peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,534 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

170,877 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2007-4068 EXP Multiple SQL injection vulnerabilities in Webyapar 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the kat_id parameter to the de… Patch early 5.8 medium 2% 2007-07-30
CVE-2017-16568 EXP Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. This vulnerability allows att… Patch early 5.4 medium 2% 2017-11-10
CVE-2006-6356 EXP Multiple cross-site scripting (XSS) vulnerabilities in templates/link_temp.php in PHPNews 1.3.0 allow remote attackers to inject arbitrary web script… Patch early 6.8 medium 2% 2006-12-07
CVE-2014-2339 EXP Multiple SQL injection vulnerabilities in bbs/ajax.autosave.php in GNUboard 5.x and possibly earlier allow remote authenticated users to execute arbit… Patch early 6.5 medium 2% 2014-03-19
CVE-2006-5056 EXP Cross-site scripting (XSS) vulnerability in index.php in Opial Audio/Video Download Management 1.0 allows remote attackers to inject arbitrary web scr… Patch early 5.1 medium 2% 2006-09-28
CVE-2006-5074 EXP Cross-site scripting (XSS) vulnerability in home.php in PHP Invoice 2.2 allows remote attackers to inject arbitrary web script or HTML via the alert p… Patch early 5.1 medium 2% 2006-09-29
CVE-2007-1101 EXP Multiple cross-site scripting (XSS) vulnerabilities in Photostand 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) mess… Patch early 4.3 medium 2% 2007-02-26
CVE-2006-1357 EXP Cross-site scripting (XSS) vulnerability in my.support.php3 in F5 Firepass 4100 SSL VPN 5.4.2 allows remote attackers to inject arbitrary web script o… Patch early 4.3 medium 2% 2006-03-22
CVE-2008-6658 EXP Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated admin… Patch early 4.0 medium 2% 2009-04-07
CVE-2015-6655 EXP Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for requests… Patch early 6.8 medium 2% 2015-08-31
CVE-2015-6827 EXP Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentication of users for requests tha… Patch early 6.8 medium 2% 2015-09-11
CVE-2006-6819 EXP AlstraSoft Web Host Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to downl… Patch early 6.4 medium 2% 2006-12-29
CVE-2020-13260 EXP A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload a JavaScrip… Patch early 6.1 medium 2% 2020-09-17
CVE-2008-6074 EXP Directory traversal vulnerability in frame.php in phpcrs 2.06 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and e… Patch early 5.1 medium 2% 2009-02-06
CVE-2003-0102 EXP Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large… Patch early 4.6 medium 2% 2003-03-18
CVE-2007-1709 EXP Buffer overflow in the confirm_phpdoc_compiled function in the phpDOC extension (PECL phpDOC) in PHP 5.2.1 allows context-dependent attackers to execu… Patch early 4.3 medium 2% 2007-03-27
CVE-2003-1175 EXP Cross-site scripting (XSS) vulnerability in index.php in Sympoll 1.5 allows remote attackers to inject arbitrary web script or HTML via the vo paramet… Patch early 6.8 medium 2% 2003-12-31
CVE-2003-1182 EXP Cross-site scripting (XSS) vulnerability in MPM Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter. Patch early 6.8 medium 2% 2003-11-03
CVE-2006-1916 EXP Multiple cross-site scripting (XSS) vulnerabilities in profile.php in DbbS 2.0-alpha and earlier allow remote attackers to inject arbitrary web script… Patch early 6.8 medium 2% 2006-04-20
CVE-2004-1818 EXP Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary scri… Patch early 6.8 medium 2% 2004-03-15
CVE-2005-1611 EXP Cross-site scripting (XSS) vulnerability in WebX in Web Crossing 5.x allows remote attackers to inject arbitrary web script or HTML via a URL with an… Patch early 6.8 medium 2% 2005-05-16
CVE-2008-1128 EXP PHP remote file inclusion vulnerability in tourney/index.php in phpMyTourney 2 allows remote attackers to execute arbitrary PHP code via a URL in the… Patch early 6.8 medium 2% 2008-03-03
CVE-2008-2744 EXP Cross-site scripting (XSS) vulnerability in vBulletin 3.6.10 and 3.7.1 allows remote attackers to inject arbitrary web script or HTML via unknown vect… Patch early 4.3 medium 2% 2008-06-17
CVE-2011-4709 EXP Multiple cross-site scripting (XSS) vulnerabilities in Hotaru.php in the Search plugin 1.3 for Hotaru CMS allow remote attackers to inject arbitrary w… Patch early 4.3 medium 2% 2011-12-08
CVE-2009-3715 EXP Multiple SQL injection vulnerabilities in scr_login.php in MCshoutbox 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitr… Patch early 6.8 medium 2% 2009-10-16
CVE-2008-1094 EXP SQL injection vulnerability in index.cgi in the Account View page in Barracuda Spam Firewall (BSF) before 3.5.12.007 allows remote authenticated admin… Patch early 6.5 medium 2% 2008-12-19
CVE-2008-2974 EXP Directory traversal vulnerability in chatconfig.php in MM Chat 1.5, when register_globals is enabled, allows remote attackers to include and execute a… Patch early 6.8 medium 2% 2008-07-02
CVE-2008-2982 EXP Multiple directory traversal vulnerabilities in HomePH Design 2.10 RC2, when register_globals is enabled, allow remote attackers to include and execut… Patch early 6.8 medium 2% 2008-07-02
CVE-2008-4158 EXP Multiple directory traversal vulnerabilities in index.php in Zanfi CMS lite 1.2 allow remote attackers to include and execute arbitrary local files vi… Patch early 6.8 medium 2% 2008-09-22
CVE-2009-2338 EXP Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is enabled, allows remote attack… Patch early 6.8 medium 2% 2009-07-07
← previous page 247 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt