peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,557 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

170,889 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-6433 EXP Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hijack the authentication of admin… Patch early 6.8 medium 2% 2013-01-03
CVE-2006-6391 EXP Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow… Patch early 6.8 medium 2% 2006-12-08
CVE-2006-4543 EXP Cross-site scripting (XSS) vulnerability in index.php in HLStats 1.34 allows remote attackers to inject arbitrary web script or HTML via the (1) game… Patch early 6.8 medium 2% 2006-09-06
CVE-2010-1928 EXP Directory traversal vulnerability in scr/soustab.php in openMairie openPlanning 1.00, when register_globals is enabled, allows remote attackers to inc… Patch early 6.8 medium 2% 2010-05-12
CVE-2010-1935 EXP Directory traversal vulnerability in scr/soustab.php in openMairie Openpresse 1.01, when register_globals is enabled, allows remote attackers to inclu… Patch early 6.8 medium 2% 2010-05-12
CVE-2010-1936 EXP Directory traversal vulnerability in scr/soustab.php in openMairie openComInterne 1.01, when register_globals is enabled, allows remote attackers to i… Patch early 6.8 medium 2% 2010-05-12
CVE-2008-5818 EXP Directory traversal vulnerability in index.php in eDreamers eDContainer 2.22, when magic_quotes_gpc is disabled, allows remote attackers to include an… Patch early 6.8 medium 2% 2009-01-02
CVE-2009-1488 EXP Directory traversal vulnerability in admin/load.php in FunGamez RC1 allows remote attackers to include and execute arbitrary local files via a .. (dot… Patch early 6.8 medium 2% 2009-04-29
CVE-2007-0491 EXP PHP remote file inclusion vulnerability in up.php in Sky GUNNING MySpeach 3.0.6 and earlier allows remote attackers to execute arbitrary PHP code via… Patch early 6.8 medium 2% 2007-01-25
CVE-2009-1318 EXP Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions before 3.4.0 allows remote at… Patch early 6.5 medium 2% 2009-04-17
CVE-2010-0380 EXP install.php in JCE-Tech PHP Calendars, downloaded 20100121, allows remote attackers to bypass intended access restrictions and modify application sett… Patch early 5.0 medium 2% 2010-01-22
CVE-2006-5626 EXP Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026… Patch early 4.3 medium 2% 2006-10-31
CVE-2006-4157 EXP Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web script or H… Patch early 6.8 medium 2% 2006-08-16
CVE-2006-4593 EXP Cross-site scripting (XSS) vulnerability in index.php in SoftBB 0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the… Patch early 6.8 medium 2% 2006-09-06
CVE-2009-2553 EXP Multiple SQL injection vulnerabilities in comments.php in Super Simple Blog Script 2.5.4, when magic_quotes_gpc is disabled, allow remote attackers to… Patch early 6.8 medium 2% 2009-07-20
CVE-2006-2396 EXP Cross-site scripting (XSS) vulnerability in phpODP 1.5h allows remote attackers to inject arbitrary web script via the browse parameter. Patch early 5.8 medium 2% 2006-05-16
CVE-2019-15081 EXP OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Produ… Patch early 4.8 medium 2% 2019-08-15
CVE-2009-4722 EXP SQL injection vulnerability in the CheckLogin function in includes/functions.php in Limny 1.01, when magic_quotes_gpc is disabled, allows remote attac… Patch early 6.8 medium 2% 2010-03-18
CVE-2011-4095 EXP Jara 1.6 has an XSS vulnerability Patch early 6.1 medium 2% 2020-01-21
CVE-2008-3573 EXP The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_random value) wi… Patch early 5.0 medium 2% 2008-08-10
CVE-2005-4365 EXP Multiple cross-site scripting (XSS) vulnerabilities in FLIP 0.9.0.1029 allow remote attackers to inject arbitrary web script or HTML via the (1) name… Patch early 4.3 medium 2% 2005-12-20
CVE-2003-0486 EXP SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter. Patch early 5.0 medium 1.9% 2003-08-07
CVE-2014-1671 EXP Multiple SQL injection vulnerabilities in Dell KACE K1000 5.4.76847 and possibly earlier allow remote attackers or remote authenticated users to execu… Patch early 6.5 medium 1.9% 2014-01-26
CVE-2006-4362 EXP Cross-site scripting (XSS) vulnerability in getad.php in Diesel Paid Mail allows remote attackers to inject arbitrary web script or HTML via the ps pa… Patch early 4.3 medium 1.9% 2006-08-27
CVE-2014-3415 EXP SQL injection vulnerability in Sharetronix before 3.4 allows remote authenticated users to execute arbitrary SQL commands via the invite_users[] param… Patch early 6.5 medium 1.9% 2014-05-29
CVE-2014-5275 EXP Multiple SQL injection vulnerabilities in includes/functions.php in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to execute a… Patch early 6.5 medium 1.9% 2014-10-20
CVE-2013-5028 EXP SQL injection vulnerability in IT/hardware-list.dll in Kwoksys Kwok Information Server before 2.8.5 allows remote authenticated users to execute arbit… Patch early 6.5 medium 1.9% 2013-10-11
CVE-2010-0713 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote attackers to hijack the authen… Patch early 6.8 medium 1.9% 2010-02-26
CVE-2016-2184 EXP The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate… Patch early 4.6 medium 1.9% 2016-04-27
CVE-2008-1795 EXP Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Academic Suite 7.x and earlier, and possibly some 8.0 versions, allow remote attacke… Patch early 4.3 medium 1.9% 2008-04-15
← previous page 251 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt