peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,121 CVEs 1,733 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

169,957 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2011-4449 EXP actions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically abse… Patch early 6.8 medium 4.1% 2012-09-05
CVE-2006-4610 EXP PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, allows remote attackers to exec… Patch early 5.1 medium 4.1% 2006-09-07
CVE-2006-5240 EXP PHP remote file inclusion vulnerability in engine/require.php in Docmint 2.0 and earlier, when register_globals is enabled, allows remote attackers to… Patch early 5.1 medium 4.1% 2006-10-12
CVE-2006-2285 EXP PHP remote file inclusion vulnerability in authldap.php in Dokeos 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the include… Patch early 5.1 medium 4.1% 2006-05-10
CVE-2014-3081 EXP prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbit… Patch early 6.3 medium 4.1% 2014-08-17
CVE-2007-6218 EXP Multiple PHP remote file inclusion vulnerabilities in Ossigeno CMS 2.2 pre1 allow remote attackers to execute arbitrary PHP code via a URL in the (1)… Patch early 5.0 medium 4.1% 2007-12-04
CVE-2023-36163 EXP Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the m… Patch early 6.1 medium 4.1% 2023-07-11
CVE-2009-4587 EXP Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as demonstrated by… Patch early 5.0 medium 4.1% 2010-01-07
CVE-2017-7064 EXP An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… Patch early 5.5 medium 4.1% 2017-07-20
CVE-2016-5304 EXP Open redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticat… Patch early 6.8 medium 4.1% 2016-06-30
CVE-2005-3770 EXP Multiple cross-site scripting (XSS) vulnerabilities in PHP-Post (PHPp) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the s… Patch early 4.3 medium 4.1% 2005-11-23
CVE-2015-7984 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition b… Patch early 6.8 medium 4.1% 2015-11-19
CVE-2015-8729 EXP The ascend_seek function in wiretap/ascendtext.c in the Ascend file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not ensure th… Patch early 5.5 medium 4.1% 2016-01-04
CVE-2002-2011 EXP Cross-site scripting (XSS) vulnerability in the fom CGI program (fom.cgi) in Faq-O-Matic 2.711 and 2.712 allows remote attackers to inject arbitrary w… Patch early 4.3 medium 4.1% 2002-12-31
CVE-2007-6545 EXP Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) the s… Patch early 4.3 medium 4.1% 2007-12-28
CVE-2025-52367 EXP Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the subtitle field. Patch early 5.4 medium 4.1% 2025-09-22
CVE-2016-7224 EXP Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Serve… Patch early 6.1 medium 4.1% 2016-11-10
CVE-2016-7225 EXP Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local use… Patch early 6.1 medium 4.1% 2016-11-10
CVE-2016-7226 EXP Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local use… Patch early 6.1 medium 4.1% 2016-11-10
CVE-2006-5202 EXP Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary confi… Patch early 5.0 medium 4.1% 2006-10-10
CVE-2007-3593 EXP Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 4.1% 2007-07-06
CVE-2008-5225 EXP Multiple cross-site scripting (XSS) vulnerabilities in Xerox DocuShare 6 and earlier allow remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 4.1% 2008-11-25
CVE-2010-1724 EXP Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to inject arbi… Patch early 4.3 medium 4.1% 2010-05-06
CVE-2008-3700 EXP Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and earlier allow remote attackers to inject arbitrary web script o… Patch early 4.3 medium 4.1% 2008-08-15
CVE-2012-2614 EXP Buffer overflow in programmer.exe in Lattice Diamond Programmer 1.4.2 allows user-assisted remote attackers to cause a denial of service (application… Patch early 6.8 medium 4.1% 2012-07-12
CVE-2009-1467 EXP Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary… Patch early 4.3 medium 4.1% 2009-05-05
CVE-2012-2572 EXP Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote attackers to inject arbitrary w… Patch early 4.3 medium 4.1% 2014-06-19
CVE-2005-2460 EXP Multiple cross-site scripting (XSS) vulnerabilities in Kayako liveResponse 2.x allow remote attackers to inject arbitrary web script or HTML via the (… Patch early 5.8 medium 4.1% 2005-12-31
CVE-2005-4676 EXP Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function, which allows remote attackers t… Patch early 5.0 medium 4.1% 2005-12-31
CVE-2006-1590 EXP Cross-site scripting (XSS) vulnerability in the PrintFreshPage function in (1) Basic Analysis and Security Engine (BASE) 1.2.4 and (2) Analysis Consol… Patch early 4.3 medium 4.1% 2006-04-03
← previous page 136 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt