peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,116 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

169,956 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2013-4884 EXP Cross-site scripting (XSS) vulnerability in McAfee SuperScan 4.0 allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded sequ… Patch early 4.3 medium 4.3% 2014-01-21
CVE-2014-8577 EXP Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) d… Patch early 4.3 medium 4.3% 2014-10-31
CVE-2017-13865 EXP An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchO… Patch early 5.5 medium 4.2% 2017-12-25
CVE-2008-4133 EXP The web proxy service on the D-Link DIR-100 with firmware 1.12 and earlier does not properly filter web requests with large URLs, which allows remote… Patch early 4.3 medium 4.2% 2008-09-19
CVE-2004-0675 EXP Cross-site scripting (XSS) vulnerability in (1) cart32.exe or (2) c32web.exe in Cart32 shopping cart allows remote attackers to execute arbitrary web… Patch early 6.8 medium 4.2% 2004-08-06
CVE-2005-2095 EXP options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which allows remote attackers to mo… Patch early 4.3 medium 4.2% 2005-07-13
CVE-2012-2209 EXP Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Piwigo before 2.3.4 allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 4.2% 2012-08-14
CVE-2019-0796 EXP An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privil… Patch early 5.5 medium 4.2% 2019-04-09
CVE-2015-4066 EXP Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow remote authenticated users to exe… Patch early 6.5 medium 4.2% 2015-05-27
CVE-2017-9258 EXP The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (in… Patch early 5.5 medium 4.2% 2017-07-27
CVE-2008-7136 EXP toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the (1) Reque… Patch early 4.3 medium 4.2% 2009-09-01
CVE-2006-3421 EXP PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrar… Patch early 5.1 medium 4.2% 2006-07-07
CVE-2008-1042 EXP Directory traversal vulnerability in include/body.inc.php in Linux Web Shop (LWS) php Download Manager 1.0 and 1.1 allows remote attackers to include… Patch early 6.8 medium 4.2% 2008-02-27
CVE-2017-8678 EXP The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT… Patch early 5.5 medium 4.2% 2017-09-13
CVE-2017-8680 EXP The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows… Patch early 5.5 medium 4.2% 2017-09-13
CVE-2017-8681 EXP The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT… Patch early 5.5 medium 4.2% 2017-09-13
CVE-2017-8687 EXP The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT… Patch early 5.5 medium 4.2% 2017-09-13
CVE-2005-1593 EXP Cross-site scripting (XSS) vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to inject arbitrary web script or HTML… Patch early 6.8 medium 4.2% 2005-05-16
CVE-2008-4049 EXP A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to execute arbitra… Patch early 6.8 medium 4.2% 2008-09-11
CVE-2008-6918 EXP Unrestricted file upload vulnerability in admin/galeria.php in ThePortal2 2.2 allows remote attackers to execute arbitrary PHP code by uploading a fil… Patch early 6.8 medium 4.2% 2009-08-10
CVE-2006-2398 EXP Directory traversal vulnerability in index.php in GPhotos 1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the re… Patch early 5.0 medium 4.2% 2006-05-16
CVE-2013-3515 EXP Multiple cross-site scripting (XSS) vulnerabilities in OpenX Source 2.8.10 and earlier allow remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 4.2% 2013-07-29
CVE-2003-1145 EXP Cross-site scripting (XSS) vulnerability in friendmail.php in OpenAutoClassifieds 1.0 allows remote attackers to inject arbitrary web script or HTML v… Patch early 6.8 medium 4.2% 2003-11-03
CVE-2003-1187 EXP Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via… Patch early 6.8 medium 4.2% 2003-11-02
CVE-2003-1197 EXP Cross-site scripting (XSS) vulnerability in index.php for Ledscripts.com LedForums Beta 1 allows remote attackers to inject arbitrary web script or HT… Patch early 6.8 medium 4.2% 2003-10-30
CVE-2004-0301 EXP Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter. Patch early 6.8 medium 4.2% 2004-11-23
CVE-2004-0358 EXP Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1… Patch early 6.8 medium 4.2% 2004-11-23
CVE-2009-3312 EXP PHP remote file inclusion vulnerability in php/init.poll.php in phpPollScript 1.3 and earlier, when register_globals is enabled, allows remote attacke… Patch early 6.8 medium 4.2% 2009-09-23
CVE-2006-3993 EXP PHP remote file inclusion vulnerability in copyright.php in Olaf Noehring The Search Engine Project (TSEP) 0.942 allows remote attackers to execute ar… Patch early 5.1 medium 4.2% 2006-08-05
CVE-2002-1703 EXP Cross-site scripting vulnerability (XSS) in auction.cgi for Mewsoft NetAuction 3.0 allows remote attackers to execute arbitrary script as other users… Patch early 6.8 medium 4.2% 2002-12-31
← previous page 133 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt