peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,553 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

207,229 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-9245 EXP The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the logi… Patch early 9.8 critical 3.9% 2018-04-22
CVE-2018-20503 EXP Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter. Patch early 6.1 medium 3.9% 2019-05-07
CVE-2023-24657 EXP phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php. Patch early 6.1 medium 3.9% 2023-03-08
CVE-2019-5722 EXP An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handling, it has various SQL inject… Patch early 9.8 critical 3.9% 2019-03-21
CVE-2019-8923 EXP XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued. Patch early 9.8 critical 3.9% 2019-05-14
CVE-2006-5241 EXP Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Gallery 1.4 and earlier, when register_globals is enabled, allow remote attackers… Patch early 5.1 medium 3.9% 2006-10-12
CVE-2005-0843 EXP CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body parameter… Patch early 5.0 medium 3.9% 2005-05-02
CVE-2017-9260 EXP The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of servi… Patch early 5.5 medium 3.9% 2017-07-27
CVE-2006-2040 EXP Multiple SQL injection vulnerabilities in photokorn 1.53 and 1.542 allow remote attackers to execute arbitrary SQL commands via the (1) cat, (2) pic a… Patch early 6.4 medium 3.9% 2006-04-26
CVE-2017-8479 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 3.9% 2017-06-15
CVE-2017-8481 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 3.9% 2017-06-15
CVE-2017-8489 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 3.9% 2017-06-15
CVE-2017-8491 EXP The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… Patch early 5.0 medium 3.9% 2017-06-15
CVE-2007-4140 EXP Buffer overflow in Live for Speed (LFS) S2 ALPHA PATCH 0.5x allows user-assisted remote attackers to execute arbitrary code via a .mpr file (replay fi… Patch early 6.8 medium 3.9% 2007-08-03
CVE-2010-3077 EXP Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows remote attackers to inject ar… Patch early 4.3 medium 3.9% 2010-11-09
CVE-2011-5228 EXP Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote attackers to inject arbitrary web… Patch early 4.3 medium 3.9% 2012-10-25
CVE-2013-4950 EXP Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the element_2 pa… Patch early 4.3 medium 3.9% 2013-07-29
CVE-2008-5185 EXP The highlighting functionality in geshi.php in GeSHi before 1.0.8 allows remote attackers to cause a denial of service (infinite loop) via an XML sequ… Patch early 5.0 medium 3.9% 2008-11-21
CVE-2007-4803 EXP Buffer overflow in AtomixMP3 2.3 allows user-assisted remote attackers to execute arbitrary code via long strings in file and title fields in a .pls f… Patch early 6.8 medium 3.9% 2007-09-11
CVE-2019-10349 EXP A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jen… Patch early 5.4 medium 3.9% 2019-07-11
CVE-2006-2986 EXP Multiple cross-site scripting (XSS) vulnerabilities in Baby Katie Media (a) very Simple Car Lister (vSCAL) 1.0 and (b) very simple Realty Lister (vsRE… Patch early 4.3 medium 3.9% 2006-06-13
CVE-2006-3006 EXP Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly other versions before 0.50, allows remote attackers to inject arbitrary HTML or w… Patch early 4.3 medium 3.9% 2006-06-13
CVE-2003-1157 EXP Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 3.9% 2003-12-31
CVE-2015-2511 EXP The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012… Patch early 6.9 medium 3.9% 2015-09-09
CVE-2015-2518 EXP The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012… Patch early 6.9 medium 3.9% 2015-09-09
CVE-2018-6219 EXP An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain typ… Patch early 6.5 medium 3.9% 2018-03-15
CVE-2023-1258 EXP Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allo… Patch early 5.3 medium 3.9% 2023-03-31
CVE-2002-2338 EXP The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no n… Patch early 5.0 medium 3.9% 2002-12-31
CVE-2018-7178 EXP SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter. Patch early 9.8 critical 3.9% 2018-02-17
CVE-2006-1486 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in realestateZONE 4.2 allow remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 3.9% 2006-03-29
← previous page 197 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt