peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,567 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

170,164 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2003-0523 EXP Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the… Patch early 6.8 medium 3.3% 2003-08-18
CVE-2007-0143 EXP Multiple PHP remote file inclusion vulnerabilities in NUNE News Script 2.0pre2 allow remote attackers to execute arbitrary PHP code via a URL in the c… Patch early 6.8 medium 3.3% 2007-01-09
CVE-2007-1118 EXP Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… Patch early 6.8 medium 3.3% 2007-02-27
CVE-2007-3161 EXP Buffer overflow in Ace-FTP Client 1.24a allows user-assisted, remote FTP servers to execute arbitrary code via a long response. Patch early 6.8 medium 3.3% 2007-06-11
CVE-2008-6659 EXP Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated users… Patch early 5.5 medium 3.3% 2009-04-07
CVE-2014-4033 EXP Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to inject arb… Patch early 4.3 medium 3.3% 2014-06-11
CVE-2009-0290 EXP Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files via a ..… Patch early 6.8 medium 3.3% 2009-01-27
CVE-2008-6518 EXP Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users to execute arbitrary code by… Patch early 6.5 medium 3.3% 2009-03-25
CVE-2008-1958 EXP Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to execute arbi… Patch early 6.5 medium 3.3% 2008-04-25
CVE-2007-1287 EXP A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct cross-site scripting (XSS) at… Patch early 4.3 medium 3.3% 2007-03-06
CVE-2006-6942 EXP Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1)… Patch early 6.8 medium 3.3% 2007-01-19
CVE-2011-2260 EXP Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Products Suite 2.1.1 allows remote attackers to affect confidentialit… Patch early 5.8 medium 3.3% 2011-07-20
CVE-2006-4962 EXP Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read and execute arbitrary local f… Patch early 6.4 medium 3.3% 2006-09-23
CVE-2011-4882 EXP The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to cause a denial of service (application exit) via an unsp… Patch early 5.0 medium 3.3% 2012-04-13
CVE-2008-3823 EXP Cross-site scripting (XSS) vulnerability in MIME/MIME/Contents.php in the MIME library in Horde 3.2.x before 3.2.2 allows remote attackers to inject a… Patch early 4.3 medium 3.3% 2008-09-12
CVE-2012-4739 EXP Multiple cross-site scripting (XSS) vulnerabilities in Barracuda SSL VPN before 2.2.2.203 (2012-07-05) allow remote attackers to inject arbitrary web… Patch early 4.3 medium 3.3% 2012-08-31
CVE-2011-0506 EXP Directory traversal vulnerability in modules/profile/user.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers to execute arbitrary code via… Patch early 6.8 medium 3.3% 2011-01-20
CVE-2008-6913 EXP Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated users to execute arbitrary code by… Patch early 6.5 medium 3.3% 2009-08-07
CVE-2008-6928 EXP Unrestricted file upload vulnerability in PHPStore Complete Classifieds allows remote authenticated users to execute arbitrary code by uploading a fil… Patch early 6.5 medium 3.3% 2009-08-11
CVE-2008-7052 EXP Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticated users to execute arbitrary… Patch early 6.5 medium 3.3% 2009-08-24
CVE-2000-0660 EXP The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack. Patch early 5.0 medium 3.3% 2000-07-12
CVE-2009-3182 EXP Unrestricted file upload vulnerability in admin/editor/filemanager/browser.html in Anantasoft Gazelle CMS 1.0 allows remote attackers to execute arbit… Patch early 6.8 medium 3.3% 2009-09-11
CVE-2014-2559 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allow remote attackers to h… Patch early 6.8 medium 3.3% 2014-10-17
CVE-2006-1480 EXP Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and execute commands by (1) injecti… Patch early 5.1 medium 3.3% 2006-03-29
CVE-2006-2424 EXP PHP remote file inclusion vulnerability in ezUserManager 1.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitra… Patch early 5.1 medium 3.3% 2006-05-17
CVE-2014-4035 EXP Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote attackers to in… Patch early 4.3 medium 3.3% 2014-06-11
CVE-2014-8380 EXP Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer Header in… Patch early 4.3 medium 3.3% 2014-10-21
CVE-2015-1575 EXP Multiple cross-site scripting (XSS) vulnerabilities in u5CMS before 3.9.4 allow remote attackers to inject arbitrary web script or HTML via the (1) c,… Patch early 4.3 medium 3.3% 2015-02-11
CVE-2007-4047 EXP geoBlog (aka BitDamaged) 1 does not require authentication for (1) deletecomment.php, (2) deleteblog.php, and (3) listcomment.php in admin/, which all… Patch early 6.4 medium 3.3% 2007-07-27
CVE-2002-0879 EXP showtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style pathname in the FILE parameter. Patch early 5.0 medium 3.3% 2002-10-04
← previous page 168 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt