peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,429 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

170,853 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-4698 EXP Cross-site scripting (XSS) vulnerability in TellMe 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the 91) q_IP (IP… Patch early 4.3 medium 2% 2005-12-31
CVE-2005-2468 EXP Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorre… Patch early 6.4 medium 2% 2005-12-31
CVE-2002-1495 EXP Cross-site scripting (XSS) vulnerability in JAWmail 1.0-rc1 allows remote attackers to insert arbitrary script or HTML via (1) attached file names in… Patch early 4.3 medium 2% 2003-04-02
CVE-2007-0110 EXP Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell Access Manager Identity Server before 3.0.0-1013 allows remote attackers to inject… Patch early 6.8 medium 2% 2007-01-09
CVE-2005-3849 EXP Cross-site scripting (XSS) vulnerability in the Search module in PmWiki up to 2.0.12 allows remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 2% 2005-11-27
CVE-2006-1384 EXP Cross-site scripting (XSS) vulnerability in apwc_win_main.jsp in the web console in IBM Tivoli Business Systems Manager (TBSM) before 3.1.0.1 allows r… Patch early 4.3 medium 2% 2006-03-24
CVE-2004-2245 EXP Cross-site scripting (XSS) vulnerability in Goollery 0.03 allows remote attackers to inject arbitrary HTML or web script via the (1) page parameter to… Patch early 4.3 medium 2% 2004-12-31
CVE-2008-6524 EXP resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid par… Patch early 6.5 medium 2% 2009-03-25
CVE-2005-4060 EXP Cross-site scripting (XSS) vulnerability in search.asp in rwAuction Pro 4.0 and 5.0 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 2% 2005-12-07
CVE-2006-2187 EXP Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and earlier allow remote attackers to inject arbitrary web script or HTML v… Patch early 6.8 medium 2% 2006-05-04
CVE-2006-5761 EXP Cross-site scripting (XSS) vulnerability in index.php in Rhadrix If-CMS 1.01 and 2.07 allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 2% 2006-11-06
CVE-2005-2064 EXP Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) email paramet… Patch early 5.0 medium 2% 2005-06-29
CVE-2008-6251 EXP PHP remote file inclusion vulnerability in includes/init.php in phpFan 3.3.4 allows remote attackers to execute arbitrary PHP code via a URL in the in… Patch early 6.8 medium 2% 2009-02-24
CVE-2008-6635 EXP PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when register_globals is enabled, all… Patch early 6.8 medium 2% 2009-04-07
CVE-2007-6001 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in Bandersnatch 0.4 allow remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 2% 2007-11-15
CVE-2008-5742 EXP Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phi… Patch early 4.0 medium 2% 2008-12-26
CVE-2011-2745 EXP upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of upload… Patch early 6.5 medium 2% 2011-07-27
CVE-2010-2456 EXP Multiple directory traversal vulnerabilities in index.php in Linker IMG 1.0 and earlier allow remote attackers to read and execute arbitrary local fil… Patch early 6.8 medium 2% 2010-06-25
CVE-2008-3385 EXP Directory traversal vulnerability in include/head_chat.inc.php in php Help Agent 1.0 and 1.1 Full allows remote attackers to include and execute arbit… Patch early 6.8 medium 2% 2008-07-30
CVE-2005-4491 EXP Multiple cross-site scripting (XSS) vulnerabilities in Sitekit CMS 6.6 and earlier allow remote attackers to inject arbitrary web script or HTML via t… Patch early 4.3 medium 2% 2005-12-22
CVE-2005-4307 EXP Cross-site scripting (XSS) vulnerability in ScareCrow 2.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum pa… Patch early 4.3 medium 2% 2005-12-17
CVE-2006-1135 EXP Multiple cross-site scripting (XSS) vulnerabilities in sBlog 0.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword p… Patch early 4.3 medium 2% 2006-03-10
CVE-2006-1349 EXP Multiple cross-site scripting (XSS) vulnerabilities in Musicbox 2.3 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) i… Patch early 4.3 medium 2% 2006-03-22
CVE-2008-3315 EXP Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the (1) quer… Patch early 4.3 medium 2% 2008-07-25
CVE-2009-4795 EXP Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbit… Patch early 6.8 medium 2% 2010-04-22
CVE-2006-7117 EXP Multiple directory traversal vulnerabilities in Kubix 0.7 and earlier allow remote attackers to (1) include and execute arbitrary local files via ".."… Patch early 6.8 medium 2% 2007-03-06
CVE-2017-2528 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" co… Patch early 6.1 medium 2% 2017-05-22
CVE-2002-0838 EXP Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (5) kghostview in kdegraphics 2… Patch early 4.6 medium 2% 2002-10-10
CVE-2012-6658 EXP Multiple cross-site scripting (XSS) vulnerabilities in SpiceWorks 5.3.75941 allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 4.3 medium 2% 2014-09-17
CVE-2006-1133 EXP Multiple cross-site scripting (XSS) vulnerabilities in vbzoom 1.11 allow remote attackers to inject arbitrary web script or HTML via the UserID parame… Patch early 4.3 medium 2% 2006-03-10
← previous page 242 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt