peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,984 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

207,508 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2002-0431 EXP XTux allows remote attackers to cause a denial of service (CPU consumption) via random inputs in the initial connection. Patch early 5.0 medium 3.2% 2002-07-26
CVE-2004-2475 EXP Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the Abou… Patch early 4.3 medium 3.2% 2004-12-31
CVE-2007-4081 EXP Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 3.2% 2007-07-30
CVE-2013-6233 EXP Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Descri… Patch early 4.3 medium 3.2% 2014-03-09
CVE-2004-1878 EXP LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl pr… Patch early 5.0 medium 3.2% 2004-03-30
CVE-2002-1539 EXP Buffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service via long (1) DELE or (2) UIDL a… Patch early 5.0 medium 3.2% 2003-03-31
CVE-2010-0641 EXP Cross-site scripting (XSS) vulnerability in webline/html/admin/wcs/LoginPage.jhtml in Cisco Collaboration Server (CCS) 5 allows remote attackers to in… Patch early 4.3 medium 3.2% 2010-02-17
CVE-2018-18324 EXP CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter, or the admin/index.php modul… Patch early 6.1 medium 3.2% 2018-10-15
CVE-2002-1982 EXP Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine if a directory exists via a ..… Patch early 5.0 medium 3.2% 2002-12-31
CVE-2004-0349 EXP Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot dot) in the URL. Patch early 5.0 medium 3.2% 2004-11-23
CVE-2013-2107 EXP Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote attackers to hijack the authenti… Patch early 6.8 medium 3.2% 2014-05-23
CVE-2003-0760 EXP Blubster 2.5 allows remote attackers to cause a denial of service (crash) via a flood of connections to UDP port 701. Patch early 5.0 medium 3.2% 2003-09-17
CVE-2001-0646 EXP Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating a directory name of a specifi… Patch early 5.0 medium 3.2% 2001-09-20
CVE-2009-2443 EXP Siteframe 3.2.3, and other 3.2.x versions, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which call… Patch early 5.0 medium 3.2% 2009-07-13
CVE-2009-3597 EXP Digitaldesign CMS 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… Patch early 5.0 medium 3.2% 2009-10-08
CVE-2022-0377 EXP Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this process the user cro… Patch early 4.3 medium 3.2% 2022-02-28
CVE-2009-2160 EXP TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpinfo.php, which calls the phpinf… Patch early 5.0 medium 3.2% 2009-06-22
CVE-2007-3590 EXP Cross-site scripting (XSS) vulnerability in visitenkarte.php in b1gBB 2.24.0 allows remote attackers to inject arbitrary web script or HTML via the us… Patch early 4.3 medium 3.2% 2007-07-05
CVE-2005-2106 EXP Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or po… Patch early 5.0 medium 3.2% 2005-07-05
CVE-2012-4362 EXP hydra.exe in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance has a hardcoded password of L0CAlu53R for the global$agent account, which allows rem… Patch early 4.0 medium 3.2% 2012-08-20
CVE-2004-1731 EXP signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail address. Patch early 5.0 medium 3.2% 2004-08-20
CVE-2004-2505 EXP Macromedia ColdFusion MX before 6.1 does not restrict the size of error messages, which allows remote attackers to cause a denial of service (memory c… Patch early 5.0 medium 3.2% 2004-12-31
CVE-2001-0711 EXP Cisco IOS 11.x and 12.0 with ATM support allows attackers to cause a denial of service via the undocumented Interim Local Management Interface (ILMI)… Patch early 5.0 medium 3.2% 2001-08-31
CVE-2002-1907 EXP TelCondex SimpleWebServer 2.06.20817 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request. Patch early 5.0 medium 3.2% 2002-12-31
CVE-2006-1112 EXP Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which displays the installation pat… Patch early 5.0 medium 3.2% 2006-03-09
CVE-2007-0122 EXP Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary S… Patch early 6.5 medium 3.2% 2007-01-09
CVE-2005-0340 EXP Integer signedness error in Apple File Service (AFP Server) allows remote attackers to cause a denial of service (application crash) via a negative UA… Patch early 5.0 medium 3.2% 2005-05-02
CVE-2007-0489 EXP PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier allows remote attackers to exec… Patch early 6.8 medium 3.2% 2007-01-25
CVE-2007-1524 EXP Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files via a .. (d… Patch early 5.0 medium 3.2% 2007-03-20
CVE-2009-2166 EXP Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full… Patch early 5.0 medium 3.2% 2009-06-22
← previous page 230 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt