peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,707 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-2256 EXP Cross-site scripting (XSS) vulnerability in you.php in TJSChat 0.95 allows remote attackers to inject arbitrary web script or HTML via the user parame… Patch early 4.3 medium 1.8% 2007-04-25
CVE-2007-2887 EXP Cross-site scripting (XSS) vulnerability in index.php in Web Icerik Yonetim Sistemi (WIYS) 1.0 allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 1.8% 2007-05-30
CVE-2009-2569 EXP Multiple cross-site scripting (XSS) vulnerabilities in Verlihub Control Panel (VHCP) 1.7e allow remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 1.8% 2009-07-22
CVE-2008-0982 EXP Spyce - Python Server Pages (PSP) 2.1.3 allows remote attackers to obtain sensitive information via a direct request for spyce/examples/automaton.spy,… Patch early 5.8 medium 1.8% 2008-02-25
CVE-2018-7273 EXP In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables using printk calls within the fun… Patch early 5.5 medium 1.8% 2018-02-21
CVE-2007-4252 EXP Absolute path traversal vulnerability in a certain ActiveX control in CkString.dll 1.1 and earlier in CHILKAT ASP String allows remote attackers to cr… Patch early 4.3 medium 1.8% 2007-08-08
CVE-2008-4120 EXP Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.804 allow remote attackers to inject arbitrary web script or HTML via the (1) user… Patch early 4.3 medium 1.8% 2008-09-29
CVE-2006-3996 EXP SQL injection vulnerability in links/index.php in ATutor 1.5.3.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via t… Patch early 6.5 medium 1.8% 2006-08-05
CVE-2002-2312 EXP Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2)… Patch early 5.8 medium 1.8% 2002-12-31
CVE-2003-1401 EXP login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remo… Patch early 5.8 medium 1.8% 2003-12-31
CVE-2007-2686 EXP Cross-site scripting (XSS) vulnerability in index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the login p… Patch early 4.3 medium 1.8% 2007-05-22
CVE-2017-8839 EXP XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_250… Patch early 6.1 medium 1.8% 2017-06-05
CVE-2006-1954 EXP SQL injection vulnerability in authent.php4 in Nicolas Fischer (aka NFec) RechnungsZentrale V2 1.1.3, and possibly earlier versions, allows remote att… Patch early 5.0 medium 1.8% 2006-04-21
CVE-2019-12195 EXP TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the… Patch early 4.8 medium 1.8% 2019-05-24
CVE-2009-3803 EXP Multiple cross-site scripting (XSS) vulnerabilities in Amiro.CMS 5.4.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.8% 2009-10-27
CVE-2009-4381 EXP Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 1.8% 2009-12-22
CVE-2009-4888 EXP Cross-site scripting (XSS) vulnerability in poster.php in PHortail 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) ps… Patch early 4.3 medium 1.8% 2010-06-11
CVE-2010-5318 EXP The password-reset feature in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to modify the administrator's password by specifyin… Patch early 4.3 medium 1.8% 2015-01-03
CVE-2009-2267 EXP VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware… Patch early 6.9 medium 1.8% 2009-11-02
CVE-2007-4003 EXP pioout in IBM AIX 5.3 SP6 allows local users to execute arbitrary code by specifying a malicious library with the -R (ParseRoutine) command line argum… Patch early 6.9 medium 1.8% 2007-07-26
CVE-2006-4927 EXP The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec AntiVirus and security products,… Patch early 4.6 medium 1.8% 2006-10-10
CVE-1999-0946 EXP Buffer overflow in Yamaha MidiPlug via a Text variable in an EMBED tag. Patch early 5.1 medium 1.8% 1999-11-02
CVE-2005-0981 EXP Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft EPay Pro 2.0 allow remote attackers to inject arbitrary web script or HTML via the (… Patch early 4.3 medium 1.8% 2005-05-02
CVE-2005-3790 EXP Multiple cross-site scripting (XSS) vulnerabilities in act_newsletter.php in phpwcms 1.2.5 allow remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 1.8% 2005-11-24
CVE-2004-1537 EXP Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web script via the i… Patch early 4.3 medium 1.8% 2004-12-31
CVE-2004-2007 EXP Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject arbitrary HTML or web script via… Patch early 4.3 medium 1.8% 2004-05-08
CVE-2005-0270 EXP Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 1.8% 2005-05-02
CVE-2005-2397 EXP Cross-site scripting (XSS) vulnerability in guestbook.php in phpBook 1.46 allows remote attackers to inject arbitrary web script or HTML via the admin… Patch early 4.3 medium 1.8% 2005-07-27
CVE-2005-2721 EXP Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) admin.php in Foojan PHP Weblog allow remote attackers to inject arbitrary… Patch early 4.3 medium 1.8% 2005-08-30
CVE-2005-2783 EXP Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested,… Patch early 4.3 medium 1.8% 2005-09-02
← previous page 265 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt