peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,133 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

169,961 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-1663 EXP The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a POST reque… Patch early 5.0 medium 4% 2002-12-31
CVE-2018-16134 EXP Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI. Patch early 6.1 medium 4% 2018-08-29
CVE-2012-1039 EXP Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 4.3 medium 4% 2012-03-19
CVE-2015-5520 EXP Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allows remote attackers to inject a… Patch early 4.3 medium 4% 2015-07-14
CVE-2014-9143 EXP Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect users to arbitrary web sites and… Patch early 4.3 medium 4% 2014-12-05
CVE-2003-1317 EXP Cross-site scripting (XSS) vulnerability in mod.php in eNdonesia 8.2 allows remote attackers to inject arbitrary web script or HTML via the mod parame… Patch early 6.8 medium 4% 2003-12-31
CVE-2006-1921 EXP nettools.php in PHP Net Tools 2.7.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter. Patch early 6.4 medium 4% 2006-04-20
CVE-2005-1004 EXP Cross-site scripting (XSS) vulnerability in usrdetails.php in ProfitCode PayProCart 3.0 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 4% 2005-05-02
CVE-2017-9126 EXP The quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflo… Patch early 6.5 medium 4% 2017-06-12
CVE-2006-2740 EXP Multiple SQL injection vulnerabilities in Epicdesigns tinyBB 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) q parameter in (… Patch early 6.8 medium 4% 2006-06-01
CVE-2007-3189 EXP Cross-site scripting (XSS) vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to inject arbitr… Patch early 4.3 medium 4% 2007-06-12
CVE-2010-4875 EXP Cross-site scripting (XSS) vulnerability in vodpod-video-gallery/vodpod_gallery_thumbs.php in the Vodpod Video Gallery Plugin 3.1.5 for WordPress allo… Patch early 4.3 medium 4% 2011-10-07
CVE-2008-0193 EXP Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows remote attacker… Patch early 4.3 medium 4% 2008-01-10
CVE-2017-9412 EXP The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid memory read and… Patch early 5.5 medium 4% 2017-07-27
CVE-2003-0283 EXP Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message wit… Patch early 6.8 medium 4% 2003-06-16
CVE-2005-0543 EXP Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cf… Patch early 4.3 medium 4% 2005-02-24
CVE-2008-0851 EXP Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username… Patch early 4.3 medium 4% 2008-02-21
CVE-2005-1561 EXP Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 4% 2005-05-11
CVE-2023-34834 EXP A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attackers to gain sensitive informatio… Patch early 5.3 medium 4% 2023-06-29
CVE-2005-1752 EXP viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name… Patch early 6.4 medium 4% 2005-12-31
CVE-2013-2294 EXP Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbitrary web script or HTML via a… Patch early 6.1 medium 4% 2020-01-30
CVE-2008-6944 EXP Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file… Patch early 6.5 medium 4% 2009-08-12
CVE-2014-8690 EXP Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, and 2.3.x before 2.3.1 patch 4 a… Patch early 4.3 medium 4% 2015-02-19
CVE-2012-2511 EXP The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote… Patch early 5.0 medium 4% 2012-05-15
CVE-2009-1512 EXP Static code injection vulnerability in X-Forum 0.6.2 allows remote authenticated administrators to inject arbitrary PHP code into Config.php via the a… Patch early 6.5 medium 4% 2009-05-01
CVE-2008-3280 EXP It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Random Number… Patch early 5.9 medium 4% 2021-05-21
CVE-2016-1915 EXP Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to inje… Patch early 6.1 medium 4% 2017-04-13
CVE-2004-2033 EXP Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request. Patch early 5.0 medium 4% 2004-05-26
CVE-2008-6942 EXP Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows remote authenticated users to ex… Patch early 6.5 medium 3.9% 2009-08-12
CVE-2008-6943 EXP Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading… Patch early 6.5 medium 3.9% 2009-08-12
← previous page 140 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt