peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,458 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

169,714 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-2779 EXP The Social Share, Social Login and Social Comments WordPress plugin before 7.13.52 does not sanitise and escape a parameter before outputting it back… Patch early 6.1 medium 6% 2023-06-19
CVE-2005-2543 EXP Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) i… Patch early 5.0 medium 6% 2005-08-10
CVE-2017-3631 EXP Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11. Easi… Patch early 5.3 medium 6% 2017-06-22
CVE-2007-3233 EXP The TEC-IT TBarCode OCX ActiveX control (TBarCode7.ocx) 7.0.2.3524 allows remote attackers to overwrite arbitrary files via the SaveImage method. Patch early 5.0 medium 6% 2007-06-15
CVE-2006-3533 EXP Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allow remote attackers to inject… Patch early 5.8 medium 6% 2006-07-12
CVE-2011-5105 EXP Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in ZOHO ManageEngine ADSelfService Plus 4.5 Build 4521 allow remote attackers… Patch early 4.3 medium 6% 2012-08-23
CVE-2012-2602 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers… Patch early 6.8 medium 6% 2012-08-12
CVE-2006-5310 EXP PHP remote file inclusion vulnerability in common/visiteurs/include/menus.inc.php in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences… Patch early 6.8 medium 6% 2006-10-17
CVE-2009-0855 EXP Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 on z/OS allows re… Patch early 4.3 medium 6% 2009-03-09
CVE-2006-6453 EXP PHP remote file inclusion vulnerability in JOWAMP_ShowPage.php in J-OWAMP Web Interface 2.1 allows remote authenticated users to execute arbitrary PHP… Patch early 6.5 medium 6% 2006-12-10
CVE-2014-3849 EXP The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users… Patch early 4.3 medium 6% 2014-05-23
CVE-1999-0264 EXP htmlscript CGI program allows remote read access to files. Patch early 5.0 medium 6% 1998-01-27
CVE-2013-0663 EXP Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE01… Patch early 6.8 medium 6% 2013-04-04
CVE-2002-0898 EXP Opera 6.0.1 and 6.0.2 allows a remote web site to upload arbitrary files from the client system, without prompting the client, via an input type=file… Patch early 5.0 medium 6% 2002-10-04
CVE-2004-0639 EXP Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (… Patch early 6.8 medium 6% 2004-08-06
CVE-2015-0107 EXP IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 an… Patch early 6.5 medium 6% 2017-04-24
CVE-2018-16606 EXP In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted papers (Title and Abstract) and the… Patch early 6.5 medium 5.9% 2018-09-06
CVE-2017-14939 EXP decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles a length calcul… Patch early 5.5 medium 5.9% 2017-09-30
CVE-1999-1015 EXP Buffer overflow in Apple AppleShare Mail Server 5.0.3 on MacOS 8.1 and earlier allows a remote attacker to cause a denial of service (crash) via a lon… Patch early 5.0 medium 5.9% 1998-04-08
CVE-2019-7441 EXP cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount paramet… Patch early 6.5 medium 5.9% 2019-03-21
CVE-2009-2653 EXP The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass… Patch early 4.6 medium 5.9% 2009-08-03
CVE-2006-2119 EXP PHP remote file inclusion vulnerability in event/index.php in Artmedic Event allows remote attackers to execute arbitrary code via a URL in the page p… Patch early 5.0 medium 5.9% 2006-05-01
CVE-2009-3053 EXP Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local… Patch early 6.8 medium 5.9% 2009-09-03
CVE-2007-1582 EXP The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting ce… Patch early 6.8 medium 5.9% 2007-03-21
CVE-2019-12189 EXP An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field. Patch early 6.1 medium 5.9% 2019-05-21
CVE-2000-0039 EXP AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cgi CGI program. Patch early 5.0 medium 5.9% 1999-12-29
CVE-2000-0174 EXP StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. Patch early 5.0 medium 5.9% 2000-03-09
CVE-2000-0192 EXP The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote attackers to determine what packages are ins… Patch early 5.0 medium 5.9% 2000-03-05
CVE-2000-0236 EXP Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web publishing tags such as ?wp-ver-… Patch early 5.0 medium 5.9% 2000-03-17
CVE-2000-0430 EXP Cart32 allows remote attackers to access sensitive debugging information by appending /expdate to the URL request. Patch early 5.0 medium 5.9% 2000-05-03
← previous page 104 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt