peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,893 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

207,492 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-3989 EXP PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers to execute arbitrary PHP code v… Patch early 5.1 medium 3.4% 2006-08-05
CVE-2006-4053 EXP PHP remote file inclusion vulnerability in templates/header.php in ME Download System 1.3 allows remote attackers to execute arbitrary PHP code via a… Patch early 5.1 medium 3.4% 2006-08-10
CVE-2006-4242 EXP PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote attackers to execute arbitrary… Patch early 5.1 medium 3.4% 2006-08-21
CVE-2006-4664 EXP PHP remote file inclusion vulnerability in includes/functions_portal.php in Premod Shadow 2.7.1 and earlier allows remote attackers to execute arbitra… Patch early 5.1 medium 3.4% 2006-09-09
CVE-2019-6208 EXP A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A mal… Patch early 5.5 medium 3.4% 2019-03-05
CVE-2006-3929 EXP Cross-site scripting (XSS) vulnerability in the Forms/rpSysAdmin script on the Zyxel Prestige 660H-61 ADSL Router running firmware 3.40(PT.0)b32 allow… Patch early 4.3 medium 3.4% 2006-07-31
CVE-2018-5407 EXP Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing att… Patch early 4.7 medium 3.4% 2018-11-15
CVE-2017-15878 EXP A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us featur… Patch early 6.1 medium 3.4% 2017-10-24
CVE-2001-0250 EXP The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server ro… Patch early 5.0 medium 3.4% 2001-06-02
CVE-2006-6696 EXP Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with… Patch early 6.9 medium 3.4% 2006-12-22
CVE-2000-0708 EXP Buffer overflow in Pragma Systems TelnetServer 2000 version 4.0 allows remote attackers to cause a denial of service via a long series of null charact… Patch early 5.0 medium 3.4% 2000-10-20
CVE-2006-6899 EXP hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a… Patch early 5.4 medium 3.4% 2006-12-31
CVE-1999-1081 EXP Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files. Patch early 5.0 medium 3.4% 2002-01-15
CVE-2022-4953 EXP The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be use… Patch early 6.1 medium 3.4% 2023-08-14
CVE-2002-2149 EXP Buffer overflow in Lucent Access Point 300, 600, and 1500 Service Routers allows remote attackers to cause a denial of service (reboot) via a long HTT… Patch early 5.0 medium 3.4% 2002-12-31
CVE-2003-1173 EXP Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking all of the se… Patch early 5.0 medium 3.4% 2003-12-31
CVE-2004-1194 EXP Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname… Patch early 5.0 medium 3.4% 2005-01-10
CVE-2004-2129 EXP SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow… Patch early 5.0 medium 3.4% 2004-12-31
CVE-2005-2892 EXP Directory traversal vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to read arbitrary files via… Patch early 5.0 medium 3.4% 2005-09-14
CVE-2003-1292 EXP PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbitrary remote files via a URL in… Patch early 5.0 medium 3.4% 2003-12-31
CVE-2006-6924 EXP bitweaver 1.3.1 and earlier allows remote attackers to obtain sensitive information via a sort_mode=-98 query string to (1) blogs/list_blogs.php, (2)… Patch early 5.0 medium 3.4% 2007-01-13
CVE-2012-1059 EXP Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce Online Merchant 3.0.2 allows re… Patch early 4.3 medium 3.4% 2012-02-14
CVE-2007-6630 EXP The Url_init function in utils/url.c in Netembryo 0.0.4, when used by LScube Feng, allows remote attackers to cause a denial of service (NULL derefere… Patch early 5.0 medium 3.4% 2008-01-04
CVE-2002-2071 EXP Compaq Tru64 4.0 d allows remote attackers to cause a denial of service in (1) telnet, (2) FTP, (3) ypbind, (4) rpc.lockd, (5) snmp, (6) ttdbserverd,… Patch early 5.0 medium 3.4% 2002-12-31
CVE-2006-0175 EXP Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 3.4% 2006-01-11
CVE-2000-0394 EXP NetProwler 3.0 allows remote attackers to cause a denial of service by sending malformed IP packets that trigger NetProwler's Man-in-the-Middle signat… Patch early 5.0 medium 3.4% 2000-05-18
CVE-2003-0706 EXP Unknown vulnerability in mah-jong 1.5.6 and earlier allows remote attackers to cause a denial of service (tight loop). Patch early 5.0 medium 3.4% 2003-09-17
CVE-2014-2647 EXP Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communications Broker) before 11.14 allows… Patch early 4.3 medium 3.4% 2014-10-19
CVE-2011-4090 EXP Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation. Patch early 6.1 medium 3.4% 2019-11-26
CVE-2017-15965 EXP The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action. Patch early 9.8 critical 3.4% 2017-10-29
← previous page 218 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt