peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,746 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

170,956 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-3996 EXP SQL injection vulnerability in links/index.php in ATutor 1.5.3.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via t… Patch early 6.5 medium 1.8% 2006-08-05
CVE-2002-2312 EXP Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2)… Patch early 5.8 medium 1.8% 2002-12-31
CVE-2003-1401 EXP login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remo… Patch early 5.8 medium 1.8% 2003-12-31
CVE-2007-2686 EXP Cross-site scripting (XSS) vulnerability in index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the login p… Patch early 4.3 medium 1.8% 2007-05-22
CVE-2017-8839 EXP XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_250… Patch early 6.1 medium 1.8% 2017-06-05
CVE-2006-1954 EXP SQL injection vulnerability in authent.php4 in Nicolas Fischer (aka NFec) RechnungsZentrale V2 1.1.3, and possibly earlier versions, allows remote att… Patch early 5.0 medium 1.8% 2006-04-21
CVE-2019-12195 EXP TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the… Patch early 4.8 medium 1.8% 2019-05-24
CVE-2010-5318 EXP The password-reset feature in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to modify the administrator's password by specifyin… Patch early 4.3 medium 1.8% 2015-01-03
CVE-2009-3803 EXP Multiple cross-site scripting (XSS) vulnerabilities in Amiro.CMS 5.4.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.8% 2009-10-27
CVE-2009-4381 EXP Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 1.8% 2009-12-22
CVE-2009-4888 EXP Cross-site scripting (XSS) vulnerability in poster.php in PHortail 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) ps… Patch early 4.3 medium 1.8% 2010-06-11
CVE-2009-2267 EXP VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware… Patch early 6.9 medium 1.8% 2009-11-02
CVE-2007-4003 EXP pioout in IBM AIX 5.3 SP6 allows local users to execute arbitrary code by specifying a malicious library with the -R (ParseRoutine) command line argum… Patch early 6.9 medium 1.8% 2007-07-26
CVE-2006-4927 EXP The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec AntiVirus and security products,… Patch early 4.6 medium 1.8% 2006-10-10
CVE-1999-0946 EXP Buffer overflow in Yamaha MidiPlug via a Text variable in an EMBED tag. Patch early 5.1 medium 1.8% 1999-11-02
CVE-2005-0981 EXP Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft EPay Pro 2.0 allow remote attackers to inject arbitrary web script or HTML via the (… Patch early 4.3 medium 1.8% 2005-05-02
CVE-2005-3790 EXP Multiple cross-site scripting (XSS) vulnerabilities in act_newsletter.php in phpwcms 1.2.5 allow remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 1.8% 2005-11-24
CVE-2005-2397 EXP Cross-site scripting (XSS) vulnerability in guestbook.php in phpBook 1.46 allows remote attackers to inject arbitrary web script or HTML via the admin… Patch early 4.3 medium 1.8% 2005-07-27
CVE-2005-2721 EXP Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) admin.php in Foojan PHP Weblog allow remote attackers to inject arbitrary… Patch early 4.3 medium 1.8% 2005-08-30
CVE-2005-2783 EXP Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested,… Patch early 4.3 medium 1.8% 2005-09-02
CVE-2005-2980 EXP Cross-site scripting (XSS) vulnerability in index.php in phpoutsourcing Noah's classifieds 1.3 allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 1.8% 2005-09-20
CVE-2005-3127 EXP Cross-site scripting (XSS) vulnerability in index.php in lucidCMS 1.0.11 allows remote attackers to inject arbitrary web script or HTML via the query… Patch early 4.3 medium 1.8% 2005-10-04
CVE-2005-3368 EXP Cross-site scripting (XSS) vulnerability in the Search_Enhanced module in PHP-Nuke 7.9 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.8% 2005-10-30
CVE-2005-3422 EXP Cross-site scripting (XSS) vulnerability in error.asp in ASP Fast Forum allows remote attackers to inject arbitrary web script or HTML via the error p… Patch early 4.3 medium 1.8% 2005-11-01
CVE-2005-3742 EXP Cross-site scripting (XSS) vulnerability in popup.php in Advanced Poll 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 1.8% 2005-11-22
CVE-2005-3972 EXP Cross-site scripting (XSS) vulnerability in extremesearch.php in Extreme Search Corporate Edition 6.0 and earlier allows remote attackers to inject ar… Patch early 4.3 medium 1.8% 2005-12-03
CVE-2005-4032 EXP Cross-site scripting (XSS) vulnerability in search.cgi in Easy Search System 1.1 and earlier allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 1.8% 2005-12-06
CVE-2005-4047 EXP Cross-site scripting (XSS) vulnerability in kb.asp in IISWorks ASPKnowledgeBase 2.0 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.8% 2005-12-07
CVE-2005-4091 EXP Cross-site scripting (XSS) vulnerability in 1search.cgi in 1-Script 1-Search 1.8 allows remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 1.8% 2005-12-08
CVE-2005-4136 EXP Cross-site scripting (XSS) vulnerability in login.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web script or HTML via the customer… Patch early 4.3 medium 1.8% 2005-12-09
← previous page 271 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt