peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,813 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-8732 EXP Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_del parame… Patch early 5.4 medium 1.7% 2018-03-19
CVE-2012-2910 EXP Multiple cross-site scripting (XSS) vulnerabilities in SiliSoftware phpThumb() 1.7.11 allow remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 1.7% 2012-05-21
CVE-2009-4319 EXP PHP remote file inclusion vulnerability in js/bbcodepress/bbcode-form.php in eoCMS 0.9.03 and earlier, when register_globals is enabled, allows remote… Patch early 6.8 medium 1.7% 2009-12-14
CVE-2018-10763 EXP Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2) Sub heading fields in the Pa… Patch early 4.8 medium 1.7% 2018-09-14
CVE-2018-18416 EXP LANGO Codeigniter Multilingual Script 1.0 has XSS in the input and upload sections, as demonstrated by the site_name parameter to the admin/settings/u… Patch early 4.8 medium 1.7% 2018-10-19
CVE-2006-3358 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via… Patch early 6.8 medium 1.6% 2006-07-06
CVE-2009-4174 EXP The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with… Patch early 6.0 medium 1.6% 2009-12-02
CVE-2016-2782 EXP The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of servi… Patch early 4.6 medium 1.6% 2016-04-27
CVE-2011-5209 EXP Cross-site scripting (XSS) vulnerability in search/ in GraphicsClone Script, possibly 1.11, allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 1.6% 2012-10-09
CVE-2012-4266 EXP Cross-site scripting (XSS) vulnerability in client_details.php in Proman Xpress 5.0.1 allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 1.6% 2012-08-13
CVE-2012-4278 EXP Multiple cross-site scripting (XSS) vulnerabilities in Free Realty 3.1-0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) n… Patch early 4.3 medium 1.6% 2012-08-13
CVE-2003-0521 EXP Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly gain cPanel administrator privi… Patch early 6.8 medium 1.6% 2003-08-18
CVE-2005-0896 EXP Multiple cross-site scripting (XSS) vulnerabilities in review.php in phpMyDirectory 10.1.3-rel allow remote attackers to inject arbitrary web script o… Patch early 4.3 medium 1.6% 2005-05-02
CVE-2012-3805 EXP Multiple cross-site scripting (XSS) vulnerabilities in the getAllPassedParams function in system/functions.php in Kajona before 3.4.2 allow remote att… Patch early 4.3 medium 1.6% 2012-07-12
CVE-2012-5228 EXP Cross-site scripting (XSS) vulnerability in admin/index.php in phplist 2.10.9, 2.10.17, and possibly other versions before 2.10.19 allows remote attac… Patch early 4.3 medium 1.6% 2012-10-01
CVE-2009-4908 EXP Multiple cross-site scripting (XSS) vulnerabilities in oBlog allow remote attackers to inject arbitrary web script or HTML via the (1) commentName, (2… Patch early 4.3 medium 1.6% 2010-06-25
CVE-2018-14497 EXP Tenda D152 ADSL routers allow XSS via a crafted SSID. Patch early 5.4 medium 1.6% 2018-08-04
CVE-2018-18417 EXP In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parame… Patch early 5.4 medium 1.6% 2018-10-19
CVE-2018-18419 EXP Stored XSS has been discovered in the upload section of ARDAWAN.COM User Management 1.1, as demonstrated by a .jpg filename to the /account URI. Patch early 5.4 medium 1.6% 2018-10-19
CVE-2013-4951 EXP Multiple cross-site scripting (XSS) vulnerabilities in Mintboard 0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or… Patch early 4.3 medium 1.6% 2013-07-29
CVE-2013-6042 EXP Cross-site scripting (XSS) vulnerability in filemanager/login.php in the File Manager module in Softaculous Webuzo before 2.1.4 allows remote attacker… Patch early 4.3 medium 1.6% 2013-11-19
CVE-2011-4551 EXP Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote attackers to inj… Patch early 4.3 medium 1.6% 2012-10-01
CVE-2012-4745 EXP Cross-site scripting (XSS) vulnerability in admin/login.asp in Acuity CMS 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.6% 2012-08-31
CVE-2008-2701 EXP SQL injection vulnerability in the GameQ (com_gameq) component 4.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands v… Patch early 6.8 medium 1.6% 2008-06-13
CVE-2007-3876 EXP Stack-based buffer overflow in SMB in Apple Mac OS X 10.4.11 allows local users to execute arbitrary code via (1) a long workgroup (-W) option to moun… Patch early 6.6 medium 1.6% 2007-12-19
CVE-2009-3508 EXP Multiple directory traversal vulnerabilities in MUJE CMS 1.0.4.34 allow remote attackers to include and execute arbitrary local files via a .. (dot do… Patch early 6.0 medium 1.6% 2009-10-01
CVE-2009-2438 EXP Cross-site scripting (XSS) vulnerability in index.php in the search module in ClanSphere 2009.0 and 2009.0.2 allows remote attackers to inject arbitra… Patch early 4.3 medium 1.6% 2009-07-13
CVE-2007-3133 EXP SQL injection vulnerability in urunbak.asp in W1L3D4 WEBmarket 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. Patch early 6.8 medium 1.6% 2007-06-08
CVE-2007-6552 EXP Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitrary local files via a ..… Patch early 6.0 medium 1.6% 2007-12-28
CVE-2012-5908 EXP Cross-site scripting (XSS) vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to inject arbitra… Patch early 4.3 medium 1.6% 2012-11-17
← previous page 276 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt