peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,769 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

170,545 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-1854 EXP Unspecified vulnerability in SmarterMail Web Server (SMWebSvr.exe) in SmarterMail 5.0.2999 allows remote attackers to cause a denial of service (servi… Patch early 5.0 medium 2.7% 2008-04-16
CVE-2009-3662 EXP FileCopa FTP Server 5.01 allows remote attackers to cause a denial of service (server hang) via a large number of crafted NOOP commands. Patch early 5.0 medium 2.7% 2009-10-11
CVE-2006-5016 EXP Unrestricted file upload vulnerability in admin/x_image.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, allows remote attackers to uplo… Patch early 5.0 medium 2.7% 2006-09-27
CVE-2006-4721 EXP Directory traversal vulnerability in admin.php in CCleague Pro Sports CMS 1.0.1 RC1 allows remote attackers to read and execute arbitrary local files… Patch early 5.1 medium 2.7% 2006-09-12
CVE-2007-1516 EXP PHP remote file inclusion vulnerability in functions/update.php in Cicoandcico CcMail 1.0 allows remote attackers to execute arbitrary PHP code via a… Patch early 6.8 medium 2.7% 2007-03-20
CVE-2007-1907 EXP PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attackers to execute arbitrary PHP… Patch early 6.8 medium 2.7% 2007-04-10
CVE-2008-3368 EXP PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to exe… Patch early 6.5 medium 2.7% 2008-07-30
CVE-2009-0673 EXP Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.30 allows remote authenticated… Patch early 6.5 medium 2.7% 2009-02-22
CVE-2014-8674 EXP Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and mb… Patch early 5.4 medium 2.6% 2020-01-06
CVE-2002-2351 EXP Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with names containing a trailing ".… Patch early 6.4 medium 2.6% 2002-12-31
CVE-2014-9236 EXP Cross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allows remote attackers to injec… Patch early 4.3 medium 2.6% 2014-12-03
CVE-2022-2846 EXP The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is a… Patch early 4.3 medium 2.6% 2022-08-16
CVE-2011-1872 EXP Hyper-V in Microsoft Windows Server 2008 Gold, SP2, R2, and R2 SP1 allows guest OS users to cause a denial of service (host OS infinite loop) via malf… Patch early 4.7 medium 2.6% 2011-06-16
CVE-2016-6851 EXP An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX Guard guest reader web applicat… Patch early 6.1 medium 2.6% 2016-12-15
CVE-2013-6128 EXP The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict SaveTo… Patch early 5.8 medium 2.6% 2013-10-25
CVE-2007-3535 EXP Multiple directory traversal vulnerabilities in GL-SH Deaf Forum 6.4.4 and earlier allow remote attackers to include and execute arbitrary local files… Patch early 6.4 medium 2.6% 2007-07-03
CVE-2005-0936 EXP Cross-site scripting vulnerability in products1h.php in ESMI PayPal Storefront allows remote attackers to inject arbitrary web script or HTML via the… Patch early 5.0 medium 2.6% 2005-05-02
CVE-2006-2608 EXP artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute a… Patch early 5.1 medium 2.6% 2006-05-26
CVE-2014-7281 EXP Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hija… Patch early 6.8 medium 2.6% 2014-10-23
CVE-2014-4162 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote attackers to hijack the authentic… Patch early 6.8 medium 2.6% 2014-06-16
CVE-2009-4224 EXP Multiple PHP remote file inclusion vulnerabilities in SweetRice 0.5.4, 0.5.3, and earlier allow remote attackers to execute arbitrary PHP code via a U… Patch early 6.8 medium 2.6% 2009-12-07
CVE-2012-1900 EXP Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authentication… Patch early 6.8 medium 2.6% 2012-10-22
CVE-2000-0381 EXP The Gossamer Threads DBMan db.cgi CGI script allows remote attackers to view environmental variables and setup information by referencing a non-existi… Patch early 6.4 medium 2.6% 2000-05-05
CVE-2007-3327 EXP httpsv.exe in HTTP Server 1.6.2 allows remote attackers to obtain sensitive information (script source code) via a URI with a trailing %20 (encoded sp… Patch early 5.0 medium 2.6% 2007-06-21
CVE-1999-0915 EXP URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. Patch early 5.0 medium 2.6% 1999-10-28
CVE-2004-1551 EXP Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbitrary web s… Patch early 4.3 medium 2.6% 2004-12-31
CVE-2005-0842 EXP Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1… Patch early 4.3 medium 2.6% 2005-05-02
CVE-2017-12971 EXP Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the account paramete… Patch early 6.1 medium 2.6% 2017-08-23
CVE-2018-19041 EXP The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI. Patch early 6.1 medium 2.6% 2019-01-31
CVE-2022-47877 EXP A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in the Logs pa… Patch early 5.4 medium 2.6% 2023-05-02
← previous page 204 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt