peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,092 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

169,949 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-6500 EXP Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to delete "gateway information" via a re… Patch early 4.9 medium 4.5% 2007-12-20
CVE-2004-0192 EXP Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hija… Patch early 6.8 medium 4.5% 2004-03-15
CVE-2007-3014 EXP Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to inject arbitrary web script o… Patch early 4.3 medium 4.5% 2007-07-15
CVE-2018-19799 EXP Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS. Patch early 6.1 medium 4.5% 2018-12-26
CVE-2012-3524 EXP libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privilege… Patch early 6.9 medium 4.5% 2012-09-18
CVE-2008-7244 EXP Mozilla Firefox 3.0.1 and earlier allows remote attackers to cause a denial of service (browser hang) by calling the window.print function in a loop,… Patch early 5.0 medium 4.5% 2009-09-18
CVE-2007-2932 EXP Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web script or HTML via the blog para… Patch early 4.3 medium 4.5% 2007-05-31
CVE-2006-2922 EXP Multiple PHP remote file inclusion vulnerabilities in MiraksGalerie 2.62 allow remote attackers to execute arbitrary PHP code via a URL in the (1) g_p… Patch early 5.1 medium 4.5% 2006-06-09
CVE-2006-1145 EXP Format string vulnerability in the safe_cprintf function in acebot_cmds.c in Alien Arena 2006 Gold Edition 5.00 allows remote attackers (possibly auth… Patch early 6.5 medium 4.5% 2006-03-10
CVE-2008-5918 EXP Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php in WebSVN 2.0 and earlier allows remote attackers to inj… Patch early 4.3 medium 4.5% 2009-01-21
CVE-2011-1723 EXP Cross-site scripting (XSS) vulnerability in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows remote attackers to inject arbitrary we… Patch early 4.3 medium 4.5% 2011-04-19
CVE-2007-3130 EXP Multiple PHP remote file inclusion vulnerabilities in the OpenWiki (formerly JD-Wiki) component (com_jd-wiki) 1.0.2, and possibly earlier, for Joomla!… Patch early 6.8 medium 4.5% 2007-06-08
CVE-2012-1188 EXP Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 4.3 medium 4.5% 2012-09-26
CVE-2020-7934 EXP In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerab… Patch early 5.4 medium 4.5% 2020-01-28
CVE-2007-2191 EXP Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (… Patch early 6.8 medium 4.5% 2007-04-24
CVE-2003-1414 EXP Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attacke… Patch early 4.3 medium 4.5% 2003-12-31
CVE-2004-2518 EXP Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00") to a URL or (2) an invalid L… Patch early 5.0 medium 4.5% 2004-12-31
CVE-2012-3184 EXP Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6… Patch early 4.3 medium 4.5% 2012-10-17
CVE-2014-5464 EXP Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackers to injec… Patch early 4.3 medium 4.5% 2014-09-08
CVE-2015-2182 EXP Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script or HTML via the (1) schltr par… Patch early 4.3 medium 4.5% 2015-03-11
CVE-2018-13457 EXP qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-servi… Patch early 5.5 medium 4.5% 2018-07-12
CVE-2018-13458 EXP qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-servi… Patch early 5.5 medium 4.5% 2018-07-12
CVE-2007-1158 EXP Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows remote attackers to read arbitr… Patch early 5.0 medium 4.5% 2007-03-02
CVE-2008-3606 EXP Heap-based buffer overflow in the IMAP service in Qbik WinGate 6.2.2.1137 and earlier allows remote authenticated users to cause a denial of service (… Patch early 6.5 medium 4.5% 2008-08-12
CVE-2010-3770 EXP Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey be… Patch early 4.3 medium 4.5% 2010-12-10
CVE-2009-1233 EXP Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an XML document containing many… Patch early 4.3 medium 4.4% 2009-04-02
CVE-2012-2904 EXP player.swf in LongTail JW Player 5.9 allows remote attackers to conduct cross-site scripting (XSS) attacks to inject arbitrary web script or HTML via… Patch early 4.3 medium 4.4% 2012-05-21
CVE-2013-1804 EXP Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 4.4% 2014-04-29
CVE-2006-3324 EXP The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attackers to ov… Patch early 5.0 medium 4.4% 2006-06-30
CVE-2008-6927 EXP Multiple cross-site scripting (XSS) vulnerabilities in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allow remote a… Patch early 4.3 medium 4.4% 2009-08-10
← previous page 128 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt