peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,123 CVEs 1,733 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

169,958 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-0079 EXP The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct proces… Patch early 6.9 medium 4.1% 2009-04-15
CVE-2006-5019 EXP Google Mini 4.4.102.M.36 and earlier allows remote attackers to obtain sensitive information via a direct request for /search with an invalid client p… Patch early 5.0 medium 4.1% 2006-09-27
CVE-2005-2192 EXP SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords… Patch early 5.0 medium 4.1% 2005-07-11
CVE-2008-6670 EXP Integer overflow in Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted packet to UDP port 27… Patch early 5.0 medium 4.1% 2009-04-08
CVE-2008-7123 EXP Static code injection vulnerability in admin/configuration/modifier.php in zKup CMS 2.0 through 2.3 allows remote attackers to inject arbitrary PHP co… Patch early 6.8 medium 4.1% 2009-08-31
CVE-2006-5320 EXP Directory traversal vulnerability in getimg.php in Album Photo Sans Nom 1.6 allows remote attackers to read arbitrary files via the img parameter. Patch early 5.0 medium 4.1% 2006-10-17
CVE-2008-6619 EXP Unrestricted file upload vulnerability in class/ApplyDB.php in ClassSystem 2.3 allows remote attackers to execute arbitrary code by uploading a file w… Patch early 6.8 medium 4.1% 2009-04-06
CVE-2001-0740 EXP 3COM OfficeConnect 812 and 840 ADSL Router 4.2, running OCR812 router software 1.1.9 and earlier, allows remote attackers to cause a denial of service… Patch early 5.0 medium 4.1% 2001-10-18
CVE-2007-3703 EXP Stack-based buffer overflow in a certain ActiveX control in sasatl.dll 1.5.0.531 in Zenturi Program Checker (ProgramChecker) Pro allows remote attacke… Patch early 6.8 medium 4.1% 2007-07-11
CVE-2006-2046 EXP Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote attackers to execute arbitrary S… Patch early 6.4 medium 4% 2006-04-26
CVE-2007-1167 EXP inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and earlier allows remote attackers to obtain MySQL data via the inc/mysql.php value of… Patch early 5.0 medium 4% 2007-03-02
CVE-2004-1420 EXP Multiple cross-site scripting (XSS) vulnerabilities in header.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to inject arbitrary web… Patch early 4.3 medium 4% 2004-12-31
CVE-2023-23408 EXP Azure Apache Ambari Spoofing Vulnerability Patch early 4.5 medium 4% 2023-03-14
CVE-2009-1554 EXP Cross-site scripting (XSS) vulnerability in ThemeServlet.java in Sun Woodstock 4.2, as used in Sun GlassFish Enterprise Server and other products, all… Patch early 4.3 medium 4% 2009-05-06
CVE-2012-6522 EXP Directory traversal vulnerability in the getContent function in codes/wcms.php in w-CMS 2.01 allows remote attackers to read arbitrary files via a ..… Patch early 5.0 medium 4% 2013-01-31
CVE-2004-1384 EXP Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 4% 2004-12-31
CVE-2009-3566 EXP McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identi… Patch early 4.3 medium 4% 2009-11-13
CVE-2021-26078 EXP The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from vers… Patch early 6.1 medium 4% 2021-06-07
CVE-2005-0791 EXP Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers to inject ar… Patch early 4.3 medium 4% 2005-03-14
CVE-2018-16061 EXP Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php. Patch early 6.1 medium 4% 2021-10-15
CVE-2004-1882 EXP Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 4% 2004-12-31
CVE-2017-15284 EXP Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code as… Patch early 5.4 medium 4% 2017-10-12
CVE-2006-5043 EXP Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for Joomla! allow remote attacker… Patch early 6.8 medium 4% 2006-09-27
CVE-2013-0807 EXP Cross-site scripting (XSS) vulnerability in the NewSectionPrompt function in include/tool/editing_page.php in gpEasy CMS 3.5.2 and earlier allows remo… Patch early 4.3 medium 4% 2014-03-28
CVE-2019-11419 EXP vcodec2_hls_filter in libvoipCodec_v7a.so in the WeChat application through 7.0.3 for Android allows attackers to cause a denial of service (applicati… Patch early 5.5 medium 4% 2019-05-14
CVE-2009-4834 EXP lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibly related to now_connect.php. Patch early 6.8 medium 4% 2010-05-04
CVE-2010-3272 EXP accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for re… Patch early 4.3 medium 4% 2011-02-17
CVE-2019-17220 EXP Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line. Patch early 6.1 medium 4% 2019-10-21
CVE-2006-4825 EXP Multiple cross-site scripting (XSS) vulnerabilities in cl_files/index.php in SoftComplex PHP Event Calendar 1.5.1, and possibly earlier, allow remote… Patch early 4.3 medium 4% 2006-09-15
CVE-2006-4894 EXP Cross-site scripting (XSS) vulnerability in forms/lostpassword.php in iDevSpot NixieAffiliate 1.9 and earlier allows remote attackers to inject arbitr… Patch early 4.3 medium 4% 2006-09-19
← previous page 138 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt