peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,286 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-3233 EXP Cross-site scripting (XSS) vulnerability in __swift/thirdparty/PHPExcel/PHPExcel/Shared/JAMA/docs/download.php in Kayako Fusion 4.40.1148, and possibl… Patch early 4.3 medium 2% 2012-09-15
CVE-2014-9235 EXP Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute arbitrary SQL… Patch early 6.5 medium 2% 2014-12-03
CVE-2015-6516 EXP SQL injection vulnerability in cygnux.org sysPass 1.0.9 and earlier allows remote authenticated users to execute arbitrary SQL commands via the search… Patch early 6.5 medium 2% 2015-08-18
CVE-2008-7055 EXP module.php in ezContents 2.0.3 allows remote attackers to bypass the directory traversal protection mechanism to include and execute arbitrary local f… Patch early 5.1 medium 2% 2009-08-24
CVE-2020-23518 EXP Cross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to version 3.5 which allows remote at… Patch early 5.4 medium 2% 2021-03-02
CVE-2007-1606 EXP Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary web script or HTML via (1) the s… Patch early 4.3 medium 2% 2007-03-22
CVE-2006-1556 EXP Multiple cross-site scripting (XSS) vulnerabilities in view_caricatier.php in AL-Caricatier 2.5 allow remote attackers to inject arbitrary web script… Patch early 6.8 medium 2% 2006-03-31
CVE-2006-1713 EXP Cross-site scripting (XSS) vulnerability in index.php in Christoph Roeder phpMyForum 4.0 allows remote attackers to inject arbitrary web script or HTM… Patch early 6.8 medium 2% 2006-04-11
CVE-2006-1765 EXP Cross-site scripting (XSS) vulnerability in index.php in JBook 1.3 allows remote attackers to inject arbitrary web script or HTML via the page paramet… Patch early 6.8 medium 2% 2006-04-13
CVE-2006-1893 EXP Cross-site scripting (XSS) vulnerability in print.php in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the id paramet… Patch early 6.8 medium 2% 2006-04-20
CVE-2004-0337 EXP Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other users via a… Patch early 6.8 medium 2% 2004-11-23
CVE-2004-1213 EXP Cross-site scripting (XSS) vulnerability in index.php in Advanced Guestbook 2.3.1, 2.2, and possibly other versions allows remote attackers to inject… Patch early 6.8 medium 2% 2005-01-10
CVE-2005-1285 EXP Cross-site scripting (XSS) vulnerability in thread.php in WoltLab Burning Board 2.3.1 and earlier allows remote attackers to inject arbitrary web scri… Patch early 6.8 medium 2% 2005-04-22
CVE-2005-4476 EXP Cross-site scripting (XSS) vulnerability in store/search/results.html in OpenEdit 4.0 and earlier allows remote attackers to inject arbitrary web scri… Patch early 6.8 medium 2% 2005-12-22
CVE-2005-4482 EXP Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via… Patch early 6.8 medium 2% 2005-12-22
CVE-2016-6689 EXP Binder in the kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via a crafted application, aka int… Patch early 5.5 medium 2% 2016-10-10
CVE-2009-4115 EXP Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authenticated users with application ad… Patch early 6.5 medium 2% 2009-11-30
CVE-2009-4421 EXP Directory traversal vulnerability in languages_cgi.php in Simple PHP Blog 0.5.1 and earlier allows remote authenticated users to include and execute a… Patch early 6.5 medium 2% 2009-12-24
CVE-2007-6124 EXP Cross-site scripting (XSS) vulnerability in signin.php in Softbiz Freelancers Script 1 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 2% 2007-11-26
CVE-2010-4801 EXP Directory traversal vulnerability in admin/updatelist.php in BaconMap 1.0 allows remote attackers to include and execute arbitrary local files via a .… Patch early 6.0 medium 2% 2011-04-27
CVE-2003-1517 EXP cart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, which leaks the path in an error… Patch early 5.0 medium 2% 2003-12-31
CVE-2007-5261 EXP Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to catego… Patch early 6.4 medium 2% 2007-10-06
CVE-2008-4894 EXP Directory traversal vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS 5.0.10a, when register_globals is en… Patch early 5.1 medium 2% 2008-11-04
CVE-2008-5728 EXP Multiple directory traversal vulnerabilities in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow… Patch early 5.1 medium 2% 2008-12-26
CVE-2014-5144 EXP Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary web script or HTML via crafte… Patch early 5.4 medium 2% 2017-08-09
CVE-2007-2061 EXP Cross-site scripting (XSS) vulnerability in check_login.asp in AfterLogic MailBee WebMail Pro 3.4 allows remote attackers to inject arbitrary web scri… Patch early 4.3 medium 2% 2007-04-18
CVE-2012-5104 EXP Cross-site scripting (XSS) vulnerability in forums/ubbthreads.php in UBB.threads 7.5.6 and earlier allows remote attackers to inject arbitrary web scr… Patch early 4.3 medium 2% 2012-09-23
CVE-2014-3992 EXP Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) entity… Patch early 6.5 medium 2% 2014-07-11
CVE-2021-27308 EXP A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redir… Patch early 4.8 medium 2% 2021-03-22
CVE-2009-1798 EXP Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU (aka Rac… Patch early 4.3 medium 2% 2009-12-28
← previous page 239 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt