peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,590 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

206,921 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-1196 EXP Cross-site scripting (XSS) vulnerability in inmail.pl in Insite Inmail allows remote attackers to inject arbitrary web script or HTML via the acao par… Patch early 6.8 medium 4.3% 2005-01-10
CVE-2012-1124 EXP SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL commands via the search_terms… Patch early 9.8 critical 4.3% 2020-02-11
CVE-2014-0868 EXP RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which a… Patch early 4.9 medium 4.3% 2014-07-07
CVE-2015-1058 EXP Multiple cross-site scripting (XSS) vulnerabilities in AdaptCMS 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) data[C… Patch early 4.3 medium 4.3% 2015-01-16
CVE-2003-0416 EXP Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML or script via (1) the year para… Patch early 6.8 medium 4.3% 2003-06-30
CVE-2003-0492 EXP Cross-site scripting (XSS) vulnerability in search.asp for Snitz Forums 3.4.03 and earlier allows remote attackers to execute arbitrary web script via… Patch early 6.8 medium 4.3% 2003-08-07
CVE-2006-6962 EXP PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for Joomla! allows attackers to ex… Patch early 6.8 medium 4.3% 2007-01-29
CVE-2002-1708 EXP Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting scrip… Patch early 6.8 medium 4.3% 2002-12-31
CVE-2002-1727 EXP Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows remote attackers to execute arbi… Patch early 6.8 medium 4.3% 2002-12-31
CVE-2003-1516 EXP The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violate… Patch early 6.8 medium 4.3% 2003-12-31
CVE-1999-0986 EXP The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option. Patch early 5.0 medium 4.3% 1999-12-08
CVE-2008-7061 EXP The tooltip manager (chrome/views/tooltip_manager.cc) in Google Chrome 0.2.149.29 Build 1798 and possibly other versions before 0.2.149.30 allows remo… Patch early 4.3 medium 4.3% 2009-08-24
CVE-2007-6367 EXP Multiple cross-site scripting (XSS) vulnerabilities in the guestbook in SineCMS 2.3.4 and earlier allow remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 4.3% 2007-12-15
CVE-2012-2316 EXP Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows remote atta… Patch early 6.8 medium 4.3% 2012-09-09
CVE-2012-0873 EXP Multiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via t… Patch early 4.3 medium 4.3% 2012-02-23
CVE-2011-3850 EXP Cross-site scripting (XSS) vulnerability in the Atahualpa theme before 3.6.8 for WordPress allows remote attackers to inject arbitrary web script or H… Patch early 4.3 medium 4.3% 2011-09-28
CVE-2008-0616 EXP SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote authenticated administrators to e… Patch early 6.5 medium 4.3% 2008-02-06
CVE-2004-1442 EXP Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 4.3% 2004-12-31
CVE-2006-4425 EXP Multiple PHP remote file inclusion vulnerabilities in phpCOIN 1.2.3 allow remote attackers to execute arbitrary PHP code via the _CCFG[_PKG_PATH_INCL]… Patch early 5.1 medium 4.3% 2006-08-29
CVE-2005-0984 EXP Buffer overflow in the G_Printf function in Star Wars Jedi Knight: Jedi Academy 1.011 and earlier allows remote attackers to execute arbitrary code vi… Patch early 5.0 medium 4.3% 2005-05-02
CVE-2012-4000 EXP Cross-site scripting (XSS) vulnerability in the print_textinputs_var function in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellcheck… Patch early 4.3 medium 4.3% 2012-07-12
CVE-2013-4884 EXP Cross-site scripting (XSS) vulnerability in McAfee SuperScan 4.0 allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded sequ… Patch early 4.3 medium 4.3% 2014-01-21
CVE-2014-8577 EXP Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) d… Patch early 4.3 medium 4.3% 2014-10-31
CVE-2012-1259 EXP Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.… Patch early 9.8 critical 4.2% 2020-01-09
CVE-2017-13865 EXP An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchO… Patch early 5.5 medium 4.2% 2017-12-25
CVE-2008-4133 EXP The web proxy service on the D-Link DIR-100 with firmware 1.12 and earlier does not properly filter web requests with large URLs, which allows remote… Patch early 4.3 medium 4.2% 2008-09-19
CVE-2004-0675 EXP Cross-site scripting (XSS) vulnerability in (1) cart32.exe or (2) c32web.exe in Cart32 shopping cart allows remote attackers to execute arbitrary web… Patch early 6.8 medium 4.2% 2004-08-06
CVE-2005-2095 EXP options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which allows remote attackers to mo… Patch early 4.3 medium 4.2% 2005-07-13
CVE-2012-2209 EXP Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Piwigo before 2.3.4 allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 4.2% 2012-08-14
CVE-2019-0796 EXP An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privil… Patch early 5.5 medium 4.2% 2019-04-09
← previous page 186 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt