peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,659 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

170,909 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-5343 EXP Cross-site scripting (XSS) vulnerability in admin/login.php in Limny 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the PATH… Patch early 4.3 medium 1.9% 2012-10-09
CVE-2007-5127 EXP Multiple cross-site scripting (XSS) vulnerabilities in SimpGB 1.46.02 allow remote attackers to inject arbitrary web script or HTML via (1) the l_user… Patch early 4.3 medium 1.9% 2007-09-27
CVE-2006-6096 EXP Cross-site scripting (XSS) vulnerability in activenews_search.asp in ActiveNews Manager allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.9% 2006-11-24
CVE-2008-7152 EXP Multiple PHP remote file inclusion vulnerabilities in Specimen Image Database (SID), when register_globals is enabled, allow remote attackers to execu… Patch early 6.8 medium 1.9% 2009-09-01
CVE-2005-2219 EXP Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct… Patch early 4.6 medium 1.9% 2005-07-12
CVE-2006-1482 EXP Cross-site scripting (XSS) vulnerability in index.php in ConfTool 1.1 allows remote attackers to inject arbitrary web script or HTML via the page para… Patch early 4.3 medium 1.9% 2006-03-29
CVE-2012-0308 EXP Cross-site request forgery (CSRF) vulnerability in Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers to hijack the authentication o… Patch early 6.8 medium 1.9% 2012-08-29
CVE-2008-6773 EXP Static code injection vulnerability in user/internettoolbar/edit.php in YourPlace 1.0.2 and earlier allows remote authenticated users to execute arbit… Patch early 6.5 medium 1.9% 2009-04-29
CVE-2007-0645 EXP Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in… Patch early 6.8 medium 1.9% 2007-02-01
CVE-2008-5878 EXP Multiple directory traversal vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled and register… Patch early 5.1 medium 1.9% 2009-01-08
CVE-2008-6901 EXP Multiple directory traversal vulnerabilities in 2532designs 2532|Gigs 1.2.2 Stable, when register_globals is enabled and magic_quotes_gpc is disabled,… Patch early 5.1 medium 1.9% 2009-08-06
CVE-2008-1861 EXP Directory traversal vulnerability in modules/threadstop/threadstop.php in ExBB Italia 0.22 and earlier, when register_globals is enabled and magic_quo… Patch early 5.1 medium 1.9% 2008-04-17
CVE-2008-1208 EXP Cross-site scripting (XSS) vulnerability in the login page in Check Point VPN-1 UTM Edge W Embedded NGX 7.0.48x allows remote attackers to inject arbi… Patch early 4.3 medium 1.9% 2008-03-08
CVE-2006-6082 EXP Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.9% 2006-11-24
CVE-2009-2101 EXP Directory traversal vulnerability in archive.php in TorrentVolve 1.4, when register_globals is enabled, allows remote attackers to delete arbitrary fi… Patch early 6.8 medium 1.9% 2009-06-17
CVE-2008-3562 EXP Directory traversal vulnerability in index.php in the Contact module in Chupix CMS 0.1.0, when magic_quotes_gpc is disabled, allows remote attackers t… Patch early 5.1 medium 1.9% 2008-08-10
CVE-2006-0783 EXP Cross-site scripting (XSS) vulnerability in page.php in in Siteframe Beaumont, possibly 5.0.2 or 5.0.1a, allows remote attackers to inject arbitrary w… Patch early 4.3 medium 1.9% 2006-02-19
CVE-2007-2087 EXP Multiple PHP remote file inclusion vulnerabilities in CNStats 2.12, when register_globals is enabled and .htaccess is not recognized, allow remote att… Patch early 6.8 medium 1.9% 2007-04-18
CVE-2007-3315 EXP Multiple PHP remote file inclusion vulnerabilities in YourFreeScreamer 1.0, when register_globals is enabled, allow remote attackers to execute arbitr… Patch early 6.8 medium 1.9% 2007-06-21
CVE-2011-0635 EXP Static code injection vulnerability in Simploo CMS 1.7.1 and earlier allows remote authenticated users to inject arbitrary PHP code into config/custom… Patch early 6.0 medium 1.9% 2011-01-22
CVE-2019-12801 EXP out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name. Patch early 6.1 medium 1.9% 2019-06-17
CVE-2009-3201 EXP Integer overflow in Media Player Classic 6.4.9 allows user-assisted remote attackers to cause a denial of service (application crash) via a MIDI file… Patch early 4.3 medium 1.9% 2009-09-15
CVE-2009-3211 EXP Directory traversal vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary… Patch early 6.8 medium 1.9% 2009-09-16
CVE-2008-5265 EXP Directory traversal vulnerability in index.php in TNT Forum 0.9.4, when magic_quotes_gpc is disabled, allows remote attackers to include and execute a… Patch early 6.8 medium 1.9% 2008-11-28
CVE-2008-5894 EXP Directory traversal vulnerability in index.php in Mediatheka 4.2 allows remote attackers to include and execute arbitrary local files via a .. (dot do… Patch early 6.8 medium 1.9% 2009-01-12
CVE-2010-4406 EXP Directory traversal vulnerability in gallery.php in Brunetton LittlePhpGallery 1.0.2, when magic_quotes_gpc is disabled, allows remote attackers to li… Patch early 6.8 medium 1.9% 2010-12-06
CVE-2008-0459 EXP Directory traversal vulnerability in update/index.php in Liquid-Silver CMS 0.35, when magic_quotes_gpc is disabled, allows remote attackers to include… Patch early 6.8 medium 1.9% 2008-01-25
CVE-2008-1857 EXP Multiple directory traversal vulnerabilities in viewsource.php in Make our Life Easy (Mole) 2.1.0 allow remote attackers to read arbitrary files via d… Patch early 6.8 medium 1.9% 2008-04-16
CVE-2008-2355 EXP Directory traversal vulnerability in index.php in WR-Meeting 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute ar… Patch early 6.8 medium 1.9% 2008-05-20
CVE-2008-2483 EXP Directory traversal vulnerability in index.php in Xomol CMS 1.20071213 allows remote attackers to include and execute arbitrary local files via a .. (… Patch early 6.8 medium 1.9% 2008-05-28
← previous page 255 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt