peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,415 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

170,849 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-6979 EXP An issue was discovered in the User IP History Logs (aka IP_History_Logs) plugin 1.0.2 for MyBB. There is XSS via the admin/modules/tools/ip_history_l… Patch early 6.1 medium 2.1% 2019-01-28
CVE-2009-4512 EXP Directory traversal vulnerability in index.php in Oscailt 3.3, when Use Friendly URL's is disabled, allows remote attackers to include and execute arb… Patch early 5.1 medium 2.1% 2009-12-31
CVE-2006-6523 EXP Cross-site scripting (XSS) vulnerability in mail/manage.html in BoxTrapper in cPanel 11 allows remote attackers to inject arbitrary web script or HTML… Patch early 6.8 medium 2.1% 2006-12-14
CVE-2017-16994 EXP The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to obt… Patch early 5.5 medium 2.1% 2017-11-27
CVE-2009-1767 EXP admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary… Patch early 5.0 medium 2.1% 2009-05-22
CVE-2006-4479 EXP Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 2.1% 2006-08-31
CVE-2006-1425 EXP Cross-site scripting (XSS) vulnerability in track.php in phpmyfamily 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the name… Patch early 4.3 medium 2.1% 2006-03-28
CVE-2005-4053 EXP Cross-site scripting (XSS) vulnerability in coWiki 0.3.4 allows remote attackers to inject arbitrary web script or HTML via the q parameter, as demons… Patch early 4.3 medium 2.1% 2005-12-07
CVE-2008-1229 EXP Cross-site scripting (XSS) vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 2.1% 2008-03-10
CVE-2003-1350 EXP List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl fi… Patch early 4.3 medium 2.1% 2003-12-31
CVE-2012-5702 EXP Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (… Patch early 4.3 medium 2.1% 2014-10-21
CVE-2011-5149 EXP Multiple cross-site scripting (XSS) vulnerabilities in SpamTitan 5.08 and earlier allow remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 2.1% 2012-08-31
CVE-2004-2030 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject arbitrary… Patch early 4.3 medium 2.1% 2004-05-22
CVE-2017-17737 EXP The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diagnostics.html or /storage_info.… Patch early 6.1 medium 2.1% 2017-12-18
CVE-2010-2025 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with fir… Patch early 6.8 medium 2.1% 2010-05-26
CVE-2006-5239 EXP Multiple cross-site scripting (XSS) vulnerabilities in eXpBlog 0.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1)… Patch early 4.3 medium 2.1% 2006-10-12
CVE-2018-10109 EXP Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the content section of a ne… Patch early 4.8 medium 2.1% 2018-04-16
CVE-2006-2210 EXP Cross-site scripting (XSS) vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to inject arbitrary web script or HTML via th… Patch early 5.8 medium 2.1% 2006-05-05
CVE-2003-1149 EXP Cross-site scripting (XSS) vulnerability in Symantec Norton Internet Security 2003 6.0.4.34 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 2.1% 2003-10-27
CVE-2006-2249 EXP Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject… Patch early 4.3 medium 2.1% 2006-05-09
CVE-2006-2425 EXP Multiple cross-site scripting (XSS) vulnerabilities in PRV.php in PhpRemoteView, possibly 2003-10-23 and earlier, allow remote attackers to inject arb… Patch early 4.3 medium 2.1% 2006-05-17
CVE-2006-4668 EXP Cross-site scripting (XSS) vulnerability in index.php in Rob Hensley AckerTodo 4.0 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 2.1% 2006-09-09
CVE-2012-6555 EXP Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 2.1% 2013-05-23
CVE-2007-4886 EXP Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbitrary PHP code via a (1) UNC sh… Patch early 6.8 medium 2.1% 2007-09-14
CVE-2007-5138 EXP PHP remote file inclusion vulnerability in forum/forum.php in lustig.cms BETA 2.5 allows remote attackers to execute arbitrary PHP code via a URL in t… Patch early 6.8 medium 2.1% 2007-09-28
CVE-2007-5139 EXP PHP remote file inclusion vulnerability in admin/include/header.php in chupix 0.2.3, when register_globals is enabled, allows remote attackers to exec… Patch early 6.8 medium 2.1% 2007-09-28
CVE-2007-5409 EXP PHP remote file inclusion vulnerability in admin/nuseo_admin_d.php in NuSEO PHP Enterprise 1.6 (NuSEO.PHP), when register_globals is enabled, allows r… Patch early 6.8 medium 2.1% 2007-10-12
CVE-2007-5627 EXP PHP remote file inclusion vulnerability in content/fnc-readmail3.php in SocketMail 2.2.8 allows remote attackers to execute arbitrary PHP code via a U… Patch early 6.8 medium 2.1% 2007-10-23
CVE-2007-5754 EXP PHP remote file inclusion vulnerability in urlinn_includes/config.php in phpFaber URLInn 2.0.5 allows remote attackers to execute arbitrary PHP code v… Patch early 6.8 medium 2.1% 2007-10-31
CVE-2007-5784 EXP PHP remote file inclusion vulnerability in index.php in CaupoShop Pro 2.x allows remote attackers to execute arbitrary PHP code via a URL in the actio… Patch early 6.8 medium 2.1% 2007-11-01
← previous page 239 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt