peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,011 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-6153 EXP Multiple cross-site scripting (XSS) vulnerabilities in vSpin.net Classified System 2004 allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 2.1% 2006-11-28
CVE-2004-1640 EXP Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 0.94 and 1.0 allow remote attackers to execute arbitrary web script and HTML via the (1)… Patch early 4.3 medium 2.1% 2004-08-28
CVE-2005-3308 EXP Multiple cross-site scripting (XSS) vulnerabilities in Zomplog 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (… Patch early 4.3 medium 2.1% 2005-10-26
CVE-2006-5958 EXP Multiple cross-site scripting (XSS) vulnerabilities in INFINICART allow remote attackers to inject arbitrary web script or HTML via the (1) username a… Patch early 6.8 medium 2.1% 2006-11-17
CVE-2006-6479 EXP Multiple cross-site scripting (XSS) vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the email… Patch early 6.8 medium 2.1% 2006-12-12
CVE-2006-6520 EXP Multiple cross-site scripting (XSS) vulnerabilities in Messageriescripthp 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1… Patch early 6.8 medium 2.1% 2006-12-14
CVE-2007-0119 EXP Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script or HTML via the plain paramet… Patch early 6.8 medium 2.1% 2007-01-09
CVE-2008-5274 EXP Todd Woolums ASP News Management 2.2 allows remote attackers to obtain news items via a direct request to (1) rss.asp, (2) viewheadings.asp, or (3) vi… Patch early 5.0 medium 2.1% 2008-11-28
CVE-2008-1606 EXP Multiple directory traversal vulnerabilities in Elastic Path (EP) 4.1 and 4.1.1 allow remote attackers to (1) download arbitrary files via a .. (dot d… Patch early 6.0 medium 2.1% 2008-04-01
CVE-2006-4836 EXP SQL injection vulnerability in login.php in DCP-Portal SE 6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. N… Patch early 5.1 medium 2.1% 2006-09-15
CVE-2008-4210 EXP fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users t… Patch early 4.6 medium 2.1% 2008-09-29
CVE-2016-0400 EXP CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 all… Patch early 6.1 medium 2.1% 2016-07-02
CVE-2021-37391 EXP A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.p… Patch early 5.4 medium 2.1% 2021-08-10
CVE-2006-6925 EXP Multiple cross-site scripting (XSS) vulnerabilities in bitweaver 1.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (… Patch early 6.8 medium 2.1% 2007-01-13
CVE-2006-2294 EXP Cross-site scripting (XSS) vulnerability in Dynamic Galerie 1.0 allows remote attackers to inject arbitrary web script or HTML via the pfad parameter… Patch early 6.8 medium 2.1% 2006-05-10
CVE-2006-4293 EXP Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script or HTML via the (1) dir paramet… Patch early 4.3 medium 2.1% 2006-08-22
CVE-2005-4209 EXP WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subj… Patch early 4.3 medium 2.1% 2005-12-13
CVE-2013-5039 EXP Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote attackers to h… Patch early 5.4 medium 2.1% 2013-12-30
CVE-2006-4563 EXP Cross-site scripting (XSS) vulnerability in the MyHeadlines before 4.3.2 module for PHP-Nuke allows remote attackers to inject arbitrary web script or… Patch early 6.8 medium 2.1% 2006-09-06
CVE-2007-6539 EXP PHP local file inclusion vulnerability in index.php in IDevspot iSupport 1.8 allows remote attackers to include local files via the include_file param… Patch early 6.8 medium 2.1% 2007-12-27
CVE-2006-6928 EXP Multiple cross-site scripting (XSS) vulnerabilities in Rialto 1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parame… Patch early 6.8 medium 2.1% 2007-01-13
CVE-2007-1212 EXP Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local u… Patch early 6.6 medium 2.1% 2007-04-04
CVE-2008-0210 EXP Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers… Patch early 6.4 medium 2.1% 2008-01-10
CVE-2006-6764 EXP PHP remote file inclusion vulnerability in authenticate.php in Keep It Simple Guest Book (KISGB), when executing PHP through CGI, allows remote attack… Patch early 6.8 medium 2.1% 2006-12-27
CVE-2006-6765 EXP Multiple PHP file inclusion vulnerabilities in src/admin/pt_upload.php in Pagetool 1.07 allow remote attackers to execute arbitrary PHP code via (1) a… Patch early 6.8 medium 2.1% 2006-12-27
CVE-2006-6774 EXP PHP remote file inclusion vulnerability in socios/maquetacion_socio.php (members/maquetacion_member.php) in Ciberia Content Federator 1.0 allows remot… Patch early 6.8 medium 2.1% 2006-12-27
CVE-2006-6796 EXP PHP remote file inclusion vulnerability in admin/admin_settings.php in MTCMS 2.0 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 6.8 medium 2.1% 2006-12-28
CVE-2006-6801 EXP PHP remote file inclusion vulnerability in misc.php in SH-News 0.93, when register_globals is enabled, allows remote attackers to execute arbitrary PH… Patch early 6.8 medium 2.1% 2006-12-28
CVE-2008-0184 EXP Absolute path traversal vulnerability in index.php in Sys-Hotel on Line System allows remote attackers to read arbitrary files via an encoded "/" ("%2… Patch early 6.4 medium 2.1% 2008-01-09
CVE-2005-0629 EXP Multiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 2.1% 2005-03-01
← previous page 230 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt