peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,146 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

208,173 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-3423 EXP login.php in Zenas PaoLink 1.0, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by s… Patch early 6.8 medium 2.6% 2009-09-25
CVE-2005-1884 EXP Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to crea… Patch early 6.4 medium 2.6% 2005-06-09
CVE-2019-12745 EXP out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field. Patch early 5.4 medium 2.6% 2019-06-20
CVE-2002-2247 EXP The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full web root pat… Patch early 5.0 medium 2.6% 2002-12-31
CVE-2007-2943 EXP PHP remote file inclusion vulnerability in class/class.php in Webavis 0.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the roo… Patch early 6.8 medium 2.6% 2007-05-31
CVE-2006-5262 EXP CRLF injection vulnerability in lib/session.php in Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary IMAP… Patch early 6.5 medium 2.6% 2006-10-12
CVE-2006-0734 EXP The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remote authenticated users to cause… Patch early 4.0 medium 2.6% 2006-02-16
CVE-2007-5573 EXP PHP remote file inclusion vulnerability in classes/core/language.php in LimeSurvey 1.5.2 and earlier allows remote attackers to execute arbitrary PHP… Patch early 6.8 medium 2.6% 2007-10-18
CVE-2024-44762 EXP A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts. Patch early 5.3 medium 2.6% 2024-10-16
CVE-2010-5322 EXP Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search par… Patch early 4.3 medium 2.6% 2015-03-11
CVE-2009-0325 EXP Directory traversal vulnerability in entries/index.php in Ninja Blog 4.8, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary… Patch early 4.3 medium 2.6% 2009-01-29
CVE-2006-4206 EXP Cross-site scripting (XSS) vulnerability in calendar.asp in ASPPlayground.NET Forum Advanced Edition 2.4.5 Unicode, and possibly other versions before… Patch early 4.3 medium 2.6% 2006-08-17
CVE-2011-5075 EXP translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to obtain sensitive information via a direct request us… Patch early 5.0 medium 2.6% 2012-01-29
CVE-2014-4163 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the Featured Comments plugin 1.2.1 for WordPress allow remote attackers to hijack the au… Patch early 6.8 medium 2.6% 2014-06-16
CVE-2014-2088 EXP Unrestricted file upload vulnerability in ilias.php in ILIAS 4.4.1 allows remote authenticated users to execute arbitrary PHP code by using a .php fil… Patch early 6.5 medium 2.6% 2014-03-02
CVE-2017-9979 EXP On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the invali… Patch early 6.1 medium 2.6% 2017-08-28
CVE-2021-31673 EXP A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitra… Patch early 6.1 medium 2.6% 2022-05-02
CVE-2002-1878 EXP PHP remote file inclusion vulnerability in w-Agora 4.1.3 allows remote attackers to execute arbitrary PHP code via the inc_dir parameter. Patch early 5.0 medium 2.6% 2002-12-31
CVE-2009-5103 EXP Cross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP allows remote attackers to inject arbitrary web script or HTML via the email var… Patch early 4.3 medium 2.6% 2011-10-21
CVE-2017-11823 EXP The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass by the way it… Patch early 6.7 medium 2.6% 2017-10-13
CVE-2023-3187 EXP A vulnerability, which was classified as critical, has been found in PHPGurukul Teachers Record Management System 1.0. Affected by this issue is some… Patch early 6.3 medium 2.6% 2023-06-09
CVE-2013-7247 EXP cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows remote attackers to discover… Patch early 5.0 medium 2.6% 2014-01-26
CVE-2017-6478 EXP paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter). Patch early 6.1 medium 2.6% 2017-03-05
CVE-2008-0843 EXP StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a direct request to admin.asp. Patch early 6.4 medium 2.6% 2008-02-20
CVE-2016-3652 EXP Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow rem… Patch early 5.4 medium 2.6% 2016-06-30
CVE-2003-1325 EXP The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows remote authenticated users to c… Patch early 5.2 medium 2.6% 2003-12-31
CVE-2008-3194 EXP Multiple directory traversal vulnerabilities in data/inc/themes/predefined_variables.php in pluck 4.5.1 allow remote attackers to include and execute… Patch early 6.8 medium 2.6% 2008-07-16
CVE-2012-6608 EXP Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 2.6% 2013-11-25
CVE-2016-1000124 EXP Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6 Patch early 9.8 critical 2.6% 2016-10-06
CVE-2005-4502 EXP Cross-site scripting (XSS) vulnerability in httprint v202, and possibly other versions before v301, allows remote attackers to inject arbitrary web sc… Patch early 4.3 medium 2.6% 2005-12-22
← previous page 271 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt