peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,546 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

170,147 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-5023 EXP Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in… Patch early 6.8 medium 3.4% 2014-07-22
CVE-2006-5636 EXP PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote attackers to execute arbitrary P… Patch early 5.1 medium 3.4% 2006-11-01
CVE-2006-5727 EXP PHP remote file inclusion vulnerability in admin/controls/cart.php in sazcart 1.5 allows remote attackers to execute arbitrary PHP code via the (1) _s… Patch early 5.1 medium 3.4% 2006-11-06
CVE-2006-4664 EXP PHP remote file inclusion vulnerability in includes/functions_portal.php in Premod Shadow 2.7.1 and earlier allows remote attackers to execute arbitra… Patch early 5.1 medium 3.4% 2006-09-09
CVE-2008-5566 EXP Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote attackers to inject arbitrary w… Patch early 4.3 medium 3.4% 2008-12-15
CVE-2010-2032 EXP Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possib… Patch early 4.3 medium 3.4% 2010-05-24
CVE-2010-2130 EXP Cross-site scripting (XSS) vulnerability in wflogin.jsp in Aris Global ARISg 5.0 allows remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 3.4% 2010-06-02
CVE-2006-3546 EXP Patrice Freydiere ImgSvr (aka ADA Image Server) allows remote attackers to cause a denial of service (daemon crash) via a long HTTP POST request. NOT… Patch early 5.0 medium 3.4% 2006-07-13
CVE-2007-0986 EXP PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remote attackers to execute arbitra… Patch early 5.1 medium 3.4% 2007-02-16
CVE-2010-2856 EXP Cross-site scripting (XSS) vulnerability in admin/currencies.php in osCSS 1.2.2, and probably earlier versions, allows remote attackers to inject arbi… Patch early 4.3 medium 3.4% 2010-07-25
CVE-2005-1718 EXP Buffer overflow in LS Games War Times 1.03 and earlier allows remote attackers to cause a denial of service (server crash) via a long nickname. Patch early 5.0 medium 3.4% 2005-05-24
CVE-2018-7543 EXP Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attac… Patch early 6.1 medium 3.3% 2018-03-26
CVE-2017-2504 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. Th… Patch early 6.1 medium 3.3% 2017-05-22
CVE-2021-43701 EXP CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS[] and ord… Patch early 6.5 medium 3.3% 2022-03-29
CVE-2006-5711 EXP ECI Telecom B-FOCuS Wireless 802.11b/g ADSL2+ Router allows remote attackers to read arbitrary files via a certain HTTP request, as demonstrated by a… Patch early 5.0 medium 3.3% 2006-11-04
CVE-2011-0167 EXP The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Policy, and force the upload of arb… Patch early 4.3 medium 3.3% 2011-03-11
CVE-2007-1843 EXP PHP remote file inclusion vulnerability in gmapfactory/params.php in MapLab 2.2.1, when register_globals is enabled, allows remote attackers to execut… Patch early 6.8 medium 3.3% 2007-04-03
CVE-2019-8391 EXP qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter. Patch early 6.1 medium 3.3% 2019-05-14
CVE-2004-2371 EXP Multiple Red Storm web-based games, including Ghost Recon 1.4 and earlier, Desert Siege, and The Sum of all Fears 1.1.1.0 and earlier, do not properly… Patch early 5.0 medium 3.3% 2004-12-31
CVE-2005-1667 EXP DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request. Patch early 5.0 medium 3.3% 2005-05-18
CVE-2006-6028 EXP Directory traversal vulnerability in textview.php in Anton Vlasov DoSePa 1.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) sequ… Patch early 5.0 medium 3.3% 2006-11-21
CVE-2007-2195 EXP aMSN (aka Alvaro's Messenger) 0.96 and earlier allows remote attackers to cause a denial of service (application crash) by sending invalid data to TCP… Patch early 5.0 medium 3.3% 2007-04-24
CVE-2007-6000 EXP KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a denial of service (crash) via large HTTP cookie parameters. Patch early 5.0 medium 3.3% 2007-11-15
CVE-2009-4451 EXP Unrestricted file upload vulnerability in upper.php in kandalf upper 0.1 allows remote attackers to execute arbitrary code by uploading a file with an… Patch early 6.8 medium 3.3% 2009-12-29
CVE-2009-4819 EXP Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitrary code by uploading a file w… Patch early 6.8 medium 3.3% 2010-04-27
CVE-2010-0390 EXP Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mim… Patch early 6.8 medium 3.3% 2010-01-26
CVE-2008-6528 EXP NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to the URL, which accesses the alt… Patch early 5.0 medium 3.3% 2009-03-26
CVE-2010-4863 EXP Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 3.3% 2011-10-05
CVE-2006-4458 EXP Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers to include… Patch early 6.4 medium 3.3% 2006-08-31
CVE-2008-6900 EXP Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allows remote authenticated users… Patch early 6.5 medium 3.3% 2009-08-06
← previous page 165 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt