peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,267 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

170,013 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-2580 EXP Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly before 1.5.15, for WordPress allows remote attackers to inject arbit… Patch early 4.3 medium 3.7% 2014-06-20
CVE-2012-2583 EXP Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 3.7% 2014-09-17
CVE-2007-1678 EXP Cross-site scripting (XSS) vulnerability in the Fizzle 0.5 extension for Firefox allows remote attackers to inject arbitrary web script or HTML via RS… Patch early 4.3 medium 3.7% 2007-03-26
CVE-2020-15364 EXP The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS. Patch early 6.1 medium 3.7% 2020-06-28
CVE-2009-3861 EXP Stack-based buffer overflow in SafeNet SoftRemote 10.8.5 (Build 2) and 10.3.5 (Build 6), and possibly other versions before 10.8.9, allows local users… Patch early 6.9 medium 3.7% 2009-11-04
CVE-2004-1744 EXP Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to cause a denial of service (CPU consumption or crash) via many large HTTP requests. Patch early 5.0 medium 3.7% 2004-08-24
CVE-2004-0276 EXP The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an HTT… Patch early 5.0 medium 3.7% 2004-11-23
CVE-2003-0769 EXP Cross-site scripting (XSS) vulnerability in the ICQ Web Front guestbook (guestbook.html) allows remote attackers to insert arbitrary web script and HT… Patch early 4.3 medium 3.7% 2003-09-22
CVE-2008-0547 EXP Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably earlier 4.x and 3.x versions, all… Patch early 4.3 medium 3.7% 2008-02-01
CVE-2009-2275 EXP Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrary files via a .. (dot dot) in… Patch early 5.0 medium 3.7% 2009-07-01
CVE-2007-2532 EXP Multiple cross-site scripting (XSS) vulnerabilities in Minh Nguyen Duong Obie Website Mini Web Shop 2 allow remote attackers to inject arbitrary web s… Patch early 4.3 medium 3.7% 2007-05-09
CVE-2016-2384 EXP Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows physically proximate attackers… Patch early 4.6 medium 3.7% 2016-04-27
CVE-2008-6495 EXP Cross-site scripting (XSS) vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 allows remote att… Patch early 4.3 medium 3.7% 2009-03-20
CVE-2007-6516 EXP Buffer overflow in RavWare Software MAS Flic ActiveX Control (masflc.ocx) 1.0.0.1 allows remote attackers to execute arbitrary code via a long FileNam… Patch early 6.8 medium 3.7% 2007-12-21
CVE-2014-8948 EXP Cross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote attackers to hijack the a… Patch early 6.8 medium 3.7% 2014-11-16
CVE-2015-4018 EXP SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for WordPress allows remote authent… Patch early 6.5 medium 3.7% 2015-05-21
CVE-2009-1064 EXP Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allows remote attackers to overwrit… Patch early 5.8 medium 3.7% 2009-03-26
CVE-2006-1941 EXP Neon Responder 5.4 for LANsurveyor allows remote attackers to cause a denial of service (application outage) via a crafted Clock Synchronisation packe… Patch early 5.0 medium 3.7% 2006-04-20
CVE-2004-2592 EXP Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a modified cli… Patch early 5.0 medium 3.7% 2004-12-31
CVE-2017-8469 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.5 medium 3.7% 2017-06-15
CVE-2005-0870 EXP Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary we… Patch early 4.3 medium 3.7% 2005-05-02
CVE-2012-4668 EXP Cross-site scripting (XSS) vulnerability in Roundcube Webmail 0.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 3.7% 2012-08-25
CVE-2007-6605 EXP Buffer overflow in a certain ActiveX control in SkyFexClient.ocx 1.0.2.77 in SkyFex Client 1.0 allows remote attackers to execute arbitrary code via l… Patch early 5.8 medium 3.7% 2007-12-31
CVE-2017-8462 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 3.7% 2017-06-15
CVE-2017-8478 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 3.7% 2017-06-15
CVE-2017-8482 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 3.7% 2017-06-15
CVE-2017-8484 EXP Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,… Patch early 5.0 medium 3.7% 2017-06-15
CVE-2017-8488 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 3.7% 2017-06-15
CVE-2017-8492 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 3.7% 2017-06-15
CVE-2014-1836 EXP Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arb… Patch early 6.4 medium 3.7% 2015-07-01
← previous page 148 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt