peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,095 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

169,951 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-4140 EXP Directory traversal vulnerability in IPCheck Server Monitor before 5.3.3.639/640 allows remote attackers to read arbitrary files via modified .. (dot… Patch early 5.0 medium 4.4% 2006-08-14
CVE-2007-5105 EXP Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 and 2.0.1 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 4.4% 2007-09-26
CVE-2006-4923 EXP Cross-site scripting (XSS) vulnerability in search.php in eSyndiCat Portal System allows remote attackers to inject arbitrary web script or HTML via t… Patch early 4.3 medium 4.4% 2006-09-21
CVE-2020-15930 EXP An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag. Patch early 6.1 medium 4.4% 2020-09-24
CVE-2006-1995 EXP Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via ".." sequences in the p paramet… Patch early 5.0 medium 4.4% 2006-04-25
CVE-2007-4088 EXP Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) id,… Patch early 4.3 medium 4.4% 2007-07-30
CVE-2013-6017 EXP Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary web script or HTML via the bo… Patch early 4.3 medium 4.4% 2014-01-12
CVE-2007-6495 EXP inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1)… Patch early 6.5 medium 4.4% 2007-12-20
CVE-2007-5310 EXP PHP remote file inclusion vulnerability in admin.wmtportfolio.php in the webmaster-tips.net wmtportfolio 1.0 (com_wmtportfolio) component for Joomla!… Patch early 6.8 medium 4.4% 2007-10-09
CVE-2007-5390 EXP PHP remote file inclusion vulnerability in index.php in PicoFlat CMS 0.4.14 and earlier allows remote attackers to execute arbitrary PHP code via a UR… Patch early 6.8 medium 4.4% 2007-10-12
CVE-2006-6225 EXP Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a URL in the _CONF[path] parame… Patch early 5.1 medium 4.4% 2006-12-02
CVE-2004-1906 EXP Mcafee FreeScan allows remote attackers to cause a denial of service and possibly arbitrary code via a long string in the ScanParam property of a COM… Patch early 5.0 medium 4.4% 2004-12-31
CVE-2009-1218 EXP Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Ser… Patch early 4.3 medium 4.4% 2009-04-01
CVE-2002-1006 EXP Cross-site scripting (XSS) vulnerability in BBC Education Text to Speech Internet Enhancer (Betsie) 1.5.11 and earlier allows remote attackers to exec… Patch early 6.8 medium 4.4% 2002-10-04
CVE-2003-1472 EXP Buffer overflow in 3D-FTP client 4.0 allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long ban… Patch early 5.0 medium 4.4% 2003-12-31
CVE-2009-2705 EXP CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "… Patch early 4.3 medium 4.4% 2009-08-11
CVE-2006-4917 EXP Cross-site scripting (XSS) vulnerability in search.php in PT News 1.7.8 allows remote attackers to inject arbitrary web script or HTML via the pgname… Patch early 4.3 medium 4.4% 2006-09-21
CVE-2006-2331 EXP Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via (1) a .. (… Patch early 6.4 medium 4.4% 2006-05-12
CVE-2013-4098 EXP ServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote attackers to inject arbitrary error-page text via the message parameter. Patch early 5.0 medium 4.4% 2013-06-28
CVE-2009-2043 EXP nsViewManager.cpp in Mozilla Firefox 3.0.2 through 3.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and applicati… Patch early 4.3 medium 4.4% 2009-06-12
CVE-2006-2736 EXP PHP remote file inclusion vulnerability in blend_data/blend_common.php in Blend Portal 1.2.0, as used with phpBB when register_globals is enabled, all… Patch early 5.1 medium 4.4% 2006-06-01
CVE-2005-1492 EXP Cross-site scripting (XSS) vulnerability in user.cgi in Gossamer Threads Links SQL 2.x and 3.0 allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 4.4% 2005-05-11
CVE-2023-1826 EXP A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of t… Patch early 6.3 medium 4.4% 2023-04-04
CVE-2018-17784 EXP Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to condu… Patch early 6.1 medium 4.4% 2018-10-10
CVE-2006-7147 EXP PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier allows remote attackers to exec… Patch early 6.8 medium 4.4% 2007-03-07
CVE-2005-3995 EXP Format string vulnerability in the dosyslog function in the OBEX server (obexsrv.c) for Sobexsrv before 1.0.0-pre4, when the syslog (-S) function is e… Patch early 5.1 medium 4.4% 2005-12-05
CVE-2007-0883 EXP Directory traversal vulnerability in portalgroups/portalgroups/getfile.cgi in IP3 NetAccess before firmware 4.1.9.6 allows remote attackers to read ar… Patch early 5.0 medium 4.3% 2007-02-12
CVE-2007-5464 EXP Stack-based buffer overflow in Live for Speed 0.5X10 and earlier allows remote authenticated users to cause a denial of service (client crash) and pos… Patch early 6.5 medium 4.3% 2007-10-15
CVE-2006-3036 EXP Multiple cross-site scripting (XSS) vulnerabilities in 35mmslidegallery 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 5.8 medium 4.3% 2006-06-15
CVE-2009-0496 EXP Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 4.3% 2009-02-10
← previous page 130 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt