peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,173 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-1989 EXP Multiple cross-site scripting (XSS) vulnerabilities in DotClear before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 4.3 medium 2% 2007-04-12
CVE-2004-0681 EXP Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_customerAuthenticateForm.asp, (2) comersus_backoffice_message.asp, (3) comersus_su… Patch early 6.8 medium 2% 2004-08-06
CVE-2008-6308 EXP Multiple directory traversal vulnerabilities in Private Messaging System (PMS) 1.2.3 and earlier for PunBB allow remote attackers to include and execu… Patch early 5.1 medium 2% 2009-02-27
CVE-2006-4308 EXP Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community Portal Suite 6.2.3.23, and Blac… Patch early 4.3 medium 2% 2006-08-23
CVE-2009-4986 EXP Directory traversal vulnerability in index.php in In-Portal 4.3.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files… Patch early 6.8 medium 2% 2010-08-25
CVE-2026-33829 EXP Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network… Patch early 4.3 medium 2% 2026-04-14
CVE-2004-2548 EXP Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web… Patch early 4.3 medium 2% 2004-12-31
CVE-2005-4698 EXP Cross-site scripting (XSS) vulnerability in TellMe 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the 91) q_IP (IP… Patch early 4.3 medium 2% 2005-12-31
CVE-2005-2468 EXP Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorre… Patch early 6.4 medium 2% 2005-12-31
CVE-2002-1495 EXP Cross-site scripting (XSS) vulnerability in JAWmail 1.0-rc1 allows remote attackers to insert arbitrary script or HTML via (1) attached file names in… Patch early 4.3 medium 2% 2003-04-02
CVE-2007-0110 EXP Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell Access Manager Identity Server before 3.0.0-1013 allows remote attackers to inject… Patch early 6.8 medium 2% 2007-01-09
CVE-2006-1384 EXP Cross-site scripting (XSS) vulnerability in apwc_win_main.jsp in the web console in IBM Tivoli Business Systems Manager (TBSM) before 3.1.0.1 allows r… Patch early 4.3 medium 2% 2006-03-24
CVE-2004-2245 EXP Cross-site scripting (XSS) vulnerability in Goollery 0.03 allows remote attackers to inject arbitrary HTML or web script via the (1) page parameter to… Patch early 4.3 medium 2% 2004-12-31
CVE-2005-3849 EXP Cross-site scripting (XSS) vulnerability in the Search module in PmWiki up to 2.0.12 allows remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 2% 2005-11-27
CVE-2008-6524 EXP resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid par… Patch early 6.5 medium 2% 2009-03-25
CVE-2005-4060 EXP Cross-site scripting (XSS) vulnerability in search.asp in rwAuction Pro 4.0 and 5.0 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 2% 2005-12-07
CVE-2006-2187 EXP Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and earlier allow remote attackers to inject arbitrary web script or HTML v… Patch early 6.8 medium 2% 2006-05-04
CVE-2006-5761 EXP Cross-site scripting (XSS) vulnerability in index.php in Rhadrix If-CMS 1.01 and 2.07 allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 2% 2006-11-06
CVE-2005-2064 EXP Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) email paramet… Patch early 5.0 medium 2% 2005-06-29
CVE-2008-6251 EXP PHP remote file inclusion vulnerability in includes/init.php in phpFan 3.3.4 allows remote attackers to execute arbitrary PHP code via a URL in the in… Patch early 6.8 medium 2% 2009-02-24
CVE-2008-6635 EXP PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when register_globals is enabled, all… Patch early 6.8 medium 2% 2009-04-07
CVE-2007-6001 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in Bandersnatch 0.4 allow remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 2% 2007-11-15
CVE-2008-5742 EXP Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phi… Patch early 4.0 medium 2% 2008-12-26
CVE-2011-2745 EXP upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of upload… Patch early 6.5 medium 2% 2011-07-27
CVE-2010-2456 EXP Multiple directory traversal vulnerabilities in index.php in Linker IMG 1.0 and earlier allow remote attackers to read and execute arbitrary local fil… Patch early 6.8 medium 2% 2010-06-25
CVE-2008-3385 EXP Directory traversal vulnerability in include/head_chat.inc.php in php Help Agent 1.0 and 1.1 Full allows remote attackers to include and execute arbit… Patch early 6.8 medium 2% 2008-07-30
CVE-2005-4491 EXP Multiple cross-site scripting (XSS) vulnerabilities in Sitekit CMS 6.6 and earlier allow remote attackers to inject arbitrary web script or HTML via t… Patch early 4.3 medium 2% 2005-12-22
CVE-2005-4307 EXP Cross-site scripting (XSS) vulnerability in ScareCrow 2.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum pa… Patch early 4.3 medium 2% 2005-12-17
CVE-2008-3315 EXP Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the (1) quer… Patch early 4.3 medium 2% 2008-07-25
CVE-2006-1135 EXP Multiple cross-site scripting (XSS) vulnerabilities in sBlog 0.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword p… Patch early 4.3 medium 2% 2006-03-10
← previous page 236 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt