peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,166 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-0620 EXP Multiple cross-site scripting (XSS) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote attackers to inject arbitrary web… Patch early 4.3 medium 1.4% 2014-01-08
CVE-2020-29469 EXP WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacker to inject the XSS payload in… Patch early 5.4 medium 1.4% 2020-12-30
CVE-2005-2523 EXP Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script… Patch early 4.3 medium 1.4% 2005-08-19
CVE-2004-2288 EXP Cross-site scripting (XSS) vulnerability in index.php in Jelsoft vBulletin allows remote attackers to spoof parts of a website via the loc parameter. Patch early 4.3 medium 1.4% 2004-12-31
CVE-2005-2386 EXP Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ 1.20 allows remote attackers to inject arbitrary web script or HTML via the messag… Patch early 4.3 medium 1.4% 2005-07-27
CVE-2005-3083 EXP Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 0.10 allows remote attackers to inject arbitrary web script or HTML via the p… Patch early 4.3 medium 1.4% 2005-09-27
CVE-2005-3584 EXP Cross-site scripting (XSS) vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to inject arbitrary web script or HTML via the for… Patch early 4.3 medium 1.4% 2005-11-16
CVE-2005-4289 EXP Cross-site scripting (XSS) vulnerability in EDCstore.pl in eDatCat 0.3 allows remote attackers to inject arbitrary web script or HTML via the user_act… Patch early 4.3 medium 1.4% 2005-12-16
CVE-2005-4588 EXP Cross-site scripting (XSS) vulnerability in Koobi 5 allows remote attackers to inject arbitrary web script or HTML via nested, malformed url BBCode ta… Patch early 4.3 medium 1.4% 2005-12-30
CVE-2006-1535 EXP Cross-site scripting (XSS) vulnerability in login.php in Phoetux.net PhxContacts 0.93.1 beta and earlier allows remote attackers to inject arbitrary w… Patch early 4.3 medium 1.4% 2006-03-30
CVE-2017-17752 EXP Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka… Patch early 6.1 medium 1.4% 2017-12-20
CVE-2014-0981 EXP VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4… Patch early 4.4 medium 1.4% 2014-03-31
CVE-2020-35687 EXP PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in vic… Patch early 4.3 medium 1.4% 2021-01-13
CVE-2006-6410 EXP Buffer overflow in an ActiveX control in VMWare 5.5.1 allows local users to execute arbitrary code via a long VmdbDb parameter to the Initialize funct… Patch early 4.6 medium 1.4% 2006-12-10
CVE-2006-1001 EXP SQL injection vulnerability in the board module in LanSuite LanParty Intranet System 2.0.6 and 2.1.0 beta allows remote attackers to execute arbitrary… Patch early 5.0 medium 1.4% 2006-03-06
CVE-2012-3872 EXP Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrary web script or HTML via (1) t… Patch early 4.3 medium 1.4% 2012-12-28
CVE-2023-1998 EXP The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which disables the speculation feature… Patch early 5.6 medium 1.4% 2023-04-21
CVE-2008-2087 EXP SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to e… Patch early 6.8 medium 1.4% 2008-05-06
CVE-2006-0903 EXP MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handl… Patch early 4.6 medium 1.4% 2006-02-27
CVE-2009-3805 EXP gpg2.exe in Gpg4win 2.0.1, as used in KDE Kleopatra 2.0.11, allows remote attackers to cause a denial of service (application crash) via a long certif… Patch early 4.3 medium 1.4% 2009-10-27
CVE-2013-4888 EXP Cross-site scripting (XSS) vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.4% 2014-01-29
CVE-2005-1076 EXP Cross-site scripting (XSS) vulnerability in the discussion board functionality for WebCT Campus Edition 4.1 allows remote attackers to inject arbitrar… Patch early 4.3 medium 1.4% 2005-05-02
CVE-2025-26263 EXP GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to credentials disclosure due to impr… Patch early 5.1 medium 1.4% 2025-02-28
CVE-2000-0338 EXP Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creatin… Patch early 5.5 medium 1.4% 2000-04-23
CVE-2014-2987 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition befor… Patch early 6.8 medium 1.4% 2014-10-26
CVE-2000-0987 EXP Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter. Patch early 4.6 medium 1.4% 2000-12-19
CVE-2009-1623 EXP Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary web script or HTML via the PI… Patch early 4.3 medium 1.4% 2009-05-12
CVE-2018-10507 EXP A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or render the OfficeScan Unauthor… Patch early 4.4 medium 1.4% 2018-06-12
CVE-2007-5923 EXP Cross-site scripting (XSS) vulnerability in forms/smpwservices.fcc in CA (formerly Computer Associates) eTrust SiteMinder Agent allows remote attacker… Patch early 4.3 medium 1.4% 2007-11-10
CVE-2017-7620 EXP MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpreta… Patch early 6.5 medium 1.4% 2017-05-21
← previous page 302 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt