peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,999 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

170,624 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-1495 EXP Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a da… Patch early 5.0 medium 2.3% 2009-05-01
CVE-2015-5534 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall before 1.8 allow remote attackers to hijack the authentication of administrators… Patch early 6.8 medium 2.3% 2015-11-02
CVE-2018-13134 EXP TP-Link Archer C1200 1.13 Build 2018/01/24 rel.52299 EU devices have XSS via the PATH_INFO to the /webpages/data URI. Patch early 6.1 medium 2.3% 2018-07-04
CVE-2018-7203 EXP Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the fr… Patch early 6.1 medium 2.3% 2018-03-30
CVE-2012-3819 EXP Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and other products, allows remote… Patch early 5.0 medium 2.3% 2012-10-04
CVE-2011-2743 EXP Multiple cross-site scripting (XSS) vulnerabilities in Chyrp 2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the act… Patch early 4.3 medium 2.3% 2011-07-19
CVE-2017-10033 EXP Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Support Tools). Supported versions that are affected… Patch early 4.0 medium 2.3% 2017-10-19
CVE-2006-6732 EXP PHP remote file inclusion vulnerability in archive.php in cwmVote 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the abs param… Patch early 6.8 medium 2.3% 2006-12-26
CVE-2008-6849 EXP Unrestricted file upload vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to execute arbitrary PHP code by uploading a file wit… Patch early 6.8 medium 2.3% 2009-07-07
CVE-2008-0351 EXP admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter an… Patch early 5.0 medium 2.3% 2008-01-18
CVE-2014-3216 EXP GOM Media Player 2.2.57.5189 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg file. Patch early 4.3 medium 2.3% 2014-06-10
CVE-2005-4238 EXP Cross-site scripting (XSS) vulnerability in view_filters_page.php in Mantis 1.0.0rc3 and earlier allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 2.3% 2005-12-14
CVE-2012-1027 EXP Cross-site scripting (XSS) vulnerability in account-closed.tcl in ]project-open[ (aka ]po[) 3.4.x, 3.5.0.1-2, and possibly other versions allows remot… Patch early 4.3 medium 2.3% 2012-02-08
CVE-2014-4699 EXP The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a… Patch early 6.9 medium 2.3% 2014-07-09
CVE-2018-17310 EXP On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNam… Patch early 6.1 medium 2.3% 2018-09-26
CVE-2018-17313 EXP On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn p… Patch early 6.1 medium 2.3% 2018-09-26
CVE-2007-1895 EXP PHP remote file inclusion vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier, when used with PHP 5, allows remote attackers to execut… Patch early 6.8 medium 2.3% 2007-04-09
CVE-2007-2049 EXP Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (com_calendar) 1.5.5 for Mambo allow remote attackers to execute arbitrary P… Patch early 6.8 medium 2.3% 2007-04-16
CVE-2006-0936 EXP Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a form… Patch early 6.5 medium 2.3% 2006-02-28
CVE-2007-6513 EXP HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via… Patch early 4.3 medium 2.3% 2007-12-21
CVE-2018-17587 EXP AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. Patch early 6.1 medium 2.3% 2018-10-02
CVE-2018-17588 EXP AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. Patch early 6.1 medium 2.3% 2018-10-02
CVE-2018-18776 EXP Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the adm… Patch early 6.1 medium 2.3% 2018-11-01
CVE-2017-2509 EXP An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" component. It allows attackers to… Patch early 5.5 medium 2.3% 2017-05-22
CVE-2013-7196 EXP static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment on a private… Patch early 5.5 medium 2.3% 2014-04-18
CVE-2007-3936 EXP Directory traversal vulnerability in admin/filebrowser.asp in A-shop 0.70 and earlier, and possibly 0.71, allows remote attackers to delete arbitrary… Patch early 6.4 medium 2.3% 2007-07-21
CVE-2007-5112 EXP Cross-site scripting (XSS) vulnerability in session.cgi (aka the login page) in Google Urchin 5 5.7.03 and earlier allows remote attackers to inject a… Patch early 4.3 medium 2.3% 2007-09-26
CVE-2010-1095 EXP Cross-site scripting (XSS) vulnerability in login_reset_password_page.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 and earlier allows remote… Patch early 4.3 medium 2.3% 2010-03-24
CVE-2012-5386 EXP Directory traversal vulnerability in index.php in phpPaleo 4.8b180 allows remote attackers to include and execute arbitrary local files via a .. (dot… Patch early 6.8 medium 2.3% 2012-10-11
CVE-2018-1204 EXP Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected… Patch early 6.7 medium 2.3% 2018-03-26
← previous page 223 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt