peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,573 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

206,921 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-1218 EXP Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Ser… Patch early 4.3 medium 4.4% 2009-04-01
CVE-2002-1006 EXP Cross-site scripting (XSS) vulnerability in BBC Education Text to Speech Internet Enhancer (Betsie) 1.5.11 and earlier allows remote attackers to exec… Patch early 6.8 medium 4.4% 2002-10-04
CVE-2003-1472 EXP Buffer overflow in 3D-FTP client 4.0 allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long ban… Patch early 5.0 medium 4.4% 2003-12-31
CVE-2009-2705 EXP CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "… Patch early 4.3 medium 4.4% 2009-08-11
CVE-2006-4917 EXP Cross-site scripting (XSS) vulnerability in search.php in PT News 1.7.8 allows remote attackers to inject arbitrary web script or HTML via the pgname… Patch early 4.3 medium 4.4% 2006-09-21
CVE-2006-2331 EXP Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via (1) a .. (… Patch early 6.4 medium 4.4% 2006-05-12
CVE-2013-4098 EXP ServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote attackers to inject arbitrary error-page text via the message parameter. Patch early 5.0 medium 4.4% 2013-06-28
CVE-2009-2043 EXP nsViewManager.cpp in Mozilla Firefox 3.0.2 through 3.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and applicati… Patch early 4.3 medium 4.4% 2009-06-12
CVE-2006-2736 EXP PHP remote file inclusion vulnerability in blend_data/blend_common.php in Blend Portal 1.2.0, as used with phpBB when register_globals is enabled, all… Patch early 5.1 medium 4.4% 2006-06-01
CVE-2005-1492 EXP Cross-site scripting (XSS) vulnerability in user.cgi in Gossamer Threads Links SQL 2.x and 3.0 allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 4.4% 2005-05-11
CVE-2023-1826 EXP A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of t… Patch early 6.3 medium 4.4% 2023-04-04
CVE-2018-17784 EXP Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to condu… Patch early 6.1 medium 4.4% 2018-10-10
CVE-2006-7147 EXP PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier allows remote attackers to exec… Patch early 6.8 medium 4.4% 2007-03-07
CVE-2005-3995 EXP Format string vulnerability in the dosyslog function in the OBEX server (obexsrv.c) for Sobexsrv before 1.0.0-pre4, when the syslog (-S) function is e… Patch early 5.1 medium 4.4% 2005-12-05
CVE-2007-0883 EXP Directory traversal vulnerability in portalgroups/portalgroups/getfile.cgi in IP3 NetAccess before firmware 4.1.9.6 allows remote attackers to read ar… Patch early 5.0 medium 4.3% 2007-02-12
CVE-2007-5464 EXP Stack-based buffer overflow in Live for Speed 0.5X10 and earlier allows remote authenticated users to cause a denial of service (client crash) and pos… Patch early 6.5 medium 4.3% 2007-10-15
CVE-2006-3036 EXP Multiple cross-site scripting (XSS) vulnerabilities in 35mmslidegallery 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 5.8 medium 4.3% 2006-06-15
CVE-2009-0496 EXP Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 4.3% 2009-02-10
CVE-2019-16693 EXP phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used. Patch early 9.8 critical 4.3% 2019-09-22
CVE-2005-4402 EXP Buffer overflow in MailEnable Professional 1.71 and earlier, and Enterprise 1.1 and earlier, allows remote authenticated users to execute arbitrary co… Patch early 6.5 medium 4.3% 2005-12-20
CVE-2008-4795 EXP The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which allows remote attackers to inje… Patch early 4.3 medium 4.3% 2008-10-30
CVE-2007-5111 EXP A certain ActiveX control in EBCRYPT.DLL 2.0 in EB Design ebCrypt allows remote attackers to cause a denial of service (crash) via a string argument t… Patch early 4.3 medium 4.3% 2007-09-26
CVE-2015-8724 EXP The AirPDcapDecryptWPABroadcastKey function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1… Patch early 5.5 medium 4.3% 2016-01-04
CVE-2015-8731 EXP The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 doe… Patch early 5.5 medium 4.3% 2016-01-04
CVE-2006-7026 EXP PHP remote file inclusion vulnerability in sources/join.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows remot… Patch early 6.8 medium 4.3% 2007-02-23
CVE-2017-16884 EXP Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web script or HTML via vectors related… Patch early 6.1 medium 4.3% 2017-12-07
CVE-2016-5348 EXP The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows man-in-… Patch early 5.9 medium 4.3% 2016-10-10
CVE-2001-1097 EXP Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets. Patch early 5.0 medium 4.3% 2001-07-24
CVE-2012-6290 EXP SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL commands via the q parameter to… Patch early 6.5 medium 4.3% 2014-03-11
CVE-2017-2480 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affect… Patch early 6.5 medium 4.3% 2017-04-02
← previous page 184 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt