peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,939 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-30256 EXP Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_cre… Patch early 6.1 medium 9.1% 2023-05-11
CVE-2019-12962 EXP LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header. Patch early 6.1 medium 9.1% 2019-06-25
CVE-2018-15768 EXP Dell OpenManage Network Manager versions prior to 6.5.0 enabled read/write access to the file system for MySQL users due to insecure default configura… Patch early 6.5 medium 9.1% 2018-11-30
CVE-2009-0037 EXP The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which… Patch early 6.8 medium 9.1% 2009-03-05
CVE-2003-0511 EXP The web server for Cisco Aironet AP1x00 Series Wireless devices running certain versions of IOS 12.2 allow remote attackers to cause a denial of servi… Patch early 5.0 medium 9% 2003-08-27
CVE-2014-9261 EXP The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to rea… Patch early 5.0 medium 9% 2015-03-23
CVE-2007-0676 EXP SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. Patch early 6.8 medium 9% 2007-02-03
CVE-2009-0677 EXP avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to exec… Patch early 6.5 medium 9% 2009-02-22
CVE-2000-0656 EXP Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the FTP proto… Patch early 5.0 medium 9% 2000-07-25
CVE-2009-1220 EXP Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30… Patch early 4.3 medium 9% 2009-04-01
CVE-2008-0132 EXP Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message window and waiting for the adminis… Patch early 5.0 medium 9% 2008-01-08
CVE-2004-1965 EXP Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbitrary web… Patch early 4.3 medium 9% 2004-04-25
CVE-2006-4126 EXP The dc_chat function in cmd.dc.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to cause a denial of service (application crash) by send… Patch early 5.0 medium 9% 2006-08-14
CVE-2006-4192 EXP Multiple buffer overflows in MODPlug Tracker (OpenMPT) 1.17.02.43 and earlier and libmodplug 0.8 and earlier, as used in GStreamer and possibly other… Patch early 5.1 medium 9% 2006-08-17
CVE-2020-25495 EXP A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote attackers to inject arbitrary we… Patch early 6.1 medium 9% 2020-12-18
CVE-2007-4802 EXP Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a long eighth argument to the SetI… Patch early 6.8 medium 9% 2007-09-11
CVE-2011-2744 EXP Directory traversal vulnerability in Chyrp 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded d… Patch early 6.8 medium 9% 2011-07-19
CVE-2012-0788 EXP The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of… Patch early 5.0 medium 9% 2012-02-14
CVE-2004-1269 EXP lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subs… Patch early 5.0 medium 9% 2005-01-10
CVE-2009-4495 EXP Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or pos… Patch early 5.0 medium 9% 2010-01-13
CVE-2019-3474 EXP A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authenticated as a low privilege user… Patch early 6.5 medium 9% 2019-02-20
CVE-2009-2285 EXP Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial of service (crash) via a crafte… Patch early 4.3 medium 9% 2009-07-01
CVE-2008-3286 EXP SWAT 4 1.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via a (1) VERIFYCONTENT or (2) GAMECONFIG command sent to t… Patch early 5.0 medium 8.9% 2008-07-24
CVE-2012-1835 EXP Multiple cross-site scripting (XSS) vulnerabilities in the All-in-One Event Calendar plugin 1.4 and 1.5 for WordPress allow remote attackers to inject… Patch early 4.3 medium 8.9% 2012-08-14
CVE-2001-0080 EXP Cisco Catalyst 6000, 5000, or 4000 switches allow remote attackers to cause a denial of service by connecting to the SSH service with a non-SSH client… Patch early 5.0 medium 8.9% 2001-02-12
CVE-2016-4004 EXP Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated administrators to read arbitrary file… Patch early 4.9 medium 8.9% 2016-04-12
CVE-2009-4494 EXP AOLserver 4.5.1 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title,… Patch early 5.0 medium 8.9% 2010-01-13
CVE-2008-1561 EXP Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of service (appli… Patch early 5.0 medium 8.9% 2008-03-31
CVE-2003-0211 EXP Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections. Patch early 5.0 medium 8.9% 2003-05-05
CVE-2008-5642 EXP Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a… Patch early 5.0 medium 8.9% 2008-12-17
← previous page 59 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt