CVE-2017-16567 EXP Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. This vulnerability allows remot… Patch early 5.4 medium 2.2% 2017-11-10
CVE-2007-0098 EXP Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include… Patch early 6.8 medium 2.2% 2007-01-05
CVE-2007-6503 EXP Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arbitrary pla… Patch early 5.5 medium 2.2% 2007-12-20
CVE-2009-2337 EXP SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when magic_quotes_gpc is disabled, all… Patch early 6.8 medium 2.2% 2009-07-07
CVE-2006-2798 EXP Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to inject arbitrary web script or HTML via th… Patch early 6.8 medium 2.2% 2006-06-03
CVE-2005-3152 EXP Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the redir para… Patch early 4.3 medium 2.2% 2005-10-05
CVE-2004-1823 EXP Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 allows remote attackers to inject arbitrary web s… Patch early 4.3 medium 2.2% 2004-12-31
CVE-2004-2509 EXP Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads 6.2.3 and 6.5 allow remote at… Patch early 4.3 medium 2.2% 2004-12-31
CVE-2008-2028 EXP miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via a direct request to the glang… Patch early 4.3 medium 2.2% 2008-04-30
CVE-2013-3299 EXP RealNetworks RealPlayer 16.0.2.32 and earlier allows remote attackers to cause a denial of service (resource consumption or application crash) via an… Patch early 4.3 medium 2.2% 2013-07-06
CVE-2007-3009 EXP Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration d… Patch early 4.3 medium 2.2% 2007-06-04
CVE-2006-4754 EXP Cross-site scripting (XSS) vulnerability in index.php in PHProg before 1.1 allows remote attackers to inject arbitrary web script or HTML via the albu… Patch early 6.8 medium 2.2% 2006-09-13
CVE-2008-6084 EXP Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code… Patch early 6.8 medium 2.2% 2009-02-06
CVE-2022-47870 EXP A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows remote attackers to inject arbi… Patch early 6.1 medium 2.2% 2023-04-04
CVE-2008-1680 EXP PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain configuration information via a direct request to maintenance/index.php, which reveals set… Patch early 5.0 medium 2.2% 2008-04-04
CVE-2008-5951 EXP ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… Patch early 5.0 medium 2.2% 2009-01-23
CVE-2008-6057 EXP Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, which allows remote attackers to o… Patch early 5.0 medium 2.2% 2009-02-04
CVE-2008-6147 EXP ForumApp 3.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database vi… Patch early 5.0 medium 2.2% 2009-02-16
CVE-2008-6321 EXP CF Shopkart 5.2.2 stores cfshopkart52.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive infor… Patch early 5.0 medium 2.2% 2009-02-27
CVE-2008-6388 EXP Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downl… Patch early 5.0 medium 2.2% 2009-03-02
CVE-2008-6493 EXP Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, which allows remote attackers to… Patch early 5.0 medium 2.2% 2009-03-20
CVE-2008-6494 EXP ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a data… Patch early 5.0 medium 2.2% 2009-03-20
CVE-2008-6580 EXP The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access control, which allows remote attac… Patch early 5.0 medium 2.2% 2009-04-02
CVE-2008-7063 EXP Ocean12 FAQ Manager Pro stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a databas… Patch early 5.0 medium 2.2% 2009-08-25
CVE-2009-2602 EXP R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to… Patch early 5.0 medium 2.2% 2009-07-27
CVE-2009-2606 EXP ASP Football Pool 2.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… Patch early 5.0 medium 2.2% 2009-07-27
← previous page 224 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt