peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,585 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

207,237 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-5349 EXP Stack-based buffer overflow in Baidu Spark Browser 26.5.9999.3511 allows remote attackers to cause a denial of service (application crash) via nested… Patch early 5.0 medium 3.8% 2014-08-19
CVE-2006-2181 EXP Multiple cross-site scripting (XSS) vulnerabilities in Albinator 2.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via t… Patch early 4.3 medium 3.8% 2006-05-04
CVE-2006-4523 EXP The web-based management interface in 2Wire, Inc. HomePortal and OfficePortal Series modems and routers allows remote attackers to cause a denial of s… Patch early 5.0 medium 3.8% 2006-09-01
CVE-2008-1563 EXP The "decode as" feature in packet-bssap.c in the SCCP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.8 allows remote attackers to caus… Patch early 4.3 medium 3.8% 2008-03-31
CVE-2007-1564 EXP The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan,… Patch early 6.8 medium 3.8% 2007-03-21
CVE-2009-1203 EXP WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 does not properly distinguish its own login scree… Patch early 6.0 medium 3.8% 2009-06-25
CVE-2013-1466 EXP Multiple cross-site scripting (XSS) vulnerabilities in glFusion before 1.2.2.pl4 allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 3.8% 2014-02-05
CVE-2000-1196 EXP PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPag… Patch early 5.0 medium 3.8% 2001-08-31
CVE-2023-4119 EXP A vulnerability has been found in Academy LMS 6.0 and classified as problematic. This vulnerability affects unknown code of the file /academy/home/cou… Patch early 4.3 medium 3.8% 2023-08-03
CVE-2008-3101 EXP Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the pare… Patch early 4.3 medium 3.8% 2008-09-03
CVE-2010-3602 EXP Cross-site scripting (XSS) vulnerability in ProfileView.aspx in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 3.8% 2010-09-24
CVE-2012-2156 EXP Multiple cross-site scripting (XSS) vulnerabilities in Plume CMS 1.2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (… Patch early 4.3 medium 3.8% 2012-04-11
CVE-2012-1065 EXP Insecure method vulnerability in TuxScripting.dll in the TuxSystem ActiveX control in 2X ApplicationServer 10.1 Build 1224 allows remote attackers to… Patch early 4.3 medium 3.8% 2012-02-14
CVE-2018-5404 EXP The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows an authenticated, remote attacker with least privileges ('User Console Only' role) t… Patch early 6.5 medium 3.8% 2019-06-03
CVE-2004-1910 EXP rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to the GetPrivateProfileString fu… Patch early 5.0 medium 3.8% 2004-12-31
CVE-2008-3773 EXP Cross-site scripting (XSS) vulnerability in vBulletin 3.7.2 PL1 and 3.6.10 PL3, when "Show New Private Message Notification Pop-Up" is enabled, allows… Patch early 4.3 medium 3.8% 2008-08-22
CVE-2001-1045 EXP Directory traversal vulnerability in basilix.php3 in Basilix Webmail 1.0.3beta and earlier allows remote attackers to read arbitrary files via a .. (d… Patch early 5.0 medium 3.8% 2001-07-06
CVE-2006-7222 EXP Buffer overflow in the CFLICStream::_deltachunk function in FLICSource.cpp in Media Player Classic (MPC) 6.4.9.0 allows user-assisted remote attackers… Patch early 6.8 medium 3.8% 2007-08-28
CVE-2002-2359 EXP Cross-site scripting (XSS) vulnerability in the FTP view feature in Mozilla 1.0 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 3.8% 2002-12-31
CVE-2015-3933 EXP Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary… Patch early 9.8 critical 3.8% 2017-11-08
CVE-2013-0192 EXP File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config. Patch early 4.9 medium 3.8% 2020-02-07
CVE-2006-2241 EXP PHP remote file inclusion vulnerability in show.php in Fast Click SQL Lite 1.1.3 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 6.4 medium 3.8% 2006-05-09
CVE-2006-2393 EXP The client_cmd function in Empire 4.3.2 and earlier allows remote attackers to cause a denial of service (application crash) by causing long text stri… Patch early 5.0 medium 3.8% 2006-05-16
CVE-2020-15038 EXP The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS. Patch early 5.4 medium 3.8% 2020-06-24
CVE-2001-0463 EXP Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter. Patch early 5.0 medium 3.8% 2001-06-27
CVE-2001-0467 EXP Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a \... (modified dot… Patch early 5.0 medium 3.8% 2001-06-27
CVE-2002-0946 EXP Directory traversal vulnerability in SeaNox Devwex before 1.2002.0601 allows remote attackers to read arbitrary files via ..\ (dot dot) sequences in a… Patch early 5.0 medium 3.8% 2002-10-04
CVE-2012-2913 EXP Multiple cross-site scripting (XSS) vulnerabilities in the Leaflet plugin 0.0.1 for WordPress allow remote attackers to inject arbitrary web script or… Patch early 4.3 medium 3.8% 2012-05-21
CVE-2013-7190 EXP Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitrary files via the (1) tmpid pa… Patch early 5.0 medium 3.8% 2013-12-20
CVE-2007-5304 EXP Multiple cross-site scripting (XSS) vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) r… Patch early 4.3 medium 3.8% 2007-10-09
← previous page 201 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt