peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,011 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

170,625 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-2683 EXP PHP remote file inclusion vulnerability in 404.php in open-medium.CMS 0.25 allows remote attackers to execute arbitrary PHP code via a URL in the REDS… Patch early 6.4 medium 2.3% 2006-05-31
CVE-2020-23835 EXP A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0 allows remo… Patch early 6.4 medium 2.3% 2020-09-01
CVE-2006-3568 EXP Multiple cross-site scripting (XSS) vulnerabilities in guestbook.php in Fantastic Guestbook 2.0.1, and possibly earlier versions, allow remote attacke… Patch early 4.3 medium 2.3% 2006-07-13
CVE-2009-3216 EXP Multiple directory traversal vulnerabilities in iWiccle 1.01, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a… Patch early 4.3 medium 2.3% 2009-09-16
CVE-2014-3443 EXP JetMPAd.ax in JetAudio 8.1.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg file. Patch early 4.3 medium 2.3% 2014-05-14
CVE-2005-1087 EXP CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and po… Patch early 6.4 medium 2.3% 2005-04-07
CVE-2011-5147 EXP Static code injection vulnerability in ajax_save_name.php in the Ajax File Manager module in the tinymce plugin in FreeWebshop 2.2.9 R2 and earlier al… Patch early 5.0 medium 2.3% 2012-08-31
CVE-2005-2461 EXP Multiple SQL injection vulnerabilities in the calendar feature in Kayako liveResponse 2.x allow remote attackers to execute arbitrary SQL commands via… Patch early 6.4 medium 2.3% 2005-12-31
CVE-2008-6090 EXP Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a .. (dot d… Patch early 4.3 medium 2.3% 2009-02-06
CVE-2008-6453 EXP Directory traversal vulnerability in section.php in 6rbScript 3.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files… Patch early 4.3 medium 2.3% 2009-03-13
CVE-2008-0812 EXP Directory traversal vulnerability in DMS/index.php in BanPro DMS 1.0 allows remote attackers to include and execute arbitrary files via a .. (dot dot)… Patch early 6.4 medium 2.3% 2008-02-19
CVE-2007-4457 EXP Directory traversal vulnerability in forumreply.php in Dalai Forum 1.1 allows remote attackers to include and execute arbitrary local files via a .. (… Patch early 6.4 medium 2.3% 2007-08-21
CVE-2013-1414 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow… Patch early 5.1 medium 2.3% 2013-07-08
CVE-2007-2368 EXP picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter. Patch early 5.0 medium 2.3% 2007-04-30
CVE-2009-2024 EXP Vlad Titarenko ASP VT Auth 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to down… Patch early 5.0 medium 2.3% 2009-06-09
CVE-2009-3756 EXP phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in adv… Patch early 5.0 medium 2.3% 2009-10-22
CVE-2009-0249 EXP Katy Whitton RankEm stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a data… Patch early 5.0 medium 2.3% 2009-01-22
CVE-2009-0336 EXP Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the d… Patch early 5.0 medium 2.3% 2009-01-29
CVE-2009-1322 EXP ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a… Patch early 5.0 medium 2.3% 2009-04-17
CVE-2009-1550 EXP Zakkis Technology ABC Advertise 1.0 does not properly restrict access to admin.inc.php, which allows remote attackers to obtain the administrator logi… Patch early 5.0 medium 2.3% 2009-05-06
CVE-2009-1941 EXP PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which allows remote attackers to downl… Patch early 5.0 medium 2.3% 2009-06-05
CVE-2003-1411 EXP PHP remote file inclusion vulnerability in emailreader_execute_on_each_page.inc.php in Cedric Email Reader 0.4 allows remote attackers to execute arbi… Patch early 6.8 medium 2.3% 2003-12-31
CVE-2015-3624 EXP Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content Management System (CMS) before… Patch early 5.8 medium 2.3% 2015-06-09
CVE-2012-5851 EXP html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts… Patch early 4.3 medium 2.3% 2012-11-15
CVE-2009-3809 EXP Acoustica MP3 Audio Mixer 1.0 and possibly 2.471 allows remote attackers to cause a denial of service (crash) via a long string in a .sgp playlist fil… Patch early 4.3 medium 2.3% 2009-10-27
CVE-2010-2654 EXP Multiple cross-site scripting (XSS) vulnerabilities on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possib… Patch early 4.3 medium 2.3% 2010-07-08
CVE-2009-0674 EXP images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows remote attackers to determine th… Patch early 6.0 medium 2.3% 2009-02-22
CVE-2014-3792 EXP Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005_retail allows remote attackers to hijack the authenti… Patch early 6.8 medium 2.3% 2014-05-20
CVE-2008-3100 EXP Cross-site scripting (XSS) vulnerability in lib/owl.lib.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgebase 0.95 and earlier allows re… Patch early 4.3 medium 2.3% 2008-07-29
CVE-2004-1656 EXP CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HT… Patch early 5.0 medium 2.3% 2004-09-01
← previous page 226 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt