peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,429 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

170,853 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-5678 EXP Fretwell-Downing Informatics (FDI) OLIB7 WebView 2.5.1.1 allows remote authenticated users to obtain sensitive information from files via the infile p… Patch early 4.0 medium 2% 2008-12-19
CVE-2019-19493 EXP Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS. Patch early 5.4 medium 2% 2019-12-02
CVE-2009-1222 EXP Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, a… Patch early 5.1 medium 2% 2009-04-02
CVE-2009-1948 EXP Multiple directory traversal vulnerabilities in forum.php in Unclassified NewsBoard (UNB) 1.6.4, when register_globals is enabled and magic_quotes_gpc… Patch early 5.1 medium 2% 2009-06-05
CVE-2008-0648 EXP Multiple PHP remote file inclusion vulnerabilities in OpenSiteAdmin 0.9.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL… Patch early 6.8 medium 2% 2008-02-07
CVE-2007-2001 EXP Multiple direct static code injection vulnerabilities in admin/configurer2.php in Crea-Book 1.0 and earlier allow remote authenticated administrators… Patch early 6.5 medium 2% 2007-04-12
CVE-2006-6447 EXP Multiple cross-site scripting (XSS) vulnerabilities in Vt-Forum Lite 1.3 and 1.5 allow remote attackers to inject arbitrary web script or HTML via (1)… Patch early 6.8 medium 2% 2006-12-10
CVE-2007-2303 EXP Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers to include and execute arbitr… Patch early 6.8 medium 2% 2007-04-26
CVE-2006-1238 EXP SQL injection vulnerability in DSLogin 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands and bypass authe… Patch early 5.1 medium 2% 2006-03-15
CVE-2007-5255 EXP Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance 3.4.14 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 2% 2007-10-06
CVE-2007-1031 EXP Directory traversal vulnerability in include/db_conn.php in SpoonLabs Vivvo Article Management CMS 3.4 allows remote attackers to include and execute… Patch early 6.8 medium 2% 2007-02-21
CVE-2007-5278 EXP Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers… Patch early 4.3 medium 2% 2007-10-08
CVE-2007-5721 EXP PHP remote file inclusion vulnerability in _theme/breadcrumb.php in MySpacePros MySpace Resource Script (MSRS) 1.21 allows remote attackers to execute… Patch early 6.8 medium 2% 2007-10-30
CVE-2007-5995 EXP PHP remote file inclusion vulnerability in examples/patExampleGen/bbcodeSource.php in patBBcode 1.0 allows remote attackers to execute arbitrary PHP c… Patch early 6.8 medium 2% 2007-11-15
CVE-2007-6289 EXP Multiple PHP remote file inclusion vulnerabilities in SerWeb 2.0.0 dev1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… Patch early 6.8 medium 2% 2007-12-10
CVE-2008-7099 EXP Unspecified vulnerability in the Manage Templates feature in Qsoft K-Rate Premium allows remote attackers to execute arbitrary PHP code via unknown ve… Patch early 6.8 medium 2% 2009-08-27
CVE-2007-1896 EXP Directory traversal vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier allows remote attackers to include arbitrary local files via a… Patch early 5.8 medium 2% 2007-04-09
CVE-2018-10078 EXP Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to inject arbitrary web script or… Patch early 4.8 medium 2% 2018-04-20
CVE-2007-3978 EXP Session fixation vulnerability in bwired allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. Patch early 4.3 medium 2% 2007-07-25
CVE-2007-5983 EXP Cross-site scripting (XSS) vulnerability in index.php in Justin Hagstrom AutoIndex PHP Script before 2.2.3 allows remote attackers to inject arbitrary… Patch early 4.3 medium 2% 2007-11-15
CVE-2010-4749 EXP Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to inject arbitrary web script o… Patch early 4.3 medium 2% 2011-03-01
CVE-2010-1920 EXP Directory traversal vulnerability in scr/soustab.php in OpenMairie openAnnuaire 2.00, when register_globals is enabled, allows remote attackers to inc… Patch early 6.8 medium 2% 2010-05-12
CVE-2008-6103 EXP PHP remote file inclusion vulnerability in index.php in A4Desk Event Calendar, when magic_quotes_gpc is disabled, allows remote attackers to execute a… Patch early 6.8 medium 2% 2009-02-10
CVE-2009-4315 EXP Directory traversal vulnerability in admin/ajaxsave.php in Nuggetz CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to create or mo… Patch early 6.8 medium 2% 2009-12-14
CVE-2006-3603 EXP Cross-site scripting (XSS) vulnerability in index.php in FlexWATCH Network Camera 3.0 and earlier allows remote attackers to inject arbitrary web scri… Patch early 5.8 medium 2% 2006-07-18
CVE-2008-7025 EXP TrueVector in Check Point ZoneAlarm 8.0.020.000, with vsmon.exe running, allows remote HTTP proxies to cause a denial of service (crash) and disable t… Patch early 4.3 medium 2% 2009-08-21
CVE-2009-1408 EXP Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to… Patch early 4.3 medium 2% 2009-04-24
CVE-2009-4435 EXP Multiple directory traversal vulnerabilities in F3Site 2009 allow remote attackers to include and execute arbitrary local files via directory traversa… Patch early 6.8 medium 2% 2009-12-28
CVE-2004-0672 EXP Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition 5.6 allows re… Patch early 6.8 medium 2% 2004-08-06
CVE-2002-2288 EXP Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.php with a parameter that does… Patch early 5.0 medium 2% 2002-12-31
← previous page 243 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt