peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,169 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-4983 EXP Multiple cross-site scripting (XSS) vulnerabilities in Silurus Classifieds 1.0 allow remote attackers to inject arbitrary web script or HTML via the I… Patch early 4.3 medium 1.3% 2010-08-25
CVE-2023-27636 EXP Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor. Patch early 5.4 medium 1.3% 2024-06-16
CVE-2015-7903 EXP SQL injection vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execut… Patch early 6.5 medium 1.3% 2015-10-28
CVE-2015-7890 EXP Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung S6 Edge, allow local users to… Patch early 5.5 medium 1.3% 2020-02-12
CVE-2020-29233 EXP WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allow an attacker to inject the XS… Patch early 5.4 medium 1.3% 2020-12-30
CVE-2006-6129 EXP Integer overflow in the fatfile_getarch2 in Apple Mac OS X allows local users to cause a denial of service and possibly execute arbitrary code via a c… Patch early 4.6 medium 1.3% 2006-11-27
CVE-2000-0972 EXP HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session,… Patch early 5.5 medium 1.3% 2000-12-19
CVE-2001-0565 EXP Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option. Patch early 4.6 medium 1.3% 2001-08-14
CVE-2006-1113 EXP SQL injection vulnerability in podcast.php in Loudblog before 0.42 allows remote attackers to execute arbitrary SQL commands via the id parameter. Patch early 5.0 medium 1.3% 2006-03-09
CVE-2020-29471 EXP OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as a malicious code using JavaScr… Patch early 4.8 medium 1.3% 2020-12-29
CVE-2007-3977 EXP Cross-site scripting (XSS) vulnerability in bwired allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Patch early 4.3 medium 1.3% 2007-07-25
CVE-2009-3506 EXP Multiple cross-site scripting (XSS) vulnerabilities in CMSphp 0.21 allow remote attackers to inject arbitrary web script or HTML via the (1) cook_user… Patch early 4.3 medium 1.3% 2009-10-01
CVE-2009-4984 EXP Multiple cross-site scripting (XSS) vulnerabilities in Accessories Me PHP Affiliate Script 1.4 allow remote attackers to inject arbitrary web script o… Patch early 4.3 medium 1.3% 2010-08-25
CVE-2009-1951 EXP Cross-site scripting (XSS) vulnerability in index.php in PropertyMax Pro FREE 0.3 allows remote attackers to inject arbitrary web script or HTML via t… Patch early 4.3 medium 1.3% 2009-06-05
CVE-2009-2020 EXP Cross-site scripting (XSS) vulnerability in news_detail.php in Virtue News Manager allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.3% 2009-06-09
CVE-2009-2149 EXP Multiple cross-site scripting (XSS) vulnerabilities in Campus Virtual-LMS allow remote attackers to inject arbitrary web script or HTML via the (1) co… Patch early 4.3 medium 1.3% 2009-06-22
CVE-2009-3162 EXP Cross-site scripting (XSS) vulnerability in Multi Website 1.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter… Patch early 4.3 medium 1.3% 2009-09-10
CVE-2009-3260 EXP Cross-site scripting (XSS) vulnerability in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTML via the header of the topic… Patch early 4.3 medium 1.3% 2009-09-18
CVE-2009-3833 EXP Cross-site scripting (XSS) vulnerability in index.php in TFTgallery 0.13 allows remote attackers to inject arbitrary web script or HTML via the album… Patch early 4.3 medium 1.3% 2009-11-02
CVE-2009-3901 EXP Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web script or HTML via the UserGUID pa… Patch early 4.3 medium 1.3% 2009-11-06
CVE-2009-4234 EXP Cross-site scripting (XSS) vulnerability in loginpages/error_user.shtml on the Micronet Network Access Controller SP1910 allows remote attackers to in… Patch early 4.3 medium 1.3% 2009-12-08
CVE-2009-4858 EXP Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 1.3% 2010-05-11
CVE-2009-4868 EXP Cross-site scripting (XSS) vulnerability in Hitron Soft Answer Me 1.0 allows remote attackers to inject arbitrary web script or HTML via the q_id para… Patch early 4.3 medium 1.3% 2010-05-11
CVE-2009-4991 EXP Cross-site scripting (XSS) vulnerability in users/resume_register.php in Omnistar Recruiting allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 1.3% 2010-08-25
CVE-2010-1112 EXP Cross-site scripting (XSS) vulnerability in cat.php in KloNews 2.0 allows remote attackers to inject arbitrary web script or HTML via the cat paramete… Patch early 4.3 medium 1.3% 2010-03-25
CVE-2012-5377 EXP Untrusted search path vulnerability in the installation functionality in ActivePerl 5.16.1.1601, when installed in the top-level C:\ directory, allows… Patch early 6.0 medium 1.3% 2012-10-11
CVE-2002-2087 EXP Buffer overflow in Borland InterBase 6.0 allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_d… Patch early 4.6 medium 1.3% 2002-12-31
CVE-2006-2339 EXP SQL injection vulnerability in index.php in evoTopsites 2.x and evoTopsites Pro 2.x allows remote attackers to execute arbitrary SQL commands via the… Patch early 6.4 medium 1.3% 2006-05-12
CVE-2016-1885 EXP Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1 before p31, and 10.2 before p1… Patch early 6.2 medium 1.3% 2016-04-12
CVE-2009-2138 EXP Multiple open redirect vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to redirect users to arbitrary web sites and conduct phishing atta… Patch early 4.3 medium 1.3% 2009-06-19
← previous page 305 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt