peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,265 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

10,151 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-5634 EXP Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) r… Patch early 6.8 medium 6.2% 2006-11-01
CVE-2010-3070 EXP Cross-site scripting (XSS) vulnerability in NuSOAP 0.9.5, as used in MantisBT and other products, allows remote attackers to inject arbitrary web scri… Patch early 4.3 medium 6.2% 2010-09-28
CVE-2013-5688 EXP Multiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and earlier allow remote authenticated users to read arbitrary files via… Patch early 5.5 medium 6.2% 2013-11-05
CVE-2019-9834 EXP The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injecti… Patch early 6.1 medium 6.2% 2019-03-15
CVE-2000-0720 EXP news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to ad… Patch early 5.0 medium 6.2% 2000-10-20
CVE-1999-0175 EXP The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web ser… Patch early 5.0 medium 6.2% 1996-07-01
CVE-2019-12562 EXP Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin no… Patch early 6.1 medium 6.2% 2019-09-26
CVE-2019-9816 EXP A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of se… Patch early 5.9 medium 6.2% 2019-07-23
CVE-2017-9259 EXP The TDStretch::acceptNewOverlapLength function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of ser… Patch early 5.5 medium 6.2% 2017-07-27
CVE-2017-15287 EXP There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouquets" field, or the file param… Patch early 6.1 medium 6.1% 2017-10-12
CVE-2006-4310 EXP Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FTP response, when attempting to connect with a use… Patch early 4.3 medium 6.1% 2006-08-23
CVE-2015-1481 EXP Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a superuser account. Patch early 6.5 medium 6.1% 2015-02-04
CVE-2007-5812 EXP Directory traversal vulnerability in modules/Builder/DownloadModule.php in ModuleBuilder 1.0 allows remote attackers to read arbitrary files via a ..… Patch early 5.0 medium 6.1% 2007-11-05
CVE-2009-2180 EXP Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attackers to read arbitrary files via… Patch early 5.0 medium 6.1% 2009-06-23
CVE-2018-15740 EXP Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen. Patch early 6.1 medium 6.1% 2018-08-28
CVE-2005-4809 EXP Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in the Status Bar via a… Patch early 5.0 medium 6.1% 2005-12-31
CVE-2015-1366 EXP Cross-site scripting (XSS) vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to inject… Patch early 4.3 medium 6.1% 2015-01-27
CVE-2022-3766 EXP Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8. Patch early 6.1 medium 6.1% 2022-10-31
CVE-2007-6614 EXP PHP remote file inclusion vulnerability in admin/frontpage_right.php in Agares Media phpAutoVideo 2.21 allows remote attackers to execute arbitrary PH… Patch early 6.8 medium 6.1% 2008-01-03
CVE-2003-1397 EXP The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP request containing a long stri… Patch early 4.3 medium 6.1% 2003-12-31
CVE-2005-3133 EXP Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote att… Patch early 5.0 medium 6.1% 2005-10-04
CVE-2006-3277 EXP The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, allo… Patch early 5.0 medium 6.1% 2006-06-28
CVE-2007-1882 EXP qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment in HP Mercury Quality Center 9.0 build 9.1.0.4352 allows remote authenticated users to execute arbit… Patch early 6.5 medium 6.1% 2007-04-06
CVE-2005-2540 EXP CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII ch… Patch early 5.0 medium 6.1% 2005-08-10
CVE-2014-5345 EXP Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress allows remote attackers to injec… Patch early 4.3 medium 6.1% 2014-08-19
CVE-2005-4550 EXP The PORTAL schema in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to obtain the source code for arbitrary JSP… Patch early 5.0 medium 6.1% 2005-12-28
CVE-2007-1111 EXP Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css… Patch early 6.8 medium 6.1% 2007-02-26
CVE-2008-3304 EXP BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct reque… Patch early 5.0 medium 6.1% 2008-07-25
CVE-2006-4731 EXP Multiple directory traversal vulnerabilities in (1) login.pl and (2) admin.pl in (a) SQL-Ledger before 2.6.19 and (b) LedgerSMB before 1.0.0p1 allow r… Patch early 5.0 medium 6.1% 2006-09-13
CVE-2015-5285 EXP CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting atta… Patch early 5.0 medium 6.1% 2015-10-29
← previous page 96 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt