peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,556 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

207,231 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-5290 EXP Multiple cross-site scripting (XSS) vulnerabilities in MailBee WebMail Pro 3.4 and earlier; and possibly MailBee WebMail Pro ASP before 3.4.64, WebMai… Patch early 4.3 medium 3.8% 2007-10-09
CVE-2005-0438 EXP awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter. Patch early 5.0 medium 3.8% 2005-05-02
CVE-2015-4425 EXP Directory traversal vulnerability in pimcore before build 3473 allows remote authenticated users with the "assets" permission to create or write to ar… Patch early 4.9 medium 3.8% 2015-08-18
CVE-2004-2366 EXP Buffer overflow in GlobalSCAPE Secure FTP Server 2.0 B03.11.2004.2 allows remote attackers to cause a denial of service (crash) via a SITE command wit… Patch early 5.0 medium 3.8% 2004-12-31
CVE-2012-4344 EXP Cross-site scripting (XSS) vulnerability in Ipswitch WhatsUp Gold 15.02 allows remote attackers to inject arbitrary web script or HTML via unspecified… Patch early 4.3 medium 3.8% 2012-08-15
CVE-2008-4671 EXP Cross-site scripting (XSS) vulnerability in wp-admin/wp-blogs.php in Wordpress MU (WPMU) before 2.6 allows remote attackers to inject arbitrary web sc… Patch early 4.3 medium 3.8% 2008-10-22
CVE-2003-0624 EXP Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web scri… Patch early 4.3 medium 3.8% 2003-12-01
CVE-2015-0060 EXP The font mapper in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,… Patch early 4.7 medium 3.8% 2015-02-11
CVE-2006-2635 EXP Multiple cross-site scripting (XSS) vulnerabilities in Tikiwiki (aka Tiki CMS/Groupware) 1.9.x allow remote attackers to inject arbitrary web script o… Patch early 4.3 medium 3.8% 2006-05-30
CVE-2007-0019 EXP Multiple heap-based buffer overflows in rumpusd in Rumpus 5.1 and earlier (1) allow remote authenticated users to execute arbitrary code via a long LI… Patch early 6.5 medium 3.8% 2007-01-19
CVE-2022-36664 EXP Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter. Patch early 6.1 medium 3.8% 2022-12-26
CVE-2006-2899 EXP Unspecified vulnerability in ESTsoft InternetDISK versions before 2006/04/20 allows remote authenticated users to execute arbitrary code, possibly by… Patch early 6.5 medium 3.8% 2006-06-07
CVE-2008-5712 EXP The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COLOR attribute in an H… Patch early 5.0 medium 3.8% 2008-12-24
CVE-2017-17648 EXP Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter. Patch early 9.8 critical 3.8% 2017-12-13
CVE-2018-5980 EXP SQL Injection exists in the Solidres 2.5.1 component for Joomla! via the direction parameter in a hub.search action. Patch early 9.8 critical 3.8% 2018-02-17
CVE-2018-6578 EXP SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions req… Patch early 9.8 critical 3.8% 2018-02-02
CVE-2018-6579 EXP SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request. Patch early 9.8 critical 3.8% 2018-02-02
CVE-2018-6584 EXP SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request. Patch early 9.8 critical 3.8% 2018-02-17
CVE-2020-18723 EXP Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side wh… Patch early 5.4 medium 3.8% 2021-02-03
CVE-2014-5093 EXP Status2k does not remove the install directory allowing credential reset. Patch early 9.8 critical 3.8% 2020-01-10
CVE-2004-2021 EXP Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the file… Patch early 5.0 medium 3.8% 2004-12-31
CVE-2003-0495 EXP Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote attackers to insert arbitrary web script via a news item. Patch early 4.3 medium 3.8% 2003-08-07
CVE-2008-3365 EXP Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows remote attackers to include and… Patch early 6.8 medium 3.8% 2008-07-30
CVE-2017-11331 EXP The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error)… Patch early 5.5 medium 3.8% 2017-07-31
CVE-2000-0324 EXP pcAnywhere 8.x and 9.0 allows remote attackers to cause a denial of service via a TCP SYN scan, e.g. by nmap. Patch early 5.0 medium 3.8% 2000-04-25
CVE-2006-2121 EXP PHP remote file include vulnerability in admin/config_settings.tpl.php in I-RATER Platinum allows remote attackers to execute arbitrary code via a URL… Patch early 5.0 medium 3.8% 2006-05-01
CVE-2013-3304 EXP Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in th… Patch early 5.0 medium 3.8% 2014-10-30
CVE-2026-59827 EXP Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances wi… Patch early 9.9 critical 3.8% 2026-07-09
CVE-2011-5257 EXP Multiple cross-site scripting (XSS) vulnerabilities in the Classipress theme before 3.1.5 for WordPress allow remote attackers to inject arbitrary web… Patch early 4.3 medium 3.8% 2013-02-12
CVE-2006-2341 EXP The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers to… Patch early 5.0 medium 3.8% 2006-05-12
← previous page 200 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt