peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,267 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

170,013 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-4631 EXP Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.2… Patch early 5.4 medium 3.7% 2018-10-18
CVE-2004-1927 EXP Directory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to de… Patch early 5.0 medium 3.7% 2004-04-11
CVE-2004-0072 EXP Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \.. (backslash .., "%5c%2… Patch early 5.0 medium 3.7% 2004-02-17
CVE-2007-5699 EXP Stack-based buffer overflow in eIQNetworks Enterprise Security Analyzer (ESA) 2.5 allows remote attackers to execute arbitrary code via certain data o… Patch early 6.8 medium 3.7% 2007-10-29
CVE-2021-44916 EXP Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routin… Patch early 6.1 medium 3.7% 2021-12-20
CVE-2019-9554 EXP In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new U… Patch early 6.1 medium 3.7% 2019-12-31
CVE-2007-6752 EXP Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for… Patch early 6.8 medium 3.7% 2012-03-28
CVE-2007-0298 EXP PHP remote file inclusion vulnerability in show.php in LunarPoll, when register_globals is enabled, allows remote attackers to execute arbitrary PHP c… Patch early 6.8 medium 3.7% 2007-01-17
CVE-2013-2684 EXP Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecifie… Patch early 6.1 medium 3.7% 2020-02-06
CVE-2007-1149 EXP Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the step paramete… Patch early 5.0 medium 3.7% 2007-03-02
CVE-2006-2410 EXP raydium_network_netcall_exec function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to cause a denial of service (appli… Patch early 5.0 medium 3.7% 2006-05-16
CVE-2006-2412 EXP The raydium_network_read function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to cause a denial of service (applicati… Patch early 5.0 medium 3.7% 2006-05-16
CVE-2018-20418 EXP index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab. Patch early 4.8 medium 3.7% 2018-12-24
CVE-2005-1480 EXP Directory traversal vulnerability in RaidenFTPD before 2.4.2241 allows remote attackers to read arbitrary files via a "..\\" (dot dot backslash) in th… Patch early 5.0 medium 3.7% 2005-05-11
CVE-2019-6209 EXP An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixe… Patch early 5.5 medium 3.7% 2019-03-05
CVE-2005-2479 EXP Quick 'n Easy FTP Server 3.0 allows remote attackers to cause a denial of service (application crash or CPU consumption) via a long USER command. Patch early 5.0 medium 3.7% 2005-08-05
CVE-2009-1067 EXP Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web script or HTML via the x para… Patch early 4.3 medium 3.7% 2009-03-26
CVE-2011-2841 EXP Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, which allows remote attackers t… Patch early 6.8 medium 3.7% 2011-09-19
CVE-2007-6553 EXP Multiple PHP remote file inclusion vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to execute arbitrary PHP code via a URL i… Patch early 6.8 medium 3.7% 2007-12-28
CVE-2015-2275 EXP Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 3.7% 2015-03-12
CVE-2003-0749 EXP Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbi… Patch early 6.8 medium 3.7% 2003-10-20
CVE-2012-2917 EXP Cross-site scripting (XSS) vulnerability in the Share and Follow plugin 1.80.3 for WordPress allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 3.7% 2012-05-21
CVE-2005-3236 EXP Multiple SQL injection vulnerabilities in Cyphor 0.19 allow remote attackers to execute arbitrary SQL and obtain administrative access via (1) the fid… Patch early 6.8 medium 3.7% 2005-10-14
CVE-2007-0347 EXP The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users… Patch early 4.3 medium 3.7% 2007-01-29
CVE-2003-1369 EXP Buffer overflow in ByteCatcher FTP client 1.04b allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a… Patch early 6.8 medium 3.7% 2003-12-31
CVE-2011-4045 EXP Buffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote atta… Patch early 4.3 medium 3.7% 2012-04-03
CVE-2002-2192 EXP Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web script via (1) a Host: header… Patch early 4.3 medium 3.7% 2002-12-31
CVE-2020-14943 EXP The Firstname and Lastname parameters in Global RADAR BSA Radar 1.6.7234.24750 and earlier are vulnerable to stored cross-site scripting (XSS) via Upd… Patch early 5.4 medium 3.7% 2020-06-22
CVE-2007-3227 EXP Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attacker… Patch early 4.3 medium 3.7% 2007-06-14
CVE-2004-1380 EXP Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the di… Patch early 5.0 medium 3.7% 2004-10-20
← previous page 149 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt