peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,370 CVEs 1,739 on KEV 17,299 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2020-12704 EXP UliCMS before 2020.2 has PageController stored XSS. Patch early 6.1 medium 1.2% 2020-05-07
CVE-2012-4877 EXP Cross-site request forgery (CSRF) vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 and earlier allows remote attackers to hijack the aut… Patch early 6.8 medium 1.2% 2012-09-06
CVE-2018-12904 EXP In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause L1 KVM guests to VMEXIT, pote… Patch early 4.9 medium 1.2% 2018-06-27
CVE-2010-4151 EXP SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute a… Patch early 6.8 medium 1.2% 2010-11-03
CVE-2016-6828 EXP The tcp_check_send_head function in include/net/tcp.h in the Linux kernel before 4.7.5 does not properly maintain certain SACK state after a failed da… Patch early 5.5 medium 1.2% 2016-10-16
CVE-2007-4863 EXP SQL injection vulnerability in example.php in SAXON 5.4 allows remote attackers to execute arbitrary SQL commands via the template parameter. Patch early 6.8 medium 1.2% 2007-10-30
CVE-2018-4863 EXP Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\Current… Patch early 5.5 medium 1.2% 2018-04-05
CVE-2007-1293 EXP SQL injection vulnerability in Rigter Portal System (RPS) 6.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL com… Patch early 5.8 medium 1.2% 2007-03-07
CVE-2009-3420 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Publisher module 2.0 for Miniweb allow remote attackers to inject arbitrary we… Patch early 4.3 medium 1.2% 2009-09-25
CVE-2009-4552 EXP Cross-site scripting (XSS) vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to inject arbitrary web script or HTML via t… Patch early 4.3 medium 1.2% 2010-01-04
CVE-2009-4651 EXP Multiple cross-site scripting (XSS) vulnerabilities in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allow remote at… Patch early 4.3 medium 1.2% 2010-02-22
CVE-2009-4780 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in phpMyFAQ before 2.5.5 allow remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 1.2% 2010-04-21
CVE-2010-2700 EXP Cross-site scripting (XSS) vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to inject a… Patch early 4.3 medium 1.2% 2010-07-12
CVE-2008-6597 EXP Cross-site scripting (XSS) vulnerability in upload/install/index.php in PHCDownload 1.1 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.2% 2009-04-03
CVE-2001-0653 EXP Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privileges via a large value in the 'ca… Patch early 4.6 medium 1.2% 2001-09-20
CVE-2003-1310 EXP The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwr… Patch early 4.6 medium 1.2% 2003-12-31
CVE-2006-5829 EXP Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to execute arbitrary SQL command… Patch early 6.8 medium 1.2% 2006-11-10
CVE-2005-1708 EXP templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP… Patch early 4.6 medium 1.2% 2005-05-24
CVE-2008-0324 EXP Cisco Systems VPN Client IPSec Driver (CVPNDRVA.sys) 5.0.02.0090 allows local users to cause a denial of service (crash) by calling the 0x80002038 IOC… Patch early 4.9 medium 1.2% 2008-01-17
CVE-2009-0036 EXP Buffer overflow in the proxyReadClientSocket function in proxy/libvirt_proxy.c in libvirt_proxy 0.5.1 might allow local users to gain privileges by se… Patch early 4.4 medium 1.2% 2009-02-11
CVE-2007-2752 EXP SQL injection vulnerability in devami.asp in RunawaySoft Haber portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id paramet… Patch early 6.4 medium 1.2% 2007-05-17
CVE-2009-1778 EXP SQL injection vulnerability in the new user registration feature in BigACE CMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to exec… Patch early 6.8 medium 1.2% 2009-05-22
CVE-2009-4349 EXP Cross-site request forgery (CSRF) vulnerability in administration/administrators.php in Link Up Gold 5.0 allows remote attackers to hijack the authent… Patch early 6.8 medium 1.2% 2009-12-17
CVE-2007-4645 EXP SQL injection vulnerability in index.php in NMDeluxe 2.0.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a newspos… Patch early 6.4 medium 1.2% 2007-08-31
CVE-2006-6343 EXP SQL injection vulnerability in polls.php in Neocrome Seditio 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the id par… Patch early 6.8 medium 1.2% 2006-12-07
CVE-2012-4054 EXP Buffer overflow in the readfile function in CPE17 Autorun Killer 1.7.1 and earlier allows physically proximate attackers to execute arbitrary code via… Patch early 6.9 medium 1.2% 2012-07-25
CVE-2013-5730 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DSL-2740B Gateway with firmware EU_1.00 allow remote attackers to hijack the auth… Patch early 6.8 medium 1.2% 2013-11-20
CVE-2008-0538 EXP Multiple SQL injection vulnerabilities in phpIP Management 4.3.2 allow remote attackers to execute arbitrary SQL commands via the (1) password paramet… Patch early 6.8 medium 1.2% 2008-02-01
CVE-2006-1864 EXP Directory traversal vulnerability in smbfs in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem… Patch early 4.6 medium 1.2% 2006-04-26
CVE-2024-50562 EXP An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 al… Patch early 4.8 medium 1.2% 2025-06-10
← previous page 310 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt