peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,729 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

170,949 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2003-1481 EXP CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack… Patch early 5.8 medium 1.8% 2003-12-31
CVE-2012-1023 EXP Open redirect vulnerability in admin/index.php in 4images 1.7.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing… Patch early 5.8 medium 1.8% 2012-02-08
CVE-2007-2901 EXP Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.8% 2007-05-30
CVE-2007-3324 EXP Multiple cross-site scripting (XSS) vulnerabilities in Comersus Cart 7.07 allow remote attackers to inject arbitrary web script or HTML via the redire… Patch early 4.3 medium 1.8% 2007-06-21
CVE-2009-3860 EXP Multiple insecure method vulnerabilities in Idefense Labs COMRaider allow remote attackers to create or overwrite arbitrary files via the (1) CreateFo… Patch early 5.8 medium 1.8% 2009-11-04
CVE-2008-2787 EXP Cross-site scripting (XSS) vulnerability in out.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the last_me… Patch early 4.3 medium 1.8% 2008-06-20
CVE-2005-4161 EXP Multiple cross-site scripting (XSS) vulnerabilities in MilliScripts 1.4 redirect script allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.8% 2005-12-11
CVE-2015-7562 EXP Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbitrary web script or HTML via t… Patch early 6.1 medium 1.8% 2017-04-12
CVE-2010-0756 EXP Session fixation vulnerability in WikyBlog 1.7.3 rc2 allows remote attackers to hijack web sessions by setting the jsessionid parameter to (1) index.p… Patch early 5.8 medium 1.8% 2010-02-27
CVE-2009-1907 EXP Cross-site scripting (XSS) vulnerability in claroline/linker/notfound.php in Claroline 1.8.11 allows remote attackers to inject arbitrary web script o… Patch early 4.3 medium 1.8% 2009-06-04
CVE-2014-5193 EXP Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the ca… Patch early 4.3 medium 1.8% 2014-08-07
CVE-2022-48177 EXP X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importModels Impor… Patch early 5.4 medium 1.8% 2023-04-15
CVE-2022-48178 EXP X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action function, ak… Patch early 5.4 medium 1.8% 2023-04-15
CVE-2007-4479 EXP Cross-site scripting (XSS) vulnerability in search.html in Search Engine Builder allows remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 1.8% 2007-08-22
CVE-2007-1229 EXP Cross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.8% 2007-03-02
CVE-2007-3055 EXP Cross-site scripting (XSS) vulnerability in index.php in Codelib Linker 2.0.4 and earlier allows remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 1.8% 2007-06-06
CVE-2006-6721 EXP Multiple cross-site scripting (XSS) vulnerabilities in shout.php in Knusperleicht ShoutBox 2.6 allow remote attackers to inject arbitrary web script o… Patch early 6.8 medium 1.8% 2006-12-23
CVE-2008-0283 EXP PHP remote file inclusion vulnerability in /aides/index.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary PHP code via a URL… Patch early 6.8 medium 1.8% 2008-01-15
CVE-2008-5947 EXP PHP remote file inclusion vulnerability in include/class_yapbbcooker.php in YapBB 1.2.Beta 2 allows remote attackers to execute arbitrary PHP code via… Patch early 6.8 medium 1.8% 2009-01-22
CVE-2008-6511 EXP Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arbitrary web sites and conduct p… Patch early 5.8 medium 1.8% 2009-03-23
CVE-2008-6044 EXP Cross-site scripting (XSS) vulnerability in advanced_search_result.php in xt:Commerce 3.0.4 and earlier allows remote attackers to inject arbitrary we… Patch early 4.3 medium 1.8% 2009-02-03
CVE-2004-1995 EXP Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm. Patch early 6.5 medium 1.8% 2004-12-31
CVE-2012-4923 EXP Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) c… Patch early 4.3 medium 1.8% 2012-09-15
CVE-2006-6951 EXP Cross-site scripting (XSS) vulnerability in blog.php in OdysseusBlog allows remote attackers to inject arbitrary web script or HTML via the page param… Patch early 6.8 medium 1.8% 2007-01-23
CVE-2008-6665 EXP change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges via a crafted email parameter… Patch early 6.8 medium 1.8% 2009-04-08
CVE-2018-1188 EXP Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and versions 7.2.1.x is affected by a cross-site scripti… Patch early 4.8 medium 1.8% 2018-03-26
CVE-2018-1201 EXP Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a… Patch early 4.8 medium 1.8% 2018-03-26
CVE-2008-2421 EXP Cross-site scripting (XSS) vulnerability in the Web GUI in SAP Web Application Server (WAS) 7.0, Web Dynpro for ABAP (aka WD4A or WDA), and Web Dynpro… Patch early 4.3 medium 1.8% 2008-05-23
CVE-2007-0768 EXP Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted… Patch early 4.3 medium 1.8% 2007-02-06
CVE-2005-3020 EXP Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1… Patch early 4.3 medium 1.8% 2005-09-21
← previous page 263 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt