peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,367 CVEs 1,739 on KEV 17,299 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-6004 EXP Cross-site scripting (XSS) vulnerability in search.php in AJ Auction Pro Platinum 2 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.2% 2009-01-28
CVE-2009-2127 EXP Cross-site scripting (XSS) vulnerability in show_activity.php in Elvin 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the id… Patch early 4.3 medium 1.2% 2009-06-19
CVE-2009-2219 EXP Multiple cross-site scripting (XSS) vulnerabilities in phpCollegeExchange 0.1.5c allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.2% 2009-06-25
CVE-2006-6339 EXP SQL injection vulnerability in sites/index.php in deV!L`z Clanportal (DZCP) before 1.3.6.1 allows remote attackers to execute arbitrary SQL commands v… Patch early 6.8 medium 1.2% 2006-12-07
CVE-2013-3729 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Kasseler CMS before 2 r1232 allow remote attackers to hijack the authentication of admin… Patch early 6.8 medium 1.2% 2014-03-13
CVE-2008-4457 EXP SQL injection vulnerability in inc/inc_statistics.php in MemHT Portal 3.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to… Patch early 6.8 medium 1.2% 2008-10-07
CVE-2008-1917 EXP Multiple cross-site scripting (XSS) vulnerabilities in AMFPHP 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) class para… Patch early 4.3 medium 1.2% 2008-04-23
CVE-2008-6562 EXP Cross-site scripting (XSS) vulnerability in jax_linklists.php in Jack (tR) Jax LinkLists 1.00 allows remote attackers to inject arbitrary web script o… Patch early 4.3 medium 1.2% 2009-03-31
CVE-2007-5235 EXP Cross-site scripting (XSS) vulnerability in index.php in Uebimiau 2.7.2 through 2.7.10 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.2% 2007-10-06
CVE-2006-2126 EXP SQL injection vulnerability in pocategories.php in MaxTrade 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) ca… Patch early 6.4 medium 1.2% 2006-05-01
CVE-2006-2293 EXP SQL injection vulnerability in all_calendars.asp in MultiCalendars 3.0 allows remote attackers to execute arbitrary SQL commands via the calsids param… Patch early 6.4 medium 1.2% 2006-05-10
CVE-2006-2296 EXP SQL injection vulnerability in search_result.asp in EDirectoryPro 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ke… Patch early 6.4 medium 1.2% 2006-05-10
CVE-2006-2638 EXP SQL injection vulnerability in member.asp in qjForum allows remote attackers to execute arbitrary SQL commands via the uName parameter. Patch early 6.4 medium 1.2% 2006-05-30
CVE-2005-4656 EXP SQL injection vulnerability in index.php in TClanPortal 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands, and retrieve all… Patch early 5.0 medium 1.2% 2005-12-31
CVE-2009-0711 EXP filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable par… Patch early 5.0 medium 1.2% 2009-02-23
CVE-2008-0722 EXP Cross-site scripting (XSS) vulnerability in index.php in Pagetool 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the search_… Patch early 4.3 medium 1.2% 2008-02-12
CVE-2008-6607 EXP Cross-site scripting (XSS) vulnerability in view.php in MatPo Link 1.2 Beta allows remote attackers to inject arbitrary web script or HTML via the the… Patch early 4.3 medium 1.2% 2009-04-06
CVE-2010-2675 EXP Cross-site scripting (XSS) vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 1.2% 2010-07-08
CVE-2009-1661 EXP SQL injection vulnerability in admin/utopic.php in uTopic 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL com… Patch early 6.8 medium 1.2% 2009-05-18
CVE-2017-4905 EXP VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 witho… Patch early 5.5 medium 1.2% 2017-06-07
CVE-2009-0764 EXP Multiple cross-site scripting (XSS) vulnerabilities in Kipper 2.01 allow remote attackers to inject arbitrary web script or HTML via the charm paramet… Patch early 4.3 medium 1.2% 2009-03-06
CVE-2009-2930 EXP Cross-site scripting (XSS) vulnerability in the Search feature in elka CMS (aka Elkapax) allows remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 1.2% 2009-08-21
CVE-2009-2965 EXP Cross-site scripting (XSS) vulnerability in entry/index.jsp in Radvision Scopia 5.7, and possibly other versions before SD 7.0.100, allows remote atta… Patch early 4.3 medium 1.2% 2009-08-25
CVE-2009-4746 EXP Cross-site scripting (XSS) vulnerability in index.php in Dreamlevels DreamPoll 3.1 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.2% 2010-03-26
CVE-2010-1052 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.2% 2010-03-23
CVE-2020-12882 EXP Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a Teaching Fellow. Patch early 5.4 medium 1.2% 2020-05-15
CVE-1999-0711 EXP The oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl commands as root. Patch early 4.6 medium 1.2% 1999-04-29
CVE-2016-4578 EXP sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive inform… Patch early 5.5 medium 1.2% 2016-05-23
CVE-2002-1349 EXP Buffer overflow in pop3trap.exe for PC-cillin 2000, 2002, and 2003 allows local users to execute arbitrary code via a long input string to TCP port 11… Patch early 4.6 medium 1.2% 2002-12-18
CVE-2013-1120 EXP Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow remote attackers to hijack the au… Patch early 6.8 medium 1.2% 2013-02-06
← previous page 308 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt