peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,602 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-1068 EXP Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a U… Patch early 6.8 medium 1.8% 2008-02-28
CVE-2008-1123 EXP Multiple PHP remote file inclusion vulnerabilities in SiteBuilder Elite 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the Carp… Patch early 6.8 medium 1.8% 2008-03-03
CVE-2006-6087 EXP Cross-site scripting (XSS) vulnerability in weblog.php in my little weblog allows remote attackers to inject arbitrary web script or HTML via the acti… Patch early 4.3 medium 1.8% 2006-11-24
CVE-2006-6746 EXP Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script or HTML via the id_news param… Patch early 4.3 medium 1.8% 2006-12-27
CVE-2006-1825 EXP Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML v… Patch early 6.8 medium 1.8% 2006-04-18
CVE-2004-0032 EXP Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script via the firs… Patch early 6.8 medium 1.8% 2004-01-20
CVE-2007-0836 EXP admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to include arbitrary local and possibly remote f… Patch early 4.0 medium 1.8% 2007-02-08
CVE-2003-1481 EXP CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack… Patch early 5.8 medium 1.8% 2003-12-31
CVE-2012-1023 EXP Open redirect vulnerability in admin/index.php in 4images 1.7.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing… Patch early 5.8 medium 1.8% 2012-02-08
CVE-2007-2901 EXP Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.8% 2007-05-30
CVE-2007-3324 EXP Multiple cross-site scripting (XSS) vulnerabilities in Comersus Cart 7.07 allow remote attackers to inject arbitrary web script or HTML via the redire… Patch early 4.3 medium 1.8% 2007-06-21
CVE-2009-3860 EXP Multiple insecure method vulnerabilities in Idefense Labs COMRaider allow remote attackers to create or overwrite arbitrary files via the (1) CreateFo… Patch early 5.8 medium 1.8% 2009-11-04
CVE-2008-2787 EXP Cross-site scripting (XSS) vulnerability in out.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the last_me… Patch early 4.3 medium 1.8% 2008-06-20
CVE-2005-4161 EXP Multiple cross-site scripting (XSS) vulnerabilities in MilliScripts 1.4 redirect script allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.8% 2005-12-11
CVE-2015-7562 EXP Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbitrary web script or HTML via t… Patch early 6.1 medium 1.8% 2017-04-12
CVE-2010-0756 EXP Session fixation vulnerability in WikyBlog 1.7.3 rc2 allows remote attackers to hijack web sessions by setting the jsessionid parameter to (1) index.p… Patch early 5.8 medium 1.8% 2010-02-27
CVE-2014-5193 EXP Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the ca… Patch early 4.3 medium 1.8% 2014-08-07
CVE-2009-1907 EXP Cross-site scripting (XSS) vulnerability in claroline/linker/notfound.php in Claroline 1.8.11 allows remote attackers to inject arbitrary web script o… Patch early 4.3 medium 1.8% 2009-06-04
CVE-2022-48177 EXP X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importModels Impor… Patch early 5.4 medium 1.8% 2023-04-15
CVE-2022-48178 EXP X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action function, ak… Patch early 5.4 medium 1.8% 2023-04-15
CVE-2007-1229 EXP Cross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.8% 2007-03-02
CVE-2007-3055 EXP Cross-site scripting (XSS) vulnerability in index.php in Codelib Linker 2.0.4 and earlier allows remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 1.8% 2007-06-06
CVE-2007-4479 EXP Cross-site scripting (XSS) vulnerability in search.html in Search Engine Builder allows remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 1.8% 2007-08-22
CVE-2006-6721 EXP Multiple cross-site scripting (XSS) vulnerabilities in shout.php in Knusperleicht ShoutBox 2.6 allow remote attackers to inject arbitrary web script o… Patch early 6.8 medium 1.8% 2006-12-23
CVE-2008-0283 EXP PHP remote file inclusion vulnerability in /aides/index.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary PHP code via a URL… Patch early 6.8 medium 1.8% 2008-01-15
CVE-2008-5947 EXP PHP remote file inclusion vulnerability in include/class_yapbbcooker.php in YapBB 1.2.Beta 2 allows remote attackers to execute arbitrary PHP code via… Patch early 6.8 medium 1.8% 2009-01-22
CVE-2008-6511 EXP Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arbitrary web sites and conduct p… Patch early 5.8 medium 1.8% 2009-03-23
CVE-2008-6044 EXP Cross-site scripting (XSS) vulnerability in advanced_search_result.php in xt:Commerce 3.0.4 and earlier allows remote attackers to inject arbitrary we… Patch early 4.3 medium 1.8% 2009-02-03
CVE-2004-1995 EXP Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm. Patch early 6.5 medium 1.8% 2004-12-31
CVE-2012-4923 EXP Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) c… Patch early 4.3 medium 1.8% 2012-09-15
← previous page 257 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt