peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,032 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

170,268 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-1749 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 3% 2009-05-22
CVE-2009-4542 EXP Cross-site scripting (XSS) vulnerability in newticket.php in IsolSoft Support Center 2.5 allows remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 3% 2010-01-04
CVE-2009-2325 EXP Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the side para… Patch early 5.0 medium 3% 2009-07-05
CVE-2006-5832 EXP All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to obtain the full path of the web server via certain requests to (1) pub… Patch early 5.0 medium 3% 2006-11-10
CVE-2006-2431 EXP Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 a… Patch early 4.3 medium 3% 2006-05-17
CVE-2007-1190 EXP Unspecified vulnerability in the EmbeddedWB Web Browser ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors. NO… Patch early 6.8 medium 3% 2007-03-02
CVE-2006-5730 EXP PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS 0.9.2.1 and earlier allows re… Patch early 5.1 medium 3% 2006-11-06
CVE-2011-5040 EXP Multiple cross-site scripting (XSS) vulnerabilities in Infoproject Biznis Heroj allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 3% 2011-12-30
CVE-2006-4977 EXP Multiple unrestricted file upload vulnerabilities in (1) back/upload_img.php and (2) admin/upload_img.php in Walter Beschmout PhpQuiz 1.2 and earlier… Patch early 5.0 medium 3% 2006-09-25
CVE-2005-2030 EXP Ultimate PHP Board (UPB) 1.9.6 GOLD uses weak encryption for passwords in the users.dat file, which allows attackers to easily decrypt the passwords a… Patch early 5.0 medium 3% 2005-06-16
CVE-2012-1467 EXP Multiple directory traversal vulnerabilities in the iBrowser plugin library, as used in Open Journal Systems before 2.3.7, allow remote authenticated… Patch early 6.5 medium 3% 2012-09-06
CVE-2008-5787 EXP Directory traversal vulnerability in mod.php in Arab Portal 2.1 on Windows allows remote attackers to read arbitrary files via a .. (dot dot) in the f… Patch early 5.4 medium 3% 2008-12-31
CVE-2005-1325 EXP set_lang.php in phpMyVisites 1.3 allows remote attackers to read and include arbitrary files via the mylang parameter. Patch early 5.0 medium 3% 2005-05-02
CVE-2005-3018 EXP Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted data:// URL. Patch early 5.0 medium 3% 2005-09-21
CVE-2003-1017 EXP Macromedia Flash Player before 7,0,19,0 stores a Flash data file in a predictable location that is accessible to web browsers such as Internet Explore… Patch early 5.0 medium 3% 2004-01-05
CVE-2006-1922 EXP PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a… Patch early 6.4 medium 3% 2006-04-20
CVE-2006-5866 EXP Directory traversal vulnerability in Mdoc/view-sourcecode.php for phpManta 1.0.2 and earlier allows remote attackers to read and include arbitrary fil… Patch early 6.4 medium 3% 2006-11-11
CVE-2006-2723 EXP Unspecified versions of Mozilla Firefox allow remote attackers to cause a denial of service (crash) via a web page that contains a large number of nes… Patch early 5.0 medium 3% 2006-06-01
CVE-2006-5661 EXP Cross-site scripting (XSS) vulnerability in nquser.php in VIRtech Netquery allows remote attackers to inject arbitrary web script or HTML via the User… Patch early 6.8 medium 3% 2006-11-03
CVE-2006-6715 EXP PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabled, allows remote attackers to… Patch early 5.1 medium 3% 2006-12-23
CVE-2006-6938 EXP Directory traversal vulnerability in includes/common.php in NitroTech 0.0.3a, as distributed before 2006, allows remote attackers to include arbitrary… Patch early 5.0 medium 3% 2007-01-17
CVE-2002-2422 EXP Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remote attackers to inject arbitrar… Patch early 4.3 medium 3% 2002-12-31
CVE-2010-2154 EXP Cross-site scripting (XSS) vulnerability in the Search Site in CMScout 2.09, and possibly other versions, allows remote attackers to inject arbitrary… Patch early 4.3 medium 3% 2010-06-03
CVE-2009-2923 EXP Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1)… Patch early 5.0 medium 3% 2009-08-21
CVE-2009-3124 EXP Directory traversal vulnerability in get_message.cgi in QuarkMail allows remote attackers to read arbitrary files via a .. (dot dot) in the tf paramet… Patch early 5.0 medium 3% 2009-09-09
CVE-2006-7235 EXP Teamtek Universal FTP Server 1.0.50 allows remote attackers to cause a denial of service (daemon crash or hang) via (1) multiple STOR (aka PUT) comman… Patch early 5.0 medium 3% 2008-12-11
CVE-2012-5387 EXP Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordPress allows remote attackers t… Patch early 6.8 medium 3% 2012-10-24
CVE-2019-1262 EXP A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an af… Patch early 5.4 medium 3% 2019-09-11
CVE-2006-3298 EXP Yahoo! Messenger 7.5.0.814 and 7.0.438 allows remote attackers to cause a denial of service (crash) via messages that contain non-ASCII characters, wh… Patch early 5.0 medium 3% 2006-06-29
CVE-2007-5646 EXP SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows remote attackers to execute arbit… Patch early 6.8 medium 3% 2007-10-23
← previous page 184 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt