peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,534 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

170,877 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-4250 EXP Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allow remote attackers to inject arbitrary… Patch early 4.3 medium 2% 2009-12-10
CVE-2002-0492 EXP dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter. Patch early 5.0 medium 2% 2002-08-12
CVE-2004-1825 EXP Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary we… Patch early 4.3 medium 2% 2004-03-16
CVE-2004-2355 EXP Cross-site scripting (XSS) vulnerability in Crafty Syntax Live Help (CSLH) before 2.7.4 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 2% 2004-12-31
CVE-2005-1715 EXP Cross-site scripting (XSS) vulnerability in index.php for TOPo 2.2 (2.2.178) allows remote attackers to inject arbitrary web script or HTML via the (1… Patch early 4.3 medium 2% 2005-05-24
CVE-2005-2603 EXP Cross-site scripting (XSS) vulnerability in index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 2% 2005-08-17
CVE-2010-1926 EXP Directory traversal vulnerability in scr/soustab.php in openMairie openCourrier 2.02 and 2.03 beta, when register_globals is enabled, allows remote at… Patch early 6.8 medium 2% 2010-05-12
CVE-2011-1671 EXP Cross-site scripting (XSS) vulnerability in app/controllers/todos_controller.rb in Tracks 1.7.2, 2.0RC2, and 2.0devel allows remote attackers to injec… Patch early 4.3 medium 2% 2011-04-10
CVE-2008-3098 EXP Cross-site scripting (XSS) vulnerability in admin/usercheck.php in fuzzylime (cms) before 3.03 allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 2% 2008-09-24
CVE-2005-3638 EXP Cross-site scripting (XSS) vulnerabilities in Ekinboard 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter i… Patch early 4.3 medium 2% 2005-11-16
CVE-2005-4555 EXP Cross-site scripting (XSS) vulnerability in add.php in DEV web management system 1.5 and earlier allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 2% 2005-12-28
CVE-2006-0946 EXP Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 2% 2006-03-01
CVE-2004-2293 EXP Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.0 to 7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) e… Patch early 4.3 medium 2% 2004-12-31
CVE-2008-6316 EXP Directory traversal vulnerability in _conf/core/common-tpl-vars.php in PHPmyGallery 1.0 beta2 allows remote attackers to include and execute arbitrary… Patch early 6.8 medium 2% 2009-02-27
CVE-2008-6317 EXP Directory traversal vulnerability in _conf/_php-core/common-tpl-vars.php in PHPmyGallery 1.5 beta allows remote attackers to include and execute arbit… Patch early 6.8 medium 2% 2009-02-27
CVE-2008-7176 EXP Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) change_la… Patch early 6.8 medium 2% 2009-09-08
CVE-2009-3515 EXP Directory traversal vulnerability in dnet_admin/index.php in d.net CMS allows remote authenticated administrators to include and execute arbitrary loc… Patch early 6.5 medium 2% 2009-10-01
CVE-2009-1777 EXP CRLF injection vulnerability in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allows remote attackers to inject arbitrary HTTP heade… Patch early 5.0 medium 2% 2009-05-22
CVE-2006-5847 EXP Cross-site scripting (XSS) vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML… Patch early 6.1 medium 2% 2006-11-10
CVE-2006-1580 EXP Multiple cross-site scripting (XSS) vulnerabilities in Bugzero 4.3.1 and other versions allow remote attackers to inject arbitrary web script or HTML… Patch early 5.8 medium 2% 2006-04-02
CVE-2009-4876 EXP admin/cikkform.php in Netrix CMS 1.0 allows remote attackers to modify arbitrary pages via a direct request using the cid parameter. Patch early 5.0 medium 2% 2010-05-26
CVE-2006-1428 EXP Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 2% 2006-03-28
CVE-2006-3385 EXP Cross-site scripting (XSS) vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to inject arbitrary web script or HTML via… Patch early 5.8 medium 2% 2006-07-06
CVE-2009-2220 EXP Multiple directory traversal vulnerabilities in Tribiq CMS 5.0.12c, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote at… Patch early 5.1 medium 2% 2009-06-26
CVE-2009-4725 EXP Directory traversal vulnerability in modules/aljazeera/admin/setup.php in Arab Portal 2.2 and earlier, when register_globals is enabled and magic_quot… Patch early 5.1 medium 2% 2010-03-18
CVE-2008-0504 EXP Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary… Patch early 6.5 medium 2% 2008-01-31
CVE-2011-2403 EXP SQL injection vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote authenticated users to execute arbitrary SQL comman… Patch early 6.5 medium 2% 2011-08-01
CVE-2008-6313 EXP Directory traversal vulnerability in addedit-render.php in phpAddEdit 1.3, when magic_quotes_gpc is disabled, allows remote attackers to include and e… Patch early 6.8 medium 2% 2009-02-27
CVE-2008-0602 EXP Directory traversal vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to include and execute arbitrary loc… Patch early 6.8 medium 2% 2008-02-06
CVE-2009-2611 EXP Directory traversal vulnerability in infusions/last_seen_users_panel/last_seen_users_panel.php in MyFusion (aka MyF) 6 Beta, when register_globals is… Patch early 6.8 medium 2% 2009-07-27
← previous page 249 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt