peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,011 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2020-20139 EXP Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17. Patch early 6.1 medium 2.2% 2020-12-17
CVE-2020-20140 EXP Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17. Patch early 6.1 medium 2.2% 2020-12-17
CVE-2020-20141 EXP Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17. Patch early 6.1 medium 2.2% 2020-12-17
CVE-2004-0344 EXP Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot… Patch early 6.4 medium 2.2% 2004-11-23
CVE-2008-2018 EXP The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings delimited by '{' and '}' characte… Patch early 4.0 medium 2.2% 2008-04-30
CVE-2008-0289 EXP PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remote attackers to execute arbitr… Patch early 6.8 medium 2.2% 2008-01-16
CVE-2009-0735 EXP Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled and magic_quotes_gpc is disabled… Patch early 5.1 medium 2.2% 2009-02-25
CVE-2007-6005 EXP Unspecified vulnerability in the GpcContainer.GpcContainer.1 ActiveX control in WebEx allows remote attackers to cause a denial of service (memory acc… Patch early 4.3 medium 2.2% 2007-11-15
CVE-2010-0754 EXP Cross-site scripting (XSS) vulnerability in index.php/Special/Main/Templates in WikyBlog 1.7.2 and 1.7.3 rc2 allows remote attackers to inject arbitra… Patch early 4.3 medium 2.2% 2010-02-27
CVE-2010-4874 EXP Multiple cross-site scripting (XSS) vulnerabilities in users.php in NinkoBB 1.3 RC5 allow remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 2.2% 2011-10-07
CVE-2004-2670 EXP Multiple cross-site scripting (XSS) vulnerabilities in mod.php in eNdonesia 8.3 allow remote attackers to inject arbitrary web script or HTML via (1)… Patch early 6.8 medium 2.2% 2004-12-31
CVE-2005-3208 EXP Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execute arbitrary SQL code via (a) t… Patch early 6.8 medium 2.2% 2005-10-14
CVE-2008-7213 EXP Cross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php in MOStlyCE before 2.4… Patch early 4.3 medium 2.2% 2009-09-11
CVE-2018-9238 EXP proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter. Patch early 6.1 medium 2.2% 2018-04-04
CVE-2018-9857 EXP PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" screen). Patch early 6.1 medium 2.2% 2018-04-09
CVE-2006-4273 EXP Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML by upload… Patch early 6.8 medium 2.2% 2006-08-21
CVE-2015-8398 EXP Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 6.1 medium 2.2% 2016-04-11
CVE-2008-5621 EXP Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unautho… Patch early 6.0 medium 2.2% 2008-12-17
CVE-2008-7135 EXP toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the IsChecked… Patch early 4.3 medium 2.2% 2009-09-01
CVE-2003-1419 EXP Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript… Patch early 4.3 medium 2.2% 2003-12-31
CVE-2007-4635 EXP Yahoo! Messenger 8.1.0.209 and 8.1.0.402 allows remote attackers to cause a denial of service (application crash) via certain file-transfer packets, p… Patch early 5.0 medium 2.1% 2007-08-31
CVE-2013-7184 EXP Gretech GOM Media Player 2.2.56.5158 and earlier allows remote attackers to cause a denial of service (memory corruption) via a crafted AVI file. Patch early 4.3 medium 2.1% 2014-01-24
CVE-2012-4909 EXP Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted application. Patch early 4.3 medium 2.1% 2012-09-13
CVE-2018-6936 EXP Cross Site Scripting (XSS) exists on the D-Link DIR-600M C1 3.01 via the SSID or the name of a user account. Patch early 5.4 medium 2.1% 2018-02-21
CVE-2008-0158 EXP Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to read arbitrary files via a ..… Patch early 5.0 medium 2.1% 2008-01-09
CVE-2022-41413 EXP perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted input into… Patch early 4.3 medium 2.1% 2022-11-30
CVE-2006-1820 EXP Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id paramete… Patch early 5.8 medium 2.1% 2006-04-18
CVE-2021-3298 EXP Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?a… Patch early 5.4 medium 2.1% 2021-01-29
CVE-2006-6390 EXP Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow… Patch early 6.8 medium 2.1% 2006-12-08
CVE-2006-1697 EXP Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) Yo… Patch early 4.3 medium 2.1% 2006-04-11
← previous page 229 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt