peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,429 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

170,853 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2001-1524 EXP Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) unam… Patch early 4.3 medium 2% 2001-12-31
CVE-2006-4020 EXP scanf.c in PHP 5.1.4 and earlier, and 4.4.3 and earlier, allows context-dependent attackers to execute arbitrary code via a sscanf PHP function call t… Patch early 4.6 medium 2% 2006-08-08
CVE-2007-4630 EXP Cross-site scripting (XSS) vulnerability in xlaapmview.asp in Absolute Poll Manager XE 4.1 allows remote attackers to inject arbitrary web script or H… Patch early 4.3 medium 2% 2007-08-31
CVE-2008-0178 EXP Cross-site scripting (XSS) vulnerability in the Enterprise Admin Session Monitoring component in Liferay Portal 4.3.6 allows remote authenticated user… Patch early 4.3 medium 2% 2008-02-05
CVE-2004-1563 EXP Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via the (1) threa… Patch early 4.3 medium 2% 2004-12-31
CVE-2005-1075 EXP Multiple cross-site scripting (XSS) vulnerabilities in RadScripts RadBids Gold 2 allow remote attackers to inject arbitrary web script or HTML via (1)… Patch early 4.3 medium 2% 2005-05-02
CVE-2020-23522 EXP Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter. Patch early 6.8 medium 2% 2021-01-19
CVE-2014-9302 EXP Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Communit… Patch early 5.0 medium 2% 2014-12-07
CVE-2007-2002 EXP InoutMailingListManager 3.1 and earlier allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code,… Patch early 6.8 medium 2% 2007-04-12
CVE-2007-2003 EXP InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check fails, which allows remote att… Patch early 6.8 medium 2% 2007-04-12
CVE-2003-1347 EXP Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web script or HTML via the (1) cid par… Patch early 4.3 medium 2% 2003-12-31
CVE-2012-4901 EXP Cross-site scripting (XSS) vulnerability in Template CMS 2.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the them… Patch early 4.3 medium 2% 2015-05-20
CVE-2008-6911 EXP SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.0.1, when magic_quotes_gpc is… Patch early 6.8 medium 2% 2009-08-06
CVE-2012-1503 EXP Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary w… Patch early 4.3 medium 2% 2014-08-29
CVE-2012-2591 EXP Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attackers to inject arbitrary web sc… Patch early 4.3 medium 2% 2014-06-20
CVE-2010-5040 EXP PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute… Patch early 6.8 medium 2% 2011-11-02
CVE-2008-0461 EXP SQL injection vulnerability in index.php in the Search module in PHP-Nuke 8.0 FINAL and earlier, when magic_quotes_gpc is disabled, allows remote atta… Patch early 6.8 medium 2% 2008-01-25
CVE-2012-4870 EXP Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (… Patch early 4.3 medium 2% 2012-09-06
CVE-2007-2634 EXP PHP remote file inclusion vulnerability in common/errormsg.php in aForum 1.32 and possibly earlier, when register_globals is enabled, allows remote at… Patch early 6.8 medium 2% 2007-05-13
CVE-2010-2003 EXP Cross-site scripting (XSS) vulnerability in misc/get_admin.php in Advanced Poll 2.08 allows remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 2% 2010-05-20
CVE-2008-1495 EXP Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote authenticated administrators to up… Patch early 6.5 medium 2% 2008-03-25
CVE-2018-13832 EXP Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow re… Patch early 4.8 medium 2% 2018-07-16
CVE-2012-3233 EXP Cross-site scripting (XSS) vulnerability in __swift/thirdparty/PHPExcel/PHPExcel/Shared/JAMA/docs/download.php in Kayako Fusion 4.40.1148, and possibl… Patch early 4.3 medium 2% 2012-09-15
CVE-2008-7098 EXP Multiple cross-site scripting (XSS) vulnerabilities in Qsoft K-Rate Premium allow remote attackers to inject arbitrary web script or HTML via the blog… Patch early 4.3 medium 2% 2009-08-27
CVE-2014-9235 EXP Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute arbitrary SQL… Patch early 6.5 medium 2% 2014-12-03
CVE-2015-6516 EXP SQL injection vulnerability in cygnux.org sysPass 1.0.9 and earlier allows remote authenticated users to execute arbitrary SQL commands via the search… Patch early 6.5 medium 2% 2015-08-18
CVE-2008-7055 EXP module.php in ezContents 2.0.3 allows remote attackers to bypass the directory traversal protection mechanism to include and execute arbitrary local f… Patch early 5.1 medium 2% 2009-08-24
CVE-2020-23518 EXP Cross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to version 3.5 which allows remote at… Patch early 5.4 medium 2% 2021-03-02
CVE-2007-1606 EXP Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary web script or HTML via (1) the s… Patch early 4.3 medium 2% 2007-03-22
CVE-2004-1213 EXP Cross-site scripting (XSS) vulnerability in index.php in Advanced Guestbook 2.3.1, 2.2, and possibly other versions allows remote attackers to inject… Patch early 6.8 medium 2% 2005-01-10
← previous page 244 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt