peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,534 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-6517 EXP Multiple cross-site scripting (XSS) vulnerabilities in KDPics 1.16 and earlier allow remote attackers to inject arbitrary web script or HTML via the (… Patch early 6.8 medium 1.9% 2006-12-14
CVE-2018-9034 EXP Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote attackers to inject arbitrary… Patch early 5.4 medium 1.9% 2018-04-04
CVE-2008-1649 EXP Cross-site scripting (XSS) vulnerability in staticpages/easypublish/index.php in EasyNews 4.0 allows remote attackers to inject arbitrary web script o… Patch early 4.3 medium 1.9% 2008-04-02
CVE-2007-2098 EXP Multiple cross-site scripting (XSS) vulnerabilities in showpic.php in Wabbit PHP Gallery 0.9 allow remote attackers to inject arbitrary web script or… Patch early 6.8 medium 1.9% 2007-04-18
CVE-2008-3682 EXP SQL injection vulnerability in dpage.php in YPN PHP Realty allows remote attackers to execute arbitrary SQL commands via the docID parameter. Patch early 6.8 medium 1.9% 2008-08-14
CVE-2020-15600 EXP An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password. Patch early 6.5 medium 1.9% 2020-07-07
CVE-2012-4926 EXP approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via th… Patch early 6.4 medium 1.9% 2012-09-15
CVE-2008-7271 EXP Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE, possibly 3.3.2, allow r… Patch early 4.3 medium 1.9% 2011-01-13
CVE-2006-5120 EXP Multiple cross-site scripting (XSS) vulnerabilities in Scott Metoyer Red Mombin 0.7 allow remote attackers to inject arbitrary web script or HTML via… Patch early 4.0 medium 1.9% 2006-10-03
CVE-2008-1605 EXP The (1) ltmmCaptureCtrl Class, (2) ltmmConvertCtrl Class, and (3) ltmmPlayCtrl Class ActiveX controls (ltmm15.dll 15.1.0.17 and earlier) in LEADTOOLS… Patch early 6.8 medium 1.9% 2008-04-01
CVE-2021-30637 EXP htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php. Patch early 5.4 medium 1.9% 2021-04-13
CVE-2007-3785 EXP Absolute path traversal vulnerability in a certain ActiveX control in PGPBBox.dll in EldoS SecureBlackbox (sbb) 5.1.0.112 allows remote attackers to c… Patch early 4.0 medium 1.9% 2007-07-15
CVE-2018-7355 EXP All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scripting vulnerability. Due to imp… Patch early 6.1 medium 1.9% 2018-09-26
CVE-2017-16819 EXP A stored cross-site scripting vulnerability in the Icon Time Systems RTC-1000 v2.5.7458 and earlier time clock allows remote attackers to inject arbit… Patch early 5.4 medium 1.9% 2017-11-17
CVE-2006-6729 EXP Cross-site scripting (XSS) vulnerability in a-blog 1.51 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vec… Patch early 4.3 medium 1.9% 2006-12-26
CVE-2009-0330 EXP Directory traversal vulnerability in index.php in Simple Content Management System (SCMS) 1 allows remote attackers to include and execute arbitrary l… Patch early 6.8 medium 1.9% 2009-01-29
CVE-2009-0596 EXP Directory traversal vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled, allows remote attackers to include… Patch early 6.8 medium 1.9% 2009-02-16
CVE-2009-1405 EXP Directory traversal vulnerability in index.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute a… Patch early 6.8 medium 1.9% 2009-04-24
CVE-2009-1406 EXP Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local files via a ..… Patch early 6.8 medium 1.9% 2009-04-24
CVE-2009-3694 EXP Directory traversal vulnerability in config/config.php in ezRecipe-Zee 91, when register_globals is enabled, allows remote attackers to include and ex… Patch early 6.8 medium 1.9% 2009-10-13
CVE-2007-2300 EXP Multiple cross-site scripting (XSS) vulnerabilities in Endy Kristanto Surat kabar / News Management Online (aka phpwebnews) 0.2 and earlier allow remo… Patch early 4.3 medium 1.9% 2007-04-26
CVE-2007-3001 EXP Multiple cross-site scripting (XSS) vulnerabilities in PHP JackKnife (PHPJK) allow remote attackers to inject arbitrary web script or HTML via (1) the… Patch early 4.3 medium 1.9% 2007-06-04
CVE-2008-5727 EXP SQL injection vulnerability in modules/auth/password_recovery.php in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled, allows remote at… Patch early 6.8 medium 1.9% 2008-12-26
CVE-2006-6879 EXP Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated users to upload arbitrary PHP sc… Patch early 6.0 medium 1.9% 2006-12-31
CVE-2006-3823 EXP SQL injection vulnerability in index.php in GeodesicSolutions (1) GeoAuctions Premier 2.0.3 and (2) GeoClassifieds Basic 2.0.3 allows remote attackers… Patch early 5.1 medium 1.9% 2006-07-25
CVE-2011-4717 EXP Directory traversal vulnerability in zFTPServer Suite 6.0.0.52 allows remote authenticated users to delete arbitrary directories via a crafted RMD (ak… Patch early 5.5 medium 1.9% 2011-12-20
CVE-2006-4973 EXP Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5, and 4.x before 4.3.5, allows… Patch early 4.3 medium 1.9% 2006-09-25
CVE-2004-1944 EXP Eudora 6.1 and 6.0.3 for Windows allows remote attackers to cause a denial of service (crash) via a deeply nested multipart MIME message. Patch early 5.0 medium 1.9% 2004-04-14
CVE-2009-3424 EXP Multiple PHP remote file inclusion vulnerabilities in MaxCMS 3.11.20b, when register_globals is enabled, allow remote attackers to execute arbitrary P… Patch early 6.8 medium 1.9% 2009-09-25
CVE-2008-0159 EXP SQL injection vulnerability in index.php in eggBlog 3.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the eggblogpasswor… Patch early 6.8 medium 1.9% 2008-01-09
← previous page 252 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt