peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,534 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-6636 EXP PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when register_globals is enabled, all… Patch early 6.8 medium 1.9% 2009-04-07
CVE-2023-0214 EXP A cross-site scripting vulnerability in Skyhigh SWG in main releases 11.x prior to 11.2.6, 10.x prior to 10.2.17, and controlled release 12.x prior to… Patch early 6.1 medium 1.9% 2023-01-18
CVE-2008-0552 EXP Cross-site scripting (XSS) vulnerability in index.php in eTicket 1.5.6-RC4 allows remote attackers to inject arbitrary web script or HTML via the PATH… Patch early 4.3 medium 1.9% 2008-02-01
CVE-2013-1649 EXP Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses the crypt and SHA-1 algorithms for password hashing, which… Patch early 4.3 medium 1.9% 2013-09-05
CVE-2007-1125 EXP Cross-site scripting (XSS) vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to inject arbitrary web script or H… Patch early 4.3 medium 1.9% 2007-02-27
CVE-2012-2517 EXP Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of th… Patch early 6.1 medium 1.9% 2020-02-11
CVE-2001-1442 EXP Buffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the "news" group to gain privileges via a long -c command lin… Patch early 4.6 medium 1.9% 2001-04-21
CVE-2009-2377 EXP Buffer overflow in the Avax Vector ActiveX control in avPreview.ocx in AVAX-software Avax Vector ActiveX 1.3 allows remote attackers to cause a denial… Patch early 4.3 medium 1.9% 2009-07-08
CVE-2005-3908 EXP Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2, allows remote attackers to… Patch early 4.3 medium 1.9% 2005-11-30
CVE-2006-0442 EXP Multiple cross-site scripting (XSS) vulnerabilities in usercp.php in MyBulletinBoard (MyBB) 1.02 allow remote attackers to inject arbitrary web script… Patch early 4.3 medium 1.9% 2006-01-26
CVE-2006-6088 EXP Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar i-Gallery 3.4 allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.9% 2006-11-24
CVE-2007-4545 EXP Multiple directory traversal vulnerabilities in Unreal Commander 0.92 build 565 and 573 allow user-assisted remote attackers to create or overwrite ar… Patch early 6.8 medium 1.9% 2007-08-27
CVE-2007-6079 EXP Directory traversal vulnerability in include/common.php in bcoos 1.0.10 allows remote attackers to include and execute arbitrary local files via a ..… Patch early 6.8 medium 1.9% 2007-11-21
CVE-2009-0340 EXP Multiple directory traversal vulnerabilities in Simple PHP Newsletter 1.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the ola… Patch early 6.8 medium 1.9% 2009-01-29
CVE-2009-0371 EXP Directory traversal vulnerability in post.php in SiteXS CMS 0.1.1 and earlier allows remote attackers to include and execute arbitrary local files via… Patch early 6.8 medium 1.9% 2009-01-30
CVE-2009-1407 EXP Directory traversal vulnerability in config.php in NotFTP 1.3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a certain langua… Patch early 6.8 medium 1.9% 2009-04-24
CVE-2009-1498 EXP Directory traversal vulnerability in inc/profilemain.php in Game Maker 2k Internet Discussion Boards (iDB) 0.2.5 Pre-Alpha SVN 243 allows remote attac… Patch early 6.8 medium 1.9% 2009-05-01
CVE-2008-2185 EXP Directory traversal vulnerability in index.php in SMartBlog (aka SMBlog) 1.3 allows remote attackers to include arbitrary local files via directory tr… Patch early 4.3 medium 1.9% 2008-05-13
CVE-2023-0961 EXP A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been classified as critical. This affects an unknown part of the file view_… Patch early 6.3 medium 1.9% 2023-02-22
CVE-2006-6786 EXP Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email paramete… Patch early 6.5 medium 1.9% 2006-12-28
CVE-2018-15707 EXP Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability t… Patch early 5.4 medium 1.9% 2018-10-31
CVE-2006-6518 EXP Multiple cross-site scripting (XSS) vulnerabilities in ProNews 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo, (… Patch early 6.8 medium 1.9% 2006-12-14
CVE-2006-2124 EXP Multiple cross-site scripting (XSS) vulnerabilities in SunShop 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (… Patch early 5.8 medium 1.9% 2006-05-01
CVE-2006-2680 EXP Cross-site scripting (XSS) vulnerability in index.php in AZ Photo Album Script Pro allows remote attackers to inject arbitrary web script or HTML via… Patch early 5.8 medium 1.9% 2006-05-31
CVE-2006-3151 EXP Cross-site scripting (XSS) vulnerability in index.php in AssoCIateD (aka ACID) 1.2.0 and earlier allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 1.9% 2006-06-22
CVE-2009-3449 EXP MP3 Collector 2.3 allows remote attackers to cause a denial of service (application crash) via a long URL in a .m3u playlist file. Patch early 4.3 medium 1.9% 2009-09-29
CVE-2011-4909 EXP Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTT… Patch early 4.3 medium 1.9% 2012-10-07
CVE-2012-6523 EXP Multiple cross-site scripting (XSS) vulnerabilities in w-CMS 2.01 allow remote attackers to inject arbitrary web script or HTML via (1) the p paramete… Patch early 4.3 medium 1.9% 2013-01-31
CVE-2007-3542 EXP Cross-site scripting (XSS) vulnerability in admin/auth.php in Pluxml 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the msg… Patch early 4.3 medium 1.9% 2007-07-03
CVE-2007-0846 EXP Cross-site scripting (XSS) vulnerability in forum.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to inject arbitrary… Patch early 6.8 medium 1.9% 2007-02-08
← previous page 253 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt