peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,746 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-2037 EXP Cross-site scripting (XSS) vulnerability in index.php in Thwboard 3.0 Beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.7% 2006-04-26
CVE-2009-1735 EXP Cross-site scripting (XSS) vulnerability in search.php in VidSharePro allows remote attackers to inject arbitrary web script or HTML via the searchtxt… Patch early 4.3 medium 1.7% 2009-05-20
CVE-2008-2981 EXP PHP remote file inclusion vulnerability in admin/templates/template_thumbnail.php in HomePH Design 2.10 RC2, when register_globals is enabled, allows… Patch early 6.8 medium 1.7% 2008-07-02
CVE-2009-2399 EXP PHP remote file inclusion vulnerability in dm-albums/template/album.php in DM FileManager 3.9.4, when register_globals is enabled, allows remote attac… Patch early 6.8 medium 1.7% 2009-07-09
CVE-2009-2769 EXP PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attackers… Patch early 6.8 medium 1.7% 2009-08-14
CVE-2007-6700 EXP Cross-site scripting (XSS) vulnerability in cgi-bin/bgplg in the web interface for the BGPD daemon in OpenBSD 4.1 allows remote attackers to inject ar… Patch early 4.3 medium 1.7% 2008-02-05
CVE-2006-7112 EXP Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via… Patch early 6.0 medium 1.7% 2007-03-06
CVE-2006-2177 EXP Cross-site scripting (XSS) vulnerability in viewcat.php in geoBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the cat para… Patch early 4.3 medium 1.7% 2006-05-04
CVE-2010-4276 EXP Cross-site scripting (XSS) vulnerability in the lz_tracking_set_sessid function in templates/jscript/jstrack.tpl in LiveZilla 3.2.0.2 allows remote at… Patch early 4.3 medium 1.7% 2010-12-30
CVE-2010-4949 EXP Cross-site scripting (XSS) vulnerability in the (1) FreiChat component before 2.1.2 for Joomla! and the (2) FreiChatPure component before 1.2.2 for Jo… Patch early 4.3 medium 1.7% 2011-10-09
CVE-2018-11508 EXP The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memo… Patch early 5.5 medium 1.7% 2018-05-28
CVE-2002-1497 EXP Cross-site scripting (XSS) vulnerability in Null HTTP Server 0.5.0 and earlier allows remote attackers to insert arbitrary HTML into a "404 Not Found"… Patch early 4.3 medium 1.7% 2003-04-02
CVE-2005-0548 EXP Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 1.7% 2005-03-07
CVE-2005-0829 EXP Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitrary web scr… Patch early 4.3 medium 1.7% 2005-05-02
CVE-2005-2560 EXP Cross-site scripting (XSS) vulnerability in index.cfm in CFBB 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the page parame… Patch early 4.3 medium 1.7% 2005-08-16
CVE-2006-0073 EXP Cross-site scripting (XSS) vulnerability in DiscusWare Discus Freeware 3.10.5 and Professional 3.10.4 allows remote attackers to inject arbitrary web… Patch early 4.3 medium 1.7% 2006-01-04
CVE-2023-0904 EXP A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been rated as critical. This issue affects some unknown proces… Patch early 6.3 medium 1.7% 2023-02-18
CVE-2003-0165 EXP Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument f… Patch early 4.6 medium 1.7% 2003-04-02
CVE-2006-0198 EXP Cross-site scripting (XSS) vulnerability in a certain module, possibly poll or Pool, for XOOPS allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 1.7% 2006-01-13
CVE-2026-33534 EXP EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have an authenticated Server-Side Request Forgery (SS… Patch early 4.3 medium 1.7% 2026-04-13
CVE-2008-5979 EXP Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Mailing List Manager Gold allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 1.7% 2009-01-27
CVE-2018-11715 EXP The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject. Patch early 5.4 medium 1.7% 2018-06-04
CVE-2006-1008 EXP Multiple cross-site scripting (XSS) vulnerabilities in N8cms 1.1 and 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) dir… Patch early 5.8 medium 1.7% 2006-03-06
CVE-2012-1470 EXP Multiple cross-site scripting (XSS) vulnerabilities in code_editor.php in ocPortal before 7.1.6 allow remote attackers to inject arbitrary web script… Patch early 4.3 medium 1.7% 2012-10-01
CVE-2013-0125 EXP Cross-site scripting (XSS) vulnerability in fileview.asp in C2 WebResource allows remote attackers to inject arbitrary web script or HTML via the File… Patch early 4.3 medium 1.7% 2013-04-04
CVE-2011-4403 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote attackers to hijack the authentication of administrators fo… Patch early 5.8 medium 1.7% 2015-04-24
CVE-2009-2641 EXP PHP remote file inclusion vulnerability in app_and_readme/navigator/index.php in School Data Navigator allows remote attackers to execute arbitrary PH… Patch early 6.8 medium 1.7% 2009-07-28
CVE-2006-4988 EXP Multiple cross-site scripting (XSS) vulnerabilities in Patrick Michaelis Wili-CMS allow remote attackers to inject arbitrary web script or HTML via (1… Patch early 4.3 medium 1.7% 2006-09-26
CVE-2006-5503 EXP Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) 1.1 RC2 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 1.7% 2006-10-25
CVE-2006-5652 EXP Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via… Patch early 4.3 medium 1.7% 2006-11-03
← previous page 274 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt