peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,011 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

170,625 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-2029 EXP Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (… Patch early 6.4 medium 2.3% 2006-04-26
CVE-2014-4964 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to hijack the authentication of users… Patch early 6.8 medium 2.3% 2014-07-15
CVE-2006-4449 EXP Cross-site scripting (XSS) vulnerability in attachment.php in MyBulletinBoard (MyBB) 1.1.7 and possibly other versions allows remote attackers to inje… Patch early 5.1 medium 2.3% 2006-08-30
CVE-2007-6471 EXP Incomplete blacklist vulnerability in main.php in phPay 2.02.01 on Windows allows remote attackers to conduct directory traversal attacks and include… Patch early 5.8 medium 2.3% 2007-12-20
CVE-2016-4807 EXP Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (adm… Patch early 4.8 medium 2.3% 2017-01-11
CVE-2006-2001 EXP Cross-site scripting (XSS) vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the p par… Patch early 4.3 medium 2.3% 2006-04-25
CVE-2006-2755 EXP Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 2.3% 2006-06-02
CVE-2008-1555 EXP Directory traversal vulnerability in system/_b/contentFiles/gbincluder.php in BolinOS 4.6.1 allows remote attackers to include and execute arbitrary l… Patch early 6.8 medium 2.3% 2008-03-31
CVE-2008-3165 EXP Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to inclu… Patch early 6.8 medium 2.3% 2008-07-14
CVE-2008-3190 EXP Directory traversal vulnerability in list.php in 1Scripts CodeDB 1.1.1 allows remote attackers to include and execute arbitrary local files via a .. (… Patch early 6.8 medium 2.3% 2008-07-16
CVE-2010-1058 EXP Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote… Patch early 6.8 medium 2.3% 2010-03-23
CVE-2010-1268 EXP Directory traversal vulnerability in index.php in justVisual CMS 2.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execut… Patch early 6.8 medium 2.3% 2010-04-06
CVE-2010-1710 EXP Directory traversal vulnerability in login.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to include and execute arbitr… Patch early 6.8 medium 2.3% 2010-05-04
CVE-2008-0140 EXP Directory traversal vulnerability in error.php in Uebimiau Webmail 2.7.10 and 2.7.2 allows remote authenticated users to read arbitrary files via a ..… Patch early 6.4 medium 2.3% 2008-01-08
CVE-2018-17590 EXP AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. Patch early 6.1 medium 2.3% 2018-10-02
CVE-2018-17591 EXP AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. Patch early 6.1 medium 2.3% 2018-10-02
CVE-2018-17593 EXP AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. Patch early 6.1 medium 2.3% 2018-10-02
CVE-2004-2749 EXP Directory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other product lines, allows remote attac… Patch early 4.3 medium 2.3% 2004-12-31
CVE-2014-4939 EXP SQL injection vulnerability in the ENL Newsletter (enl-newsletter) plugin 1.0.1 for WordPress allows remote authenticated administrators to execute ar… Patch early 6.5 medium 2.3% 2014-07-11
CVE-2014-7153 EXP SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remot… Patch early 6.5 medium 2.3% 2014-09-22
CVE-2018-12705 EXP DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side). Patch early 6.1 medium 2.3% 2018-06-24
CVE-2021-43009 EXP A Cross Site Scripting (XSS) vulnerability exists in OpServices OpMon through 9.11 via the search parameter in the request URL. Patch early 6.1 medium 2.3% 2022-04-08
CVE-2006-2109 EXP Cross-site scripting (XSS) vulnerability in the parse_query_str function in include/print.php in JSBoard 2.0.10 and 2.0.11, and possibly other version… Patch early 6.8 medium 2.3% 2006-05-02
CVE-2006-7072 EXP Cross-site scripting (XSS) vulnerability in GeoClassifieds Enterprise 2.0.5.2 and earlier allows remote attackers to inject arbitrary web script and H… Patch early 4.3 medium 2.3% 2007-03-02
CVE-2007-5676 EXP PHP remote file inclusion vulnerability in modules/Forums/favorites.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execute arbitrary PHP… Patch early 6.8 medium 2.3% 2007-10-24
CVE-2010-2655 EXP Directory traversal vulnerability in private/file_management.php on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48… Patch early 4.0 medium 2.3% 2010-07-08
CVE-2006-5834 EXP Directory traversal vulnerability in general.php in OpenSolution Quick.Cms.Lite 0.3 allows remote attackers to include arbitrary files via a .. (dot d… Patch early 5.0 medium 2.3% 2006-11-10
CVE-2012-4234 EXP Cross-site scripting (XSS) vulnerability in the group moderation screen in the control center (control.php) in Phorum before 5.2.19 allows remote atta… Patch early 4.3 medium 2.3% 2014-09-04
CVE-2006-3184 EXP Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to execute arbitrary ASP code via… Patch early 4.0 medium 2.3% 2006-06-23
CVE-2010-5281 EXP Directory traversal vulnerability in ibrowser.php in the CMScout 2.09 IBrowser TinyMCE Plugin 1.4.1, when magic_quotes_gpc is disabled, allows remote… Patch early 6.8 medium 2.3% 2012-11-26
← previous page 225 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt