peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,590 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

206,921 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2013-1408 EXP Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execut… Patch early 6.5 medium 4.3% 2014-03-24
CVE-2019-2861 EXP Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported version that is affected is 11.1.2.… Patch early 4.2 medium 4.3% 2019-07-23
CVE-2002-1434 EXP Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML script as ot… Patch early 6.8 medium 4.3% 2003-04-11
CVE-2006-2955 EXP Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice 7.5 and earlier allow remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 4.3% 2006-06-12
CVE-2007-0827 EXP The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that invokes the R… Patch early 6.8 medium 4.3% 2007-02-07
CVE-2004-0725 EXP Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbitrary web script or HTML via th… Patch early 6.8 medium 4.3% 2004-07-27
CVE-2010-2544 EXP Cross-site scripting (XSS) vulnerability in utilities.php in Cacti before 0.8.7g, as used in Red Hat High Performance Computing (HPC) Solution and oth… Patch early 4.3 medium 4.3% 2010-08-23
CVE-2013-2637 EXP A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorde… Patch early 6.1 medium 4.3% 2020-02-12
CVE-2009-1938 EXP Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecifie… Patch early 4.3 medium 4.3% 2009-06-05
CVE-2006-6719 EXP The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause a denial of service (applicati… Patch early 5.0 medium 4.3% 2006-12-23
CVE-2006-2122 EXP PHP remote file inclusion vulnerability in index.php in CoolMenus allows remote attackers to execute arbitrary code via a URL in the page parameter.… Patch early 6.8 medium 4.3% 2006-05-01
CVE-2018-11522 EXP Yosoro 1.0.4 has stored XSS. Patch early 6.1 medium 4.3% 2018-06-02
CVE-2012-4231 EXP Cross-site scripting (XSS) vulnerability in admin/index.php in jCore before 1.0pre2 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 4.3% 2012-10-22
CVE-2007-3182 EXP Multiple cross-site scripting (XSS) vulnerabilities in Calendarix 0.7.20070307, when register_globals is enabled, allow remote attackers to inject arb… Patch early 4.3 medium 4.3% 2007-06-26
CVE-2008-6978 EXP Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary code by uploading a file with a… Patch early 6.8 medium 4.3% 2009-08-19
CVE-2000-0984 EXP The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string. Patch early 5.0 medium 4.3% 2000-12-19
CVE-2017-9602 EXP KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthen… Patch early 9.8 critical 4.3% 2017-06-16
CVE-2006-3259 EXP Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) ep paramet… Patch early 4.3 medium 4.3% 2006-06-27
CVE-2012-5876 EXP Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to cause a denial of service (cras… Patch early 5.0 medium 4.3% 2014-05-30
CVE-2006-5210 EXP Directory traversal vulnerability in IronWebMail before 6.1.1 HotFix-17 allows remote attackers to read arbitrary files via a GET request to the IM_FI… Patch early 5.0 medium 4.3% 2006-10-16
CVE-2004-2099 EXP Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary cod… Patch early 5.1 medium 4.3% 2004-12-31
CVE-2011-5049 EXP MySQL 5.5.8, when running on Windows, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted packet to TCP port… Patch early 4.3 medium 4.3% 2012-01-04
CVE-2003-1368 EXP Buffer overflow in the 32bit FTP client 9.49.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a… Patch early 6.4 medium 4.3% 2003-12-31
CVE-2008-1467 EXP CenterIM 4.22.3 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URI, related to "receive… Patch early 6.8 medium 4.3% 2008-03-24
CVE-2016-5740 EXP An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical attachments within scheduling E-Ma… Patch early 6.1 medium 4.3% 2016-12-15
CVE-2002-1480 EXP Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which i… Patch early 6.8 medium 4.3% 2003-04-22
CVE-2017-2445 EXP An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… Patch early 6.1 medium 4.3% 2017-04-02
CVE-2017-8684 EXP Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1, allows… Patch early 5.5 medium 4.3% 2017-09-13
CVE-2012-5858 EXP Samsung Kies Air 2.1.207051 and 2.1.210161 relies on the IP address for authentication, which allows remote man-in-the-middle attackers to read arbitr… Patch early 4.3 medium 4.3% 2012-12-03
CVE-2011-4958 EXP Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x before 2.4.6 allows remote at… Patch early 4.3 medium 4.3% 2014-04-08
← previous page 185 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt