peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,146 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

208,173 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-6512 EXP SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows remote attackers to execute ar… Patch early 5.0 medium 2.5% 2015-08-18
CVE-2002-2336 EXP Norton Personal Firewall 2002 4.0, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of… Patch early 4.3 medium 2.5% 2002-12-31
CVE-2007-5017 EXP Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.1.0.421 allows remote attacker… Patch early 5.0 medium 2.5% 2007-09-20
CVE-2006-7114 EXP P-News 2.0 stores db/user.txt under the web document root with insufficient access control, which allows remote attackers to obtain sensitive informat… Patch early 5.0 medium 2.5% 2007-03-06
CVE-2005-0344 EXP Directory traversal vulnerability in 602LAN SUITE 2004.0.04.1221 allows remote authenticated users to upload and execute arbitrary files via a .. (dot… Patch early 5.0 medium 2.5% 2005-05-02
CVE-2004-0740 EXP The HTTP server in Lexmark T522 and possibly other models allows remote attackers to cause a denial of service (server crash, reload, or hang) via an… Patch early 5.0 medium 2.5% 2004-07-27
CVE-2026-32746 EXP telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does n… Patch early 9.8 critical 2.5% 2026-03-13
CVE-2004-0820 EXP Winamp before 5.0.4 allows remote attackers to execute arbitrary script in the Local computer zone via script in HTML files that are referenced from X… Patch early 4.6 medium 2.5% 2004-08-28
CVE-2008-2116 EXP Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to read arbitrary local files via… Patch early 4.4 medium 2.5% 2008-05-08
CVE-2008-7154 EXP Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/class.conf_fw.php, (2) class.modu… Patch early 5.0 medium 2.5% 2009-09-02
CVE-2000-0734 EXP eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections. Patch early 5.0 medium 2.5% 2000-10-20
CVE-2004-2038 EXP Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a… Patch early 4.3 medium 2.5% 2004-05-29
CVE-2006-1127 EXP Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-F… Patch early 4.3 medium 2.5% 2006-03-09
CVE-2012-5242 EXP Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary… Patch early 6.8 medium 2.5% 2014-10-21
CVE-2023-25440 EXP Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/s… Patch early 5.4 medium 2.5% 2023-05-23
CVE-2007-1898 EXP formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and… Patch early 5.8 medium 2.5% 2007-05-16
CVE-2011-1665 EXP PHPBoost 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain backup SQL file… Patch early 5.0 medium 2.5% 2011-04-10
CVE-2021-25791 EXP Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated… Patch early 5.4 medium 2.5% 2021-07-23
CVE-2008-5853 EXP Chilek Content Management System (aka ChiCoMaS) 2.0.4 and earlier stores sensitive information under the web root with insufficient access control, wh… Patch early 5.0 medium 2.5% 2009-01-06
CVE-2010-0978 EXP KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to do… Patch early 5.0 medium 2.5% 2010-03-16
CVE-2012-2099 EXP Multiple cross-site scripting (XSS) vulnerabilities in Wikidforum 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) searc… Patch early 4.3 medium 2.5% 2013-01-24
CVE-2008-7024 EXP admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator privileges by s… Patch early 6.8 medium 2.5% 2009-08-21
CVE-2003-0303 EXP SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via… Patch early 5.0 medium 2.5% 2003-06-09
CVE-2022-35155 EXP Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter. Patch early 6.1 medium 2.5% 2022-09-30
CVE-2005-0251 EXP Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to inject arbitrary… Patch early 4.3 medium 2.5% 2005-05-02
CVE-2009-0253 EXP Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the… Patch early 6.8 medium 2.5% 2009-01-22
CVE-2007-6499 EXP Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage extensions of… Patch early 5.5 medium 2.5% 2007-12-20
CVE-2007-5026 EXP dBlog CMS, probably 2.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a… Patch early 5.0 medium 2.5% 2007-09-21
CVE-2006-7099 EXP Directory traversal vulnerability in index.php in SolarPay allows remote attackers to read certain files via a .. (dot dot) in the read parameter. NO… Patch early 5.0 medium 2.5% 2007-03-03
CVE-2000-0418 EXP The Cayman 3220-H DSL router allows remote attackers to cause a denial of service via oversized ICMP echo (ping) requests. Patch early 5.0 medium 2.5% 2000-05-23
← previous page 272 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt