peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,602 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

170,889 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-1033 EXP Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.9% 2006-03-07
CVE-2004-1911 EXP Cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) l paramete… Patch early 4.3 medium 1.9% 2004-12-31
CVE-2007-5231 EXP Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to upload and… Patch early 4.6 medium 1.9% 2007-10-05
CVE-2006-2883 EXP Cross-site scripting (XSS) vulnerability in search.php in Kmita FAQ 1.0 allows remote attackers to inject arbitrary web script or HTML via the q param… Patch early 4.3 medium 1.9% 2006-06-07
CVE-2006-3476 EXP Cross-site scripting (XSS) vulnerability in comments.php in PhpWebGallery 1.5.2 and earlier, and possibly 1.6.0, allows remote attackers to inject arb… Patch early 4.3 medium 1.9% 2006-07-10
CVE-2007-0144 EXP Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated attackers to inject arb… Patch early 6.8 medium 1.9% 2007-01-09
CVE-2006-5535 EXP Multiple cross-site scripting (XSS) vulnerabilities in WebHostManager (WHM) 10.8.0 cPanel 10.9.0 R50 allow remote attackers to inject arbitrary web sc… Patch early 4.3 medium 1.9% 2006-10-26
CVE-2007-6624 EXP Directory traversal vulnerability in printview.php in PNphpBB2 1.2i and earlier allows remote attackers to include and execute arbitrary local files v… Patch early 6.8 medium 1.9% 2008-01-04
CVE-2009-4047 EXP Multiple cross-site scripting (XSS) vulnerabilities in PHD Help Desk 1.43 allow remote attackers to inject arbitrary web script or HTML via (1) the PA… Patch early 4.3 medium 1.9% 2009-11-23
CVE-2011-0512 EXP SQL injection vulnerability in team.php in the Teams Structure module 3.0 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via… Patch early 6.8 medium 1.9% 2011-01-20
CVE-2015-5530 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers to hijack the authentication of… Patch early 6.8 medium 1.9% 2015-07-16
CVE-2008-2488 EXP admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated users to create new admin acco… Patch early 6.5 medium 1.9% 2008-05-28
CVE-2009-0452 EXP Multiple SQL injection vulnerabilities in parents/login.php in Online Grades 3.2.4, when magic_quotes_gpc is disabled, allow remote attackers to execu… Patch early 6.8 medium 1.9% 2009-02-10
CVE-2009-1741 EXP Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbi… Patch early 6.8 medium 1.9% 2009-05-20
CVE-2006-2473 EXP Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78 allows remote attackers to inject arbitrary web script or HTML via the p parameter… Patch early 4.3 medium 1.9% 2006-05-19
CVE-2011-0903 EXP Multiple directory traversal vulnerabilities in AR Web Content Manager (AWCM) 2.2 allow remote attackers to read arbitrary files and possibly have oth… Patch early 6.8 medium 1.9% 2011-02-07
CVE-2009-2574 EXP index.php in MiniTwitter 0.2 beta allows remote authenticated users to modify certain options of arbitrary accounts via an opt action. Patch early 6.5 medium 1.9% 2009-07-22
CVE-2020-14166 EXP The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remote attackers with project admi… Patch early 4.8 medium 1.9% 2020-07-01
CVE-2007-3574 EXP Multiple cross-site scripting (XSS) vulnerabilities in setup.cgi on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.00.06 firmware allow remo… Patch early 4.3 medium 1.9% 2007-07-05
CVE-2019-17225 EXP Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue. Patch early 5.4 medium 1.9% 2019-10-06
CVE-2011-5043 EXP TomatoSoft Free Mp3 Player 1.0 allows remote attackers to cause a denial of service (application crash) via a long string in an MP3 file, possibly a b… Patch early 4.3 medium 1.9% 2011-12-30
CVE-2007-0896 EXP Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbit… Patch early 4.3 medium 1.9% 2007-02-13
CVE-2014-3778 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in goform/RgDdns in ARRIS (formerly Motorola) SBG901 SURFboard Wireless Cable Modem allow r… Patch early 6.8 medium 1.9% 2014-06-19
CVE-2009-2783 EXP Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) op parame… Patch early 4.3 medium 1.9% 2009-08-17
CVE-2008-6840 EXP Multiple PHP remote file inclusion vulnerabilities in V-webmail 1.6.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG… Patch early 6.8 medium 1.9% 2009-07-01
CVE-2008-5320 EXP SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the… Patch early 6.5 medium 1.9% 2008-12-03
CVE-2010-3267 EXP Multiple SQL injection vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the q… Patch early 6.5 medium 1.9% 2010-12-02
CVE-2021-36654 EXP CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while updating the theme. Patch early 5.4 medium 1.9% 2021-08-03
CVE-2006-1802 EXP Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.9% 2006-04-18
CVE-2006-0211 EXP Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbit… Patch early 4.3 medium 1.9% 2006-01-14
← previous page 252 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt