peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,075 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

169,946 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-2472 EXP Multiple buffer overflows in BusinessMail 4.60.00 allow remote attackers to cause a denial of service (application crash) via a long string to SMTP (1… Patch early 5.0 medium 4.6% 2005-08-05
CVE-2007-5447 EXP ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_functions restrictions, which allow… Patch early 4.3 medium 4.6% 2007-10-14
CVE-2022-4407 EXP Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9. Patch early 6.1 medium 4.6% 2022-12-11
CVE-2013-7319 EXP Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web scr… Patch early 4.3 medium 4.6% 2014-02-06
CVE-2006-1709 EXP Cross-site scripting (XSS) vulnerability in shop_main.cgi in interaktiv.shop 5 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 6.8 medium 4.6% 2006-04-11
CVE-2013-3529 EXP Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote attackers… Patch early 4.3 medium 4.6% 2013-05-10
CVE-2007-6608 EXP Multiple cross-site scripting (XSS) vulnerabilities in OpenBiblio 0.5.2-pre4 and earlier allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 4.6% 2007-12-31
CVE-2007-3649 EXP Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Digital Imaging allows remote att… Patch early 6.8 medium 4.6% 2007-07-10
CVE-2015-8732 EXP The dissect_zcl_pwr_prof_pwrprofstatersp function in epan/dissectors/packet-zbee-zcl-general.c in the ZigBee ZCL dissector in Wireshark 1.12.x before… Patch early 5.5 medium 4.6% 2016-01-04
CVE-2013-5006 EXP main_internet.php on the Western Digital My Net N600 and N750 with firmware 1.03.12 and 1.04.16, and the N900 and N900C with firmware 1.05.12, 1.06.18… Patch early 4.3 medium 4.6% 2013-07-31
CVE-2014-7289 EXP SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security:… Patch early 6.5 medium 4.6% 2015-01-21
CVE-2014-6050 EXP phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request. Patch early 5.3 medium 4.6% 2018-08-28
CVE-2006-6242 EXP Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include arbitrary local files via a ..… Patch early 6.8 medium 4.6% 2006-12-03
CVE-2024-28397 EXP An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call. Patch early 5.3 medium 4.5% 2024-06-20
CVE-2006-2971 EXP Integer overflow in the recv_packet function in 0verkill 0.16 allows remote attackers to cause a denial of service (daemon crash) via a UDP packet wit… Patch early 5.0 medium 4.5% 2006-06-12
CVE-2006-2351 EXP Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers… Patch early 4.3 medium 4.5% 2006-05-15
CVE-2005-4584 EXP BZFlag server 2.0.4 and earlier allows remote attackers to cause a denial of service (application crash) via a callsign that is not followed by a NULL… Patch early 5.0 medium 4.5% 2005-12-29
CVE-2010-2273 EXP Multiple cross-site scripting (XSS) vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x… Patch early 4.3 medium 4.5% 2010-06-15
CVE-2007-2524 EXP Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket Request System (OTRS) 2.0.x allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 4.5% 2007-05-08
CVE-2003-0375 EXP Cross-site scripting (XSS) vulnerability in member.php of XMBforum XMB 1.8.x (aka Partagium) allows remote attackers to insert arbitrary HTML and web… Patch early 4.3 medium 4.5% 2003-06-16
CVE-2019-8649 EXP A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is fixed in iOS 1… Patch early 6.1 medium 4.5% 2019-12-18
CVE-2019-8690 EXP A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, mac… Patch early 6.1 medium 4.5% 2019-12-18
CVE-2009-1204 EXP Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrary web script or HTML via the P… Patch early 4.3 medium 4.5% 2009-04-01
CVE-2015-0003 EXP win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wind… Patch early 6.9 medium 4.5% 2015-02-11
CVE-2011-5207 EXP Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1.1.6 before 2011-12-31 allows… Patch early 4.3 medium 4.5% 2012-10-04
CVE-2017-15223 EXP Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) v… Patch early 5.3 medium 4.5% 2017-10-24
CVE-2001-0791 EXP Trend Micro InterScan VirusWall for Windows NT allows remote attackers to make configuration changes by directly calling certain CGI programs, which d… Patch early 5.0 medium 4.5% 2001-10-18
CVE-2006-6770 EXP Multiple PHP remote file inclusion vulnerabilities in Jinzora Media Jukebox 2.7 and earlier, when register_globals is enabled, allow remote attackers… Patch early 6.8 medium 4.5% 2006-12-27
CVE-2017-3630 EXP Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11… Patch early 5.3 medium 4.5% 2017-06-22
CVE-2009-5065 EXP Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0 allows remote atta… Patch early 4.3 medium 4.5% 2011-04-11
← previous page 126 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt