peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,899 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

170,616 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-9146 EXP Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web script or HTML via the (1) view… Patch early 4.3 medium 2.5% 2015-04-14
CVE-2019-6965 EXP An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter. Patch early 6.1 medium 2.5% 2019-06-18
CVE-2007-5816 EXP dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to obtain sensitive author credentials by making a request with an editautho… Patch early 5.0 medium 2.5% 2007-11-05
CVE-2011-0772 EXP Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow remote attackers to inject arbitr… Patch early 4.3 medium 2.5% 2011-02-04
CVE-2009-2081 EXP Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read ar… Patch early 4.3 medium 2.5% 2009-06-16
CVE-2000-0669 EXP Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data. Patch early 5.0 medium 2.5% 2000-07-11
CVE-2003-1344 EXP Trend Micro Virus Control System (TVCS) Log Collector allows remote attackers to obtain usernames, encrypted passwords, and other sensitive informatio… Patch early 5.0 medium 2.5% 2003-12-31
CVE-2006-1196 EXP Multiple cross-site scripting (XSS) vulnerabilities in QwikiWiki 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) from an… Patch early 4.3 medium 2.5% 2006-03-13
CVE-2006-1233 EXP Multiple cross-site scripting (XSS) vulnerabilities in WMNews allow remote attackers to inject arbitrary web script or HTML via the (1) ArtCat paramet… Patch early 4.3 medium 2.5% 2006-03-14
CVE-2006-1430 EXP Multiple cross-site scripting (XSS) vulnerabilities in CONTROLzx HMS (formerly DRZES) 3.3.4 and earlier allow remote attackers to inject arbitrary web… Patch early 4.3 medium 2.5% 2006-03-28
CVE-2008-0403 EXP The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, which allows remote attackers to r… Patch early 5.5 medium 2.5% 2008-01-23
CVE-2001-0270 EXP Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet w… Patch early 5.0 medium 2.5% 2001-05-03
CVE-2001-1525 EXP Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.dat and poss… Patch early 5.0 medium 2.5% 2001-12-31
CVE-2018-6845 EXP PHP Scripts Mall Multi Language Olx Clone Script 2.0.6 has XSS via the Leave Comment field. Patch early 6.1 medium 2.5% 2018-02-12
CVE-2009-0700 EXP Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sensitive Customer or Order data v… Patch early 4.0 medium 2.5% 2009-02-23
CVE-2008-6382 EXP ASP Portal 3.2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the datab… Patch early 5.0 medium 2.5% 2009-03-02
CVE-2009-0827 EXP PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing… Patch early 5.0 medium 2.5% 2009-03-05
CVE-2013-6883 EXP Cross-site request forgery (CSRF) vulnerability in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to hijack t… Patch early 6.8 medium 2.5% 2013-12-17
CVE-2006-2771 EXP admin/radera/tabort.asp in Hogstorps hogstorp guestbook 2.0 does not verify user credentials, which allows remote attackers to delete arbitrary posts… Patch early 6.4 medium 2.5% 2006-06-02
CVE-2005-4302 EXP Directory traversal vulnerability in index.php in ezDatabase 2.1.2 and earlier allows remote attackers to include arbitrary local files via ".." sequ… Patch early 5.0 medium 2.5% 2005-12-17
CVE-2009-0866 EXP pHNews Alpha 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database… Patch early 5.0 medium 2.5% 2009-03-10
CVE-2006-6724 EXP BolinTech Dream FTP Server 1.02 allows remote authenticated users, including anonymous users, to cause a denial of service (application crash) via a c… Patch early 4.0 medium 2.5% 2006-12-26
CVE-2017-9129 EXP The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (larg… Patch early 5.5 medium 2.5% 2017-06-21
CVE-2005-1118 EXP Cross-site scripting (XSS) vulnerability in IISWebAgentIF.dll in the RSA Authentication Agent for Web 5.2 allows remote attackers to inject arbitrary… Patch early 4.3 medium 2.5% 2005-04-14
CVE-2012-5917 EXP SnackAmp 3.1.3 allows remote attackers to cause a denial of service (application crash) via a long string in an aiff file. Patch early 4.3 medium 2.5% 2012-11-17
CVE-2017-17649 EXP Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter. Patch early 6.1 medium 2.5% 2017-12-18
CVE-2021-3186 EXP A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_multi allows remote attackers t… Patch early 5.4 medium 2.5% 2021-01-26
CVE-2003-1409 EXP TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter to (1) in.php or (2) out.php, w… Patch early 5.0 medium 2.5% 2003-12-31
CVE-2014-5101 EXP Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) TPL_name,… Patch early 4.3 medium 2.5% 2014-07-25
CVE-2004-1754 EXP The DNS proxy (DNSd) for multiple Symantec Gateway Security products allows remote attackers to poison the DNS cache via a malicious DNS server query… Patch early 5.0 medium 2.5% 2004-06-15
← previous page 212 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt