peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,488 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

170,124 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-0680 EXP Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a ..… Patch early 5.0 medium 3.5% 2002-07-23
CVE-2014-9179 EXP Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authenticated users to inject arbit… Patch early 4.0 medium 3.5% 2014-12-02
CVE-2004-2005 EXP Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-mail with (1) a link to a long… Patch early 5.1 medium 3.5% 2004-05-06
CVE-2012-4773 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of administ… Patch early 6.8 medium 3.5% 2012-10-22
CVE-2002-0708 EXP Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary files via a… Patch early 5.0 medium 3.5% 2002-10-10
CVE-2014-8677 EXP The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing databas… Patch early 5.3 medium 3.5% 2017-08-31
CVE-2008-2748 EXP Skulltag 0.97d2-RC2 and earlier allows remote attackers to cause a denial of service (daemon hang) via a series of long, malformed connect packets, re… Patch early 5.0 medium 3.5% 2008-06-18
CVE-2015-6945 EXP Cross-site scripting (XSS) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to inject arbitrary web script or HTML via the bd pa… Patch early 4.3 medium 3.5% 2015-09-15
CVE-2008-0388 EXP SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user paramete… Patch early 6.8 medium 3.5% 2008-01-23
CVE-2007-6187 EXP Multiple directory traversal vulnerabilities in PHP Content Architect (aka NoAh) 0.9 pre 1.2 and earlier allow remote attackers to read arbitrary file… Patch early 5.0 medium 3.5% 2007-11-30
CVE-2008-0265 EXP Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP 9.4.3 allow remote attackers t… Patch early 4.3 medium 3.5% 2008-01-15
CVE-2007-3479 EXP Stack-based buffer overflow in PCSoft WinDEV 11 (01F110053p) allows user-assisted remote attackers to execute arbitrary code via a long string in the… Patch early 6.8 medium 3.5% 2007-06-28
CVE-2012-1468 EXP Incomplete blacklist vulnerability in Open Journal Systems before 2.3.7 allows remote authenticated users with the Author Role permission to execute a… Patch early 6.0 medium 3.5% 2012-09-06
CVE-2006-4874 EXP Multiple cross-site scripting (XSS) vulnerabilities in Jupiter CMS allow remote attackers to inject arbitrary web script or HTML via the (1) language[… Patch early 4.3 medium 3.5% 2006-09-19
CVE-2003-1146 EXP Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via th… Patch early 6.8 medium 3.5% 2003-05-11
CVE-2006-2770 EXP Directory traversal vulnerability in randompic.php in pppBLOG 0.3.8 and earlier, when register_globals is enabled, allows remote attackers to read arb… Patch early 5.4 medium 3.5% 2006-06-02
CVE-2006-4633 EXP index.php in SoftBB 0.1, and possibly earlier, allows remote attackers to obtain the installation path via a null or invalid page[] parameter. Patch early 5.0 medium 3.5% 2006-09-08
CVE-2008-5061 EXP Cross-site scripting (XSS) vulnerability in php/cal_default.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 3.5% 2008-11-13
CVE-2011-5173 EXP Buffer overflow in Bugbear Entertainment FlatOut 2005 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute… Patch early 6.8 medium 3.5% 2012-09-15
CVE-2007-4463 EXP The Fileinfo 2.0.9 plugin for Total Commander allows user-assisted remote attackers to cause a denial of service (unhandled exception) via an invalid… Patch early 5.0 medium 3.5% 2007-08-21
CVE-2007-4531 EXP Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a client denial of service (crash) via… Patch early 5.0 medium 3.5% 2007-08-25
CVE-2013-6882 EXP Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earlier allow (1) remote attackers… Patch early 4.3 medium 3.5% 2013-12-17
CVE-2007-5685 EXP The safe_path function in shttp before 0.0.5 allows remote attackers to conduct directory traversal attacks and read files via a combination of ".." a… Patch early 5.0 medium 3.5% 2007-10-28
CVE-2018-11628 EXP Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malicious attackers to send a crafte… Patch early 6.1 medium 3.5% 2018-06-01
CVE-2006-4753 EXP Directory traversal vulnerability in index.php in PHProg before 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang par… Patch early 5.0 medium 3.5% 2006-09-13
CVE-2019-11398 EXP Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitrary web script or HTML via the… Patch early 6.1 medium 3.5% 2019-05-08
CVE-2005-3285 EXP Cross-site scripting (XSS) vulnerability in comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus allows remote attackers to inject arbit… Patch early 4.3 medium 3.5% 2005-10-23
CVE-2004-1698 EXP The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via… Patch early 5.0 medium 3.5% 2004-09-24
CVE-2006-6800 EXP PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to execute arbitrary PHP code via… Patch early 6.8 medium 3.5% 2006-12-28
CVE-2008-5160 EXP Unspecified vulnerability in MyServer 0.8.11 allows remote attackers to cause a denial of service (daemon crash) via multiple invalid requests with th… Patch early 5.0 medium 3.5% 2008-11-18
← previous page 159 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt