peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,659 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-6951 EXP Cross-site scripting (XSS) vulnerability in blog.php in OdysseusBlog allows remote attackers to inject arbitrary web script or HTML via the page param… Patch early 6.8 medium 1.8% 2007-01-23
CVE-2008-6665 EXP change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges via a crafted email parameter… Patch early 6.8 medium 1.8% 2009-04-08
CVE-2018-1188 EXP Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and versions 7.2.1.x is affected by a cross-site scripti… Patch early 4.8 medium 1.8% 2018-03-26
CVE-2018-1201 EXP Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a… Patch early 4.8 medium 1.8% 2018-03-26
CVE-2008-2421 EXP Cross-site scripting (XSS) vulnerability in the Web GUI in SAP Web Application Server (WAS) 7.0, Web Dynpro for ABAP (aka WD4A or WDA), and Web Dynpro… Patch early 4.3 medium 1.8% 2008-05-23
CVE-2005-3020 EXP Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1… Patch early 4.3 medium 1.8% 2005-09-21
CVE-2007-0768 EXP Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted… Patch early 4.3 medium 1.8% 2007-02-06
CVE-2013-2712 EXP Cross-site scripting (XSS) vulnerability in services/get_article.php in KrisonAV CMS before 3.0.2 allows remote attackers to inject arbitrary web scri… Patch early 4.3 medium 1.8% 2014-05-23
CVE-2007-1553 EXP admin/configuration.php in Guestbara 1.2 and earlier allows remote attackers to modify the e-mail, name, and password of the admin account by setting… Patch early 5.0 medium 1.8% 2007-03-20
CVE-2010-1146 EXP The Linux kernel 2.6.33.2 and earlier, when a ReiserFS filesystem exists, does not restrict read or write access to the .reiserfs_priv directory, whic… Patch early 6.9 medium 1.8% 2010-04-12
CVE-2006-1979 EXP Cross-site scripting (XSS) vulnerability in mwguest.php in Manic Web MWGuest 2.1.0 allows remote attackers to inject arbitrary web script or HTML via… Patch early 5.8 medium 1.8% 2006-04-21
CVE-2007-1248 EXP Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 1.8% 2007-03-03
CVE-2014-10018 EXP Cross-site scripting (XSS) vulnerability in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem allows remote attackers to in… Patch early 4.3 medium 1.8% 2015-01-13
CVE-2012-2569 EXP Cross-site scripting (XSS) vulnerability in Synametrics Technologies Xeams 4.4 Build 5720 allows remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 1.8% 2014-06-19
CVE-2012-2592 EXP Cross-site scripting (XSS) vulnerability in Axigen Mail Server 8.0.1 allows remote attackers to inject arbitrary web script or HTML via the body of an… Patch early 4.3 medium 1.8% 2014-06-18
CVE-2010-0678 EXP PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, when register_globals is en… Patch early 6.8 medium 1.8% 2010-02-22
CVE-2008-2224 EXP Multiple PHP remote file inclusion vulnerabilities in SazCart 1.5.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP… Patch early 6.8 medium 1.8% 2008-05-14
CVE-2008-6305 EXP PHP remote file inclusion vulnerability in init.php in Free Directory Script 1.1.1, when register_globals is enabled, allows remote attackers to execu… Patch early 6.8 medium 1.8% 2009-02-26
CVE-2008-6431 EXP Multiple cross-site scripting (XSS) vulnerabilities in BMForum 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) outpused… Patch early 4.3 medium 1.8% 2009-03-06
CVE-2007-2337 EXP Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS 0.96.6 Alpha and earlier allow remote attackers to inject arbitrary web script or… Patch early 4.3 medium 1.8% 2007-04-27
CVE-2006-2696 EXP Cross-site scripting (XSS) vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) startl… Patch early 6.8 medium 1.8% 2006-05-31
CVE-2006-2052 EXP Cross-site scripting (XSS) vulnerability in Verosky Media Instant Photo Gallery allows remote attackers to inject arbitrary web script or HTML via the… Patch early 5.8 medium 1.8% 2006-04-26
CVE-2012-5919 EXP Multiple cross-site scripting (XSS) vulnerabilities in Havalite 1.0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 1.8% 2012-11-19
CVE-2007-0890 EXP Cross-site scripting (XSS) vulnerability in scripts/passwdmysql in cPanel WebHost Manager (WHM) 11.0.0 and earlier allows remote attackers to inject a… Patch early 4.3 medium 1.8% 2007-02-12
CVE-2007-0225 EXP Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to inject arbitrary web… Patch early 6.8 medium 1.8% 2007-01-13
CVE-2012-4685 EXP Cross-site scripting (XSS) vulnerability in Arbor Networks Peakflow SP 5.1.1 before patch 6, 5.5 before patch 4, and 5.6.0 before patch 1 allows remot… Patch early 4.3 medium 1.8% 2012-08-28
CVE-2007-4874 EXP Multiple cross-site scripting (XSS) vulnerabilities in SimpNews 2.41.03 allow remote attackers to inject arbitrary web script or HTML via the (1) l_us… Patch early 4.3 medium 1.8% 2007-09-26
CVE-2008-2637 EXP Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN 6.0.2 hotfix 3, and possibly earlier versions, allow remote attackers to in… Patch early 4.3 medium 1.8% 2008-06-10
CVE-2009-0294 EXP Multiple PHP remote file inclusion vulnerabilities in WB News 2.0.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP… Patch early 6.8 medium 1.8% 2009-01-27
CVE-2010-1351 EXP Multiple PHP remote file inclusion vulnerabilities in Nodesforum 1.033 and 1.045, when register_globals is enabled, allow remote attackers to execute… Patch early 6.8 medium 1.8% 2010-04-12
← previous page 258 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt