peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,226 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-3315 EXP Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the (1) quer… Patch early 4.3 medium 2% 2008-07-25
CVE-2009-4795 EXP Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbit… Patch early 6.8 medium 2% 2010-04-22
CVE-2006-7117 EXP Multiple directory traversal vulnerabilities in Kubix 0.7 and earlier allow remote attackers to (1) include and execute arbitrary local files via ".."… Patch early 6.8 medium 2% 2007-03-06
CVE-2017-2528 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" co… Patch early 6.1 medium 2% 2017-05-22
CVE-2002-0838 EXP Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (5) kghostview in kdegraphics 2… Patch early 4.6 medium 2% 2002-10-10
CVE-2012-6658 EXP Multiple cross-site scripting (XSS) vulnerabilities in SpiceWorks 5.3.75941 allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 4.3 medium 2% 2014-09-17
CVE-2006-1133 EXP Multiple cross-site scripting (XSS) vulnerabilities in vbzoom 1.11 allow remote attackers to inject arbitrary web script or HTML via the UserID parame… Patch early 4.3 medium 2% 2006-03-10
CVE-2008-5678 EXP Fretwell-Downing Informatics (FDI) OLIB7 WebView 2.5.1.1 allows remote authenticated users to obtain sensitive information from files via the infile p… Patch early 4.0 medium 2% 2008-12-19
CVE-2019-19493 EXP Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS. Patch early 5.4 medium 2% 2019-12-02
CVE-2009-1222 EXP Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, a… Patch early 5.1 medium 2% 2009-04-02
CVE-2009-1948 EXP Multiple directory traversal vulnerabilities in forum.php in Unclassified NewsBoard (UNB) 1.6.4, when register_globals is enabled and magic_quotes_gpc… Patch early 5.1 medium 2% 2009-06-05
CVE-2008-0648 EXP Multiple PHP remote file inclusion vulnerabilities in OpenSiteAdmin 0.9.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL… Patch early 6.8 medium 2% 2008-02-07
CVE-2007-2001 EXP Multiple direct static code injection vulnerabilities in admin/configurer2.php in Crea-Book 1.0 and earlier allow remote authenticated administrators… Patch early 6.5 medium 2% 2007-04-12
CVE-2006-6447 EXP Multiple cross-site scripting (XSS) vulnerabilities in Vt-Forum Lite 1.3 and 1.5 allow remote attackers to inject arbitrary web script or HTML via (1)… Patch early 6.8 medium 2% 2006-12-10
CVE-2007-2303 EXP Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers to include and execute arbitr… Patch early 6.8 medium 2% 2007-04-26
CVE-2006-1238 EXP SQL injection vulnerability in DSLogin 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands and bypass authe… Patch early 5.1 medium 2% 2006-03-15
CVE-2007-5255 EXP Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance 3.4.14 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 2% 2007-10-06
CVE-2007-1031 EXP Directory traversal vulnerability in include/db_conn.php in SpoonLabs Vivvo Article Management CMS 3.4 allows remote attackers to include and execute… Patch early 6.8 medium 2% 2007-02-21
CVE-2007-5278 EXP Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers… Patch early 4.3 medium 2% 2007-10-08
CVE-2007-5721 EXP PHP remote file inclusion vulnerability in _theme/breadcrumb.php in MySpacePros MySpace Resource Script (MSRS) 1.21 allows remote attackers to execute… Patch early 6.8 medium 2% 2007-10-30
CVE-2007-5995 EXP PHP remote file inclusion vulnerability in examples/patExampleGen/bbcodeSource.php in patBBcode 1.0 allows remote attackers to execute arbitrary PHP c… Patch early 6.8 medium 2% 2007-11-15
CVE-2007-6289 EXP Multiple PHP remote file inclusion vulnerabilities in SerWeb 2.0.0 dev1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 6.8 medium 2% 2007-12-10
CVE-2008-7099 EXP Unspecified vulnerability in the Manage Templates feature in Qsoft K-Rate Premium allows remote attackers to execute arbitrary PHP code via unknown ve… Patch early 6.8 medium 2% 2009-08-27
CVE-2007-1896 EXP Directory traversal vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier allows remote attackers to include arbitrary local files via a… Patch early 5.8 medium 2% 2007-04-09
CVE-2018-10078 EXP Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to inject arbitrary web script or… Patch early 4.8 medium 2% 2018-04-20
CVE-2007-3978 EXP Session fixation vulnerability in bwired allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. Patch early 4.3 medium 2% 2007-07-25
CVE-2007-5983 EXP Cross-site scripting (XSS) vulnerability in index.php in Justin Hagstrom AutoIndex PHP Script before 2.2.3 allows remote attackers to inject arbitrary… Patch early 4.3 medium 2% 2007-11-15
CVE-2010-4749 EXP Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to inject arbitrary web script o… Patch early 4.3 medium 2% 2011-03-01
CVE-2009-4315 EXP Directory traversal vulnerability in admin/ajaxsave.php in Nuggetz CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to create or mo… Patch early 6.8 medium 2% 2009-12-14
CVE-2010-1920 EXP Directory traversal vulnerability in scr/soustab.php in OpenMairie openAnnuaire 2.00, when register_globals is enabled, allows remote attackers to inc… Patch early 6.8 medium 2% 2010-05-12
← previous page 237 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt