peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,092 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

169,949 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-0670 EXP Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web script or HTML via (1) the ne… Patch early 4.3 medium 4.4% 2005-05-02
CVE-2004-1121 EXP Apple Safari 1.0 through 1.2.3 allows remote attackers to spoof the URL displayed in the status bar via TABLE tags. Patch early 5.0 medium 4.4% 2004-11-01
CVE-2018-19782 EXP Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML v… Patch early 6.1 medium 4.4% 2019-01-30
CVE-2008-6768 EXP Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute arbitrary PHP code by uploadi… Patch early 6.8 medium 4.4% 2009-04-29
CVE-2009-0470 EXP Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow remote attackers to inject arbitrary web script or… Patch early 4.3 medium 4.4% 2009-02-06
CVE-2020-10385 EXP A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress. Patch early 5.4 medium 4.4% 2020-03-24
CVE-2018-20009 EXP DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field. Patch early 4.8 medium 4.4% 2018-12-10
CVE-2018-20010 EXP DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field. Patch early 4.8 medium 4.4% 2018-12-10
CVE-2018-20011 EXP DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field. Patch early 4.8 medium 4.4% 2018-12-10
CVE-2000-0636 EXP HP JetDirect printers versions G.08.20 and H.08.20 and earlier allow remote attackers to cause a denial of service via a malformed FTP quote command. Patch early 5.0 medium 4.4% 2000-07-19
CVE-2009-4867 EXP Buffer overflow in Tuniac 090517c allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a lo… Patch early 4.3 medium 4.4% 2010-05-11
CVE-2019-9593 EXP A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or… Patch early 6.1 medium 4.4% 2019-03-06
CVE-2006-1194 EXP Integer signedness error in the enet_protocol_handle_incoming_commands function in protocol.c for ENet library CVS version Jul 2005 and earlier, as us… Patch early 5.0 medium 4.4% 2006-03-13
CVE-2007-5416 EXP Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parame… Patch early 6.8 medium 4.4% 2007-10-12
CVE-2015-8726 EXP wiretap/vwr.c in the VeriWave file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate certain signature and Modulation… Patch early 5.5 medium 4.4% 2016-01-04
CVE-2000-0737 EXP The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator… Patch early 4.6 medium 4.4% 2000-10-20
CVE-2007-2182 EXP Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP files via a t… Patch early 6.8 medium 4.4% 2007-04-24
CVE-2018-7747 EXP Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow remote attackers to inject arbit… Patch early 4.8 medium 4.4% 2018-04-20
CVE-2007-2437 EXP The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to caus… Patch early 5.5 medium 4.4% 2007-05-02
CVE-2015-1060 EXP Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect users to arbitrary web sites a… Patch early 5.8 medium 4.4% 2015-01-16
CVE-2005-3954 EXP Cross-site scripting (XSS) vulnerability in blogBuddies 0.3 allows remote attackers to inject arbitrary web script or HTML via the u parameter to inde… Patch early 4.3 medium 4.4% 2005-12-01
CVE-2015-8736 EXP The mp2t_find_next_pcr function in wiretap/mp2t.c in the MP2T file parser in Wireshark 2.0.x before 2.0.1 does not reserve memory for a trailer, which… Patch early 5.5 medium 4.4% 2016-01-04
CVE-2012-4771 EXP Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 4.4% 2012-10-22
CVE-2007-3569 EXP Multiple cross-site scripting (XSS) vulnerabilities in Oliver Library Management System allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 4.4% 2007-07-05
CVE-2012-4949 EXP SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a query… Patch early 6.5 medium 4.4% 2012-11-14
CVE-2012-4989 EXP Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote attackers to inject arbitrary w… Patch early 4.3 medium 4.4% 2012-10-22
CVE-2006-2451 EXP The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of… Patch early 4.6 medium 4.4% 2006-07-07
CVE-2005-3747 EXP Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files… Patch early 5.0 medium 4.4% 2005-11-22
CVE-2007-6110 EXP Cross-site scripting (XSS) vulnerability in htsearch in htdig 3.2.0b6 allows remote attackers to inject arbitrary web script or HTML via the sort para… Patch early 4.3 medium 4.4% 2007-11-23
CVE-2000-0698 EXP Minicom 1.82.1 and earlier on some Linux systems allows local users to create arbitrary files owned by the uucp user via a symlink attack. Patch early 5.0 medium 4.4% 2000-10-20
← previous page 129 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt