peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,178 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

169,967 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-31674 EXP Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code v… Patch early 6.1 medium 3.9% 2022-05-02
CVE-2008-3233 EXP Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 3.9% 2008-07-18
CVE-2008-0123 EXP Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject… Patch early 4.3 medium 3.9% 2008-01-12
CVE-2002-1845 EXP Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary w… Patch early 4.3 medium 3.9% 2002-12-31
CVE-2004-0660 EXP Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in CuteNews 1.3.1 allows remote att… Patch early 6.8 medium 3.9% 2004-08-06
CVE-2007-0183 EXP Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the N… Patch early 6.8 medium 3.9% 2007-01-12
CVE-2013-4900 EXP Directory traversal vulnerability in DeWeS web server 0.4.2 and possibly earlier, as used in Twilight CMS, allows remote attackers to read arbitrary f… Patch early 5.0 medium 3.9% 2013-09-09
CVE-2009-2704 EXP CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing a %00 (encoded n… Patch early 4.3 medium 3.9% 2009-08-11
CVE-2003-1266 EXP The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of ser… Patch early 5.0 medium 3.9% 2003-12-31
CVE-2002-1455 EXP Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2)… Patch early 4.3 medium 3.9% 2003-06-09
CVE-2006-5412 EXP admin.php in PHP Outburst Easynews 4.4.1 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication, and gain the… Patch early 5.1 medium 3.9% 2006-10-20
CVE-2003-0614 EXP Cross-site scripting (XSS) vulnerability in search.php of Gallery 1.1 through 1.3.4 allows remote attackers to insert arbitrary web script via the sea… Patch early 4.3 medium 3.9% 2003-08-27
CVE-2009-1827 EXP The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Rad… Patch early 5.0 medium 3.9% 2009-05-29
CVE-2012-4891 EXP Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 3.9% 2012-09-10
CVE-2018-11242 EXP An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that migh… Patch early 6.5 medium 3.9% 2018-05-20
CVE-2018-7703 EXP Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 6.1 medium 3.9% 2018-03-15
CVE-2017-13849 EXP An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issu… Patch early 5.5 medium 3.9% 2017-11-13
CVE-2009-5098 EXP The LunaSysMgr process in Palm Pre WebOS 1.1 and earlier, when not viewing web pages in landscape mode, allows remote attackers to cause a denial of s… Patch early 5.4 medium 3.9% 2011-09-13
CVE-2015-2248 EXP Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-… Patch early 6.8 medium 3.9% 2015-05-01
CVE-2015-1479 EXP SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authentic… Patch early 6.5 medium 3.9% 2015-02-04
CVE-2010-2370 EXP Unspecified vulnerability in the Oracle Business Process Management component in Oracle Fusion Middleware 5.7 MP3, 6.0 MP5, and 10.3 MP2 allows remote… Patch early 4.3 medium 3.9% 2010-07-13
CVE-2008-3723 EXP Directory traversal vulnerability in index.php in PHPizabi 0.848b C1 HFP3 allows remote authenticated administrators to read arbitrary files via (1) a… Patch early 6.3 medium 3.9% 2008-08-20
CVE-2014-9301 EXP Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows remote attackers to trigger ou… Patch early 6.4 medium 3.9% 2014-12-07
CVE-2006-6810 EXP Unspecified vulnerability in the clear_user_list function in src/main.c in DB Hub 0.3 allows remote attackers to cause a denial of service (applicatio… Patch early 5.0 medium 3.9% 2006-12-29
CVE-2009-0441 EXP PHP remote file inclusion vulnerability in skin_shop/standard/2_view_body/body_default.php in TECHNOTE 7.2, when register_globals is enabled, allows r… Patch early 6.8 medium 3.9% 2009-02-10
CVE-2009-0527 EXP PHP remote file inclusion vulnerability in plugins/rss_importer_functions.php in AdaptCMS Lite 1.4 allows remote attackers to execute arbitrary PHP co… Patch early 6.8 medium 3.9% 2009-02-11
CVE-2008-5102 EXP PythonScripts in Zope 2 2.11.2 and earlier, as used in Conga and other products, allows remote authenticated users to cause a denial of service (resou… Patch early 4.0 medium 3.9% 2008-11-17
CVE-2003-0483 EXP Cross-site scripting (XSS) vulnerabilities in XMB Forum 1.8 Partagium allow remote attackers to insert arbitrary script via (1) the member parameter t… Patch early 6.8 medium 3.9% 2003-08-07
CVE-2014-3438 EXP Multiple cross-site scripting (XSS) vulnerabilities in console interface scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allow… Patch early 4.3 medium 3.9% 2014-11-07
CVE-2004-1797 EXP Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 3.9% 2004-12-31
← previous page 141 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt