peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,041 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

170,652 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-7190 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Openfiler 2.99.1 allow remote attackers to hijack the authentication of administrators f… Patch early 6.8 medium 2.3% 2014-09-30
CVE-2014-8953 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Php Scriptlerim Who's Who script allow remote attackers to hijack the authentication of… Patch early 6.8 medium 2.3% 2014-11-17
CVE-2011-5284 EXP Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothwall Express 3.1 and 3.0 SP3 an… Patch early 6.8 medium 2.3% 2014-12-31
CVE-2012-1978 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Simple PHP Agenda 2.2.8 and earlier allow remote attackers to hijack the authentication… Patch early 6.8 medium 2.3% 2015-05-21
CVE-2008-1783 EXP Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/DeleteUser.php… Patch early 6.4 medium 2.3% 2008-04-15
CVE-2000-1069 EXP pollit.cgi in Poll It 2.01 and earlier allows remote attackers to access administrative functions without knowing the real password by specifying the… Patch early 6.4 medium 2.3% 2000-12-11
CVE-2005-2157 EXP PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path paramete… Patch early 5.0 medium 2.3% 2005-07-06
CVE-2008-1760 EXP Multiple PHP remote file inclusion vulnerabilities in Blogator-script before 1.01 allow remote attackers to execute arbitrary PHP code via a URL in th… Patch early 6.8 medium 2.3% 2008-04-12
CVE-2023-0943 EXP A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0. This issue affects the function… Patch early 4.7 medium 2.3% 2023-02-21
CVE-2008-4454 EXP Directory traversal vulnerability in EKINdesigns MySQL Quick Admin 1.5.5 allows remote attackers to read and execute arbitrary files via a .. (dot dot… Patch early 6.8 medium 2.3% 2008-10-06
CVE-2003-1410 EXP PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary… Patch early 6.8 medium 2.3% 2003-12-31
CVE-2014-10001 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication… Patch early 6.8 medium 2.3% 2015-01-13
CVE-2017-7472 EXP The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumption) via a series of KEY_REQKEY_… Patch early 5.5 medium 2.3% 2017-05-11
CVE-2007-6653 EXP Directory traversal vulnerability in download.php in Mihalism Multi Host 2.0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in t… Patch early 5.0 medium 2.3% 2008-01-04
CVE-2009-2733 EXP Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the… Patch early 4.3 medium 2.3% 2009-10-16
CVE-2019-9647 EXP Gila CMS 1.9.1 has XSS. Patch early 6.1 medium 2.3% 2019-06-05
CVE-2019-10685 EXP A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0. Patch early 6.1 medium 2.3% 2019-05-24
CVE-2018-15596 EXP An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://local… Patch early 6.1 medium 2.3% 2018-08-28
CVE-2007-5312 EXP Cross-site scripting (XSS) vulnerability in TorrentTrader Classic 1.07 allows remote attackers to inject arbitrary web script or HTML via the (1) colo… Patch early 4.3 medium 2.3% 2007-10-09
CVE-2018-11404 EXP DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter. Patch early 6.1 medium 2.3% 2018-05-24
CVE-2009-2587 EXP Multiple cross-site scripting (XSS) vulnerabilities in DragDropCart allow remote attackers to inject arbitrary web script or HTML via the (1) sid para… Patch early 4.3 medium 2.3% 2009-07-24
CVE-2009-4548 EXP Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the catego… Patch early 4.3 medium 2.3% 2010-01-04
CVE-2009-0463 EXP PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary PHP code via a URL in… Patch early 6.8 medium 2.3% 2009-02-10
CVE-2006-6877 EXP Directory traversal vulnerability in index.php in Matteo Lucarelli 3editor CMS 0.42 and earlier, when register_globals is enabled, allows remote attac… Patch early 6.8 medium 2.3% 2006-12-31
CVE-2000-1180 EXP Buffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a long command line argument. Patch early 4.6 medium 2.3% 2001-01-09
CVE-2010-4895 EXP Cross-site scripting (XSS) vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 2.3% 2011-10-08
CVE-2015-7889 EXP The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the com.samsung.android.ema… Patch early 5.5 medium 2.3% 2017-12-28
CVE-2006-3608 EXP The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files t… Patch early 4.6 medium 2.3% 2006-07-18
CVE-2008-0259 EXP Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to read arbitrary files via a .. (… Patch early 6.4 medium 2.3% 2008-01-15
CVE-2012-1260 EXP Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possib… Patch early 6.1 medium 2.3% 2020-01-09
← previous page 228 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt