peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

169,938 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2003-0293 EXP PalmOS allows remote attackers to cause a denial of service (CPU consumption) via a flood of ICMP echo request (ping) packets. Patch early 5.0 medium 5.1% 2003-06-16
CVE-2012-2171 EXP SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Seri… Patch early 6.5 medium 5.1% 2012-06-22
CVE-2020-25901 EXP Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host heade… Patch early 6.1 medium 5.1% 2020-12-18
CVE-2007-3017 EXP The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/applets/wysiwyg/rende… Patch early 4.0 medium 5.1% 2007-07-17
CVE-2004-2040 EXP Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 pa… Patch early 4.3 medium 5.1% 2004-05-29
CVE-2004-2081 EXP The samiftp.dll library in Sami FTP Server 1.1.3 allows local users to cause a denial of service (pmsystem.exe crash) by issuing (1) a CD command with… Patch early 5.0 medium 5.1% 2004-12-31
CVE-2011-4024 EXP Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 5.1% 2011-10-21
CVE-2005-0780 EXP paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php… Patch early 5.0 medium 5.1% 2005-03-12
CVE-2006-3009 EXP Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to inject arbitrary HTML or web… Patch early 5.8 medium 5.1% 2006-06-13
CVE-2000-0185 EXP RealMedia RealServer reveals the real IP address of a Real Server, even if the address is supposed to be private. Patch early 5.0 medium 5.1% 2000-03-08
CVE-2004-1100 EXP Cross-site scripting (XSS) vulnerability in mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote… Patch early 6.8 medium 5.1% 2005-01-10
CVE-2015-4591 EXP eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remote unauthenticated users to in… Patch early 6.1 medium 5.1% 2017-01-10
CVE-2012-1790 EXP Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a full pathname in the file parame… Patch early 5.0 medium 5.1% 2012-03-19
CVE-2005-1782 EXP Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node… Patch early 4.3 medium 5.1% 2005-05-26
CVE-2007-4639 EXP EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbg_create_listener, which al… Patch early 6.5 medium 5.1% 2007-08-31
CVE-2010-2313 EXP Directory traversal vulnerability in index.php in Anodyne Productions SIMM Management System (SMS) 2.6.10, when magic_quotes_gpc is disabled, allows r… Patch early 6.8 medium 5.1% 2010-06-17
CVE-2001-0649 EXP Personal Web Sharing 1.5.5 allows a remote attacker to cause a denial of service via a long HTTP request. Patch early 5.0 medium 5.1% 2001-09-20
CVE-2006-7194 EXP PHP remote file inclusion vulnerability in modules/Mysqlfinder/MysqlfinderAdmin.php in Agora 1.4 RC1, when register_globals is enabled, allows remote… Patch early 6.8 medium 5.1% 2007-04-18
CVE-2006-7208 EXP PHP remote file inclusion vulnerability in download.php in the Adam van Dongen Forum (com_forum) component (aka phpBB component) 1.2.4RC3 and earlier… Patch early 6.8 medium 5.1% 2007-06-26
CVE-2017-8477 EXP Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,… Patch early 5.0 medium 5.1% 2017-06-15
CVE-2017-8483 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 5.1% 2017-06-15
CVE-2006-2587 EXP Buffer overflow in the WebTool HTTP server component in (1) PunkBuster before 1.229, as used by multiple products including (2) America's Army 1.228 a… Patch early 5.0 medium 5.1% 2006-05-25
CVE-2005-4196 EXP Multiple cross-site scripting (XSS) vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to inject arbitrary web scr… Patch early 4.3 medium 5.1% 2005-12-13
CVE-2006-1101 EXP The (1) sgetstr and (2) getint functions in Sauerbraten 2006_02_28, as derived from the Cube engine, allow remote attackers to cause a denial of servi… Patch early 5.0 medium 5.1% 2006-03-09
CVE-2016-0073 EXP The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain p… Patch early 5.0 medium 5.1% 2016-10-14
CVE-2007-2431 EXP Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote attackers to conduct cross-site… Patch early 6.8 medium 5.1% 2007-05-02
CVE-2012-5105 EXP Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.4 allow remote attackers to inject arbitrary web script or HTML via the dbsel… Patch early 4.3 medium 5.1% 2012-09-23
CVE-2015-8368 EXP ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parame… Patch early 6.0 medium 5.1% 2015-12-17
CVE-2023-29983 EXP Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary code via the auditlog tab in the… Patch early 5.4 medium 5.1% 2023-05-12
CVE-2006-4455 EXP Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via unspecified vectors involving th… Patch early 5.0 medium 5.1% 2006-08-30
← previous page 116 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt