peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,707 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

170,932 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-2064 EXP Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web script via the (1) Email or (2) W… Patch early 4.3 medium 1.9% 2004-07-29
CVE-2015-5594 EXP The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attack… Patch early 6.1 medium 1.9% 2017-07-25
CVE-2021-45783 EXP Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information. Patch early 4.6 medium 1.9% 2022-05-05
CVE-2024-53586 EXP An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injectin… Patch early 5.3 medium 1.9% 2025-02-06
CVE-2024-12344 EXP A vulnerability, which was classified as critical, was found in TP-Link VN020 F3v(T) TT_V6.2.1021. This affects an unknown part of the component FTP U… Patch early 6.3 medium 1.9% 2024-12-08
CVE-2021-28417 EXP A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name" parameter. Patch early 4.8 medium 1.9% 2021-03-18
CVE-2021-28418 EXP A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category" parameter. Patch early 4.8 medium 1.9% 2021-03-18
CVE-2007-2011 EXP Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the username… Patch early 4.3 medium 1.9% 2007-04-12
CVE-2003-1151 EXP Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrary web script or HTML via the U… Patch early 4.3 medium 1.9% 2003-10-28
CVE-2007-3267 EXP Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.01b and earlier allows remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 1.9% 2007-06-19
CVE-2009-3948 EXP JetAudio 7.5.3 COWON Media Center allows remote attackers to cause a denial of service (memory consumption and application crash) via a long string at… Patch early 4.3 medium 1.9% 2009-11-16
CVE-2009-4659 EXP Unspecified vulnerability in MP3-Cutter Ease Audio Cutter 1.20 allows user-assisted remote attackers to cause a denial of service (application crash)… Patch early 4.3 medium 1.9% 2010-03-03
CVE-2006-6022 EXP Cross-site scripting (XSS) vulnerability in login_form.asp in BestWebApp Dating Site allows remote attackers to inject arbitrary web script or HTML vi… Patch early 6.8 medium 1.9% 2006-11-21
CVE-2006-6118 EXP Cross-site scripting (XSS) vulnerability in thumbs.php in mmgallery 1.55 allows remote attackers to inject arbitrary web script or HTML via the page p… Patch early 6.8 medium 1.9% 2006-11-26
CVE-2006-6571 EXP Multiple cross-site scripting (XSS) vulnerabilities in form.php in GenesisTrader 1.0 allow remote attackers to inject arbitrary web script or HTML via… Patch early 6.8 medium 1.9% 2006-12-15
CVE-2018-11124 EXP Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject ar… Patch early 5.4 medium 1.9% 2018-07-06
CVE-2006-2079 EXP Cross-site scripting (XSS) vulnerability in portfolio.php in Verosky Media Instant Photo Gallery, possibly before 1.0.2, allows remote attackers to in… Patch early 4.3 medium 1.9% 2006-04-27
CVE-2006-2208 EXP Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php in MyNews 1.6.2 allow remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 1.9% 2006-05-05
CVE-2012-4251 EXP Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML via the (1) pa… Patch early 4.3 medium 1.9% 2012-08-13
CVE-2008-4320 EXP Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.5.94 allow remote attackers to inject arbitrary web script or HTML via (1) the… Patch early 4.3 medium 1.9% 2008-09-29
CVE-2015-5399 EXP Cross-site scripting (XSS) vulnerability in PHPVibe before 4.21 allows remote authenticated users to inject arbitrary web script or HTML via a comment… Patch early 5.4 medium 1.9% 2016-08-26
CVE-2007-3448 EXP Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 1.9% 2007-06-27
CVE-2009-4690 EXP Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Programs Rating Script allow remote attackers to inject arbitrary web script or H… Patch early 4.3 medium 1.9% 2010-03-10
CVE-2012-1915 EXP EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks. Patch early 6.1 medium 1.9% 2020-01-09
CVE-2012-4246 EXP Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web… Patch early 4.3 medium 1.9% 2012-08-12
CVE-2008-6988 EXP Multiple cross-site scripting (XSS) vulnerabilities in Easy Photo Gallery (aka Ezphotogallery) 2.1 allow remote attackers to inject arbitrary web scri… Patch early 4.3 medium 1.9% 2009-08-19
CVE-2013-5020 EXP Multiple cross-site scripting (XSS) vulnerabilities in bb_admin.php in MiniBB before 3.0.1 allow remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 1.9% 2013-07-31
CVE-2009-0530 EXP Multiple PHP remote file inclusion vulnerabilities in SnippetMaster 2.2.2, when register_globals is enabled, allow remote attackers to execute arbitra… Patch early 6.8 medium 1.9% 2009-02-11
CVE-2009-1946 EXP PHP remote file inclusion vulnerability in latestposts.php in AdaptBB 1.0, when register_globals is enabled, allows remote attackers to execute arbitr… Patch early 6.8 medium 1.9% 2009-06-05
CVE-2007-3281 EXP Cross-site scripting (XSS) vulnerability in index.php in Php Hosting Biller 1.0 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.9% 2007-06-19
← previous page 260 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt