peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,941 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

170,623 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-1912 EXP Cross-site scripting (XSS) vulnerability in preferences.php in PHP Address Book 7.0 and earlier allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 2.4% 2012-09-09
CVE-2010-3437 EXP Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users t… Patch early 6.6 medium 2.4% 2010-10-04
CVE-2007-3523 EXP Multiple directory traversal vulnerabilities in Module/Galerie.php in XCMS 1.1 allow remote attackers to include and execute arbitrary local files via… Patch early 6.4 medium 2.4% 2007-07-03
CVE-2007-3772 EXP Directory traversal vulnerability in news/show.php in PsNews 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot do… Patch early 6.4 medium 2.4% 2007-07-15
CVE-2017-6982 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. The issue involves the "Notifications" component. It allows attacker… Patch early 5.5 medium 2.4% 2017-05-22
CVE-2010-0983 EXP PHP remote file inclusion vulnerability in include/mail.inc.php in Rezervi 3.0.2 and earlier, when register_globals is enabled, allows remote attacker… Patch early 6.8 medium 2.4% 2010-03-16
CVE-2008-5938 EXP PHP remote file inclusion vulnerability in assets/snippets/reflect/snippet.reflect.php in MODx CMS 0.9.6.2 and earlier, when magic_quotes_gpc is disab… Patch early 6.8 medium 2.4% 2009-01-22
CVE-2022-29727 EXP Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter. Patch early 5.4 medium 2.4% 2022-05-11
CVE-2006-6941 EXP index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to obtain sensitive information via an invalid action parameter in an info operatio… Patch early 5.0 medium 2.4% 2007-01-19
CVE-2009-2181 EXP Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attackers to inject arbitrary web s… Patch early 4.3 medium 2.4% 2009-06-23
CVE-2012-4237 EXP Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to execute arbit… Patch early 6.8 medium 2.4% 2012-08-20
CVE-2007-3613 EXP Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attackers to inject arbitrary web scri… Patch early 4.3 medium 2.4% 2007-07-06
CVE-2005-4880 EXP Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain I… Patch early 5.0 medium 2.4% 2009-03-31
CVE-2012-2588 EXP Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 2.4% 2014-09-19
CVE-2008-3770 EXP Multiple directory traversal vulnerabilities in Freeway 1.4.1.171, when register_globals is enabled, allow remote attackers to include and execute arb… Patch early 6.8 medium 2.4% 2008-08-22
CVE-2006-1568 EXP Multiple cross-site scripting (XSS) vulnerabilities in register.php in RedCMS 0.1 allow remote attackers to inject arbitrary web script or HTML via th… Patch early 5.1 medium 2.4% 2006-04-01
CVE-2009-2116 EXP Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to list directory contents via a .… Patch early 4.0 medium 2.4% 2009-06-18
CVE-2008-2352 EXP Directory traversal vulnerability in index.php in Smeego 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitr… Patch early 6.8 medium 2.4% 2008-05-20
CVE-2008-5570 EXP Directory traversal vulnerability in index.php in PHP Multiple Newsletters 2.7, when magic_quotes_gpc is disabled, allows remote attackers to include… Patch early 6.8 medium 2.4% 2008-12-15
CVE-2008-5604 EXP Directory traversal vulnerability in index.php in My Simple Forum 3.0 and 4.1, when magic_quotes_gpc is disabled, allows remote attackers to include a… Patch early 6.8 medium 2.4% 2008-12-16
CVE-2007-0301 EXP PHP remote file inclusion vulnerability in _admin/admin_menu.php in FdWeB Espace Membre 2.1 and earlier allows remote attackers to execute arbitrary P… Patch early 6.8 medium 2.4% 2007-01-18
CVE-2012-4262 EXP Multiple cross-site scripting (XSS) vulnerabilities in myCare2x allow remote attackers to inject arbitrary web script or HTML via the (1) name_last, (… Patch early 4.3 medium 2.4% 2012-08-13
CVE-2007-4115 EXP Multiple cross-site scripting (XSS) vulnerabilities in IT!CMS (itcms) 0.2 allow remote attackers to inject arbitrary web script or HTML via the wndtit… Patch early 4.3 medium 2.4% 2007-07-31
CVE-2010-1497 EXP Cross-site scripting (XSS) vulnerability in download_proc.php in dl_stats before 2.0 allows remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 2.4% 2010-04-23
CVE-2006-5830 EXP Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to inject arbitrary… Patch early 6.8 medium 2.4% 2006-11-10
CVE-2025-54589 EXP Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results usin… Patch early 6.3 medium 2.4% 2025-07-31
CVE-2002-2134 EXP haut.php in PEEL 1.0b allows remote attackers to execute arbitrary PHP code by modifying the dirroot parameter to reference a URL on a remote web serv… Patch early 5.0 medium 2.4% 2002-12-31
CVE-2002-2169 EXP Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activ… Patch early 5.0 medium 2.4% 2002-12-31
CVE-2007-5314 EXP PHP remote file inclusion vulnerability in system/funcs/xkurl.php in xKiosk WEB 3.0.1i, when register_globals is enabled, allows remote attackers to e… Patch early 6.8 medium 2.4% 2007-10-09
CVE-2010-1216 EXP PHP remote file inclusion vulnerability in templates/template.php in notsoPureEdit 1.4.1 and earlier, when register_globals is enabled, allows remote… Patch early 6.8 medium 2.4% 2010-03-30
← previous page 219 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt