peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,461 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-3927 EXP Cross-site scripting (XSS) vulnerability in auctionsearch.php in PhpProBid 5.24 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.9% 2006-07-31
CVE-2023-29848 EXP Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in the admin/menu.php Add New Me… Patch early 4.8 medium 1.9% 2023-04-24
CVE-2007-5427 EXP Cross-site scripting (XSS) vulnerability in the com_search component in Joomla! 1.0.13 and earlier allows remote attackers to inject arbitrary web scr… Patch early 4.3 medium 1.9% 2007-10-12
CVE-2004-2702 EXP Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.9% 2004-12-31
CVE-2008-0026 EXP SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote… Patch early 6.5 medium 1.9% 2008-02-14
CVE-2008-3701 EXP SQL injection vulnerability in staff/index.php in Kayako SupportSuite 3.20.02 and earlier allows remote authenticated users to execute arbitrary SQL c… Patch early 6.5 medium 1.9% 2008-08-15
CVE-2009-1468 EXP Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server… Patch early 6.5 medium 1.9% 2009-05-05
CVE-2012-5343 EXP Cross-site scripting (XSS) vulnerability in admin/login.php in Limny 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the PATH… Patch early 4.3 medium 1.9% 2012-10-09
CVE-2006-6096 EXP Cross-site scripting (XSS) vulnerability in activenews_search.asp in ActiveNews Manager allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.9% 2006-11-24
CVE-2007-5127 EXP Multiple cross-site scripting (XSS) vulnerabilities in SimpGB 1.46.02 allow remote attackers to inject arbitrary web script or HTML via (1) the l_user… Patch early 4.3 medium 1.9% 2007-09-27
CVE-2008-7152 EXP Multiple PHP remote file inclusion vulnerabilities in Specimen Image Database (SID), when register_globals is enabled, allow remote attackers to execu… Patch early 6.8 medium 1.9% 2009-09-01
CVE-2005-2219 EXP Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct… Patch early 4.6 medium 1.9% 2005-07-12
CVE-2006-1482 EXP Cross-site scripting (XSS) vulnerability in index.php in ConfTool 1.1 allows remote attackers to inject arbitrary web script or HTML via the page para… Patch early 4.3 medium 1.9% 2006-03-29
CVE-2012-0308 EXP Cross-site request forgery (CSRF) vulnerability in Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers to hijack the authentication o… Patch early 6.8 medium 1.9% 2012-08-29
CVE-2008-6773 EXP Static code injection vulnerability in user/internettoolbar/edit.php in YourPlace 1.0.2 and earlier allows remote authenticated users to execute arbit… Patch early 6.5 medium 1.9% 2009-04-29
CVE-2007-0645 EXP Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in… Patch early 6.8 medium 1.9% 2007-02-01
CVE-2008-1861 EXP Directory traversal vulnerability in modules/threadstop/threadstop.php in ExBB Italia 0.22 and earlier, when register_globals is enabled and magic_quo… Patch early 5.1 medium 1.9% 2008-04-17
CVE-2008-5878 EXP Multiple directory traversal vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled and register… Patch early 5.1 medium 1.9% 2009-01-08
CVE-2008-6901 EXP Multiple directory traversal vulnerabilities in 2532designs 2532|Gigs 1.2.2 Stable, when register_globals is enabled and magic_quotes_gpc is disabled,… Patch early 5.1 medium 1.9% 2009-08-06
CVE-2008-1208 EXP Cross-site scripting (XSS) vulnerability in the login page in Check Point VPN-1 UTM Edge W Embedded NGX 7.0.48x allows remote attackers to inject arbi… Patch early 4.3 medium 1.9% 2008-03-08
CVE-2006-6082 EXP Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.9% 2006-11-24
CVE-2009-2101 EXP Directory traversal vulnerability in archive.php in TorrentVolve 1.4, when register_globals is enabled, allows remote attackers to delete arbitrary fi… Patch early 6.8 medium 1.9% 2009-06-17
CVE-2008-3562 EXP Directory traversal vulnerability in index.php in the Contact module in Chupix CMS 0.1.0, when magic_quotes_gpc is disabled, allows remote attackers t… Patch early 5.1 medium 1.9% 2008-08-10
CVE-2006-0783 EXP Cross-site scripting (XSS) vulnerability in page.php in in Siteframe Beaumont, possibly 5.0.2 or 5.0.1a, allows remote attackers to inject arbitrary w… Patch early 4.3 medium 1.9% 2006-02-19
CVE-2007-2087 EXP Multiple PHP remote file inclusion vulnerabilities in CNStats 2.12, when register_globals is enabled and .htaccess is not recognized, allow remote att… Patch early 6.8 medium 1.9% 2007-04-18
CVE-2007-3315 EXP Multiple PHP remote file inclusion vulnerabilities in YourFreeScreamer 1.0, when register_globals is enabled, allow remote attackers to execute arbitr… Patch early 6.8 medium 1.9% 2007-06-21
CVE-2011-0635 EXP Static code injection vulnerability in Simploo CMS 1.7.1 and earlier allows remote authenticated users to inject arbitrary PHP code into config/custom… Patch early 6.0 medium 1.9% 2011-01-22
CVE-2019-12801 EXP out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name. Patch early 6.1 medium 1.9% 2019-06-17
CVE-2009-3201 EXP Integer overflow in Media Player Classic 6.4.9 allows user-assisted remote attackers to cause a denial of service (application crash) via a MIDI file… Patch early 4.3 medium 1.9% 2009-09-15
CVE-2009-3211 EXP Directory traversal vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary… Patch early 6.8 medium 1.9% 2009-09-16
← previous page 249 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt