peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,169 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

208,192 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-29727 EXP Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter. Patch early 5.4 medium 2.4% 2022-05-11
CVE-2006-6941 EXP index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to obtain sensitive information via an invalid action parameter in an info operatio… Patch early 5.0 medium 2.4% 2007-01-19
CVE-2009-2181 EXP Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attackers to inject arbitrary web s… Patch early 4.3 medium 2.4% 2009-06-23
CVE-2012-4237 EXP Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to execute arbit… Patch early 6.8 medium 2.4% 2012-08-20
CVE-2007-3613 EXP Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attackers to inject arbitrary web scri… Patch early 4.3 medium 2.4% 2007-07-06
CVE-2005-4880 EXP Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain I… Patch early 5.0 medium 2.4% 2009-03-31
CVE-2012-2588 EXP Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 2.4% 2014-09-19
CVE-2008-3770 EXP Multiple directory traversal vulnerabilities in Freeway 1.4.1.171, when register_globals is enabled, allow remote attackers to include and execute arb… Patch early 6.8 medium 2.4% 2008-08-22
CVE-2006-5830 EXP Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to inject arbitrary… Patch early 6.8 medium 2.4% 2006-11-10
CVE-2006-1568 EXP Multiple cross-site scripting (XSS) vulnerabilities in register.php in RedCMS 0.1 allow remote attackers to inject arbitrary web script or HTML via th… Patch early 5.1 medium 2.4% 2006-04-01
CVE-2009-2116 EXP Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to list directory contents via a .… Patch early 4.0 medium 2.4% 2009-06-18
CVE-2008-2352 EXP Directory traversal vulnerability in index.php in Smeego 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitr… Patch early 6.8 medium 2.4% 2008-05-20
CVE-2008-5570 EXP Directory traversal vulnerability in index.php in PHP Multiple Newsletters 2.7, when magic_quotes_gpc is disabled, allows remote attackers to include… Patch early 6.8 medium 2.4% 2008-12-15
CVE-2008-5604 EXP Directory traversal vulnerability in index.php in My Simple Forum 3.0 and 4.1, when magic_quotes_gpc is disabled, allows remote attackers to include a… Patch early 6.8 medium 2.4% 2008-12-16
CVE-2007-0301 EXP PHP remote file inclusion vulnerability in _admin/admin_menu.php in FdWeB Espace Membre 2.1 and earlier allows remote attackers to execute arbitrary P… Patch early 6.8 medium 2.4% 2007-01-18
CVE-2012-4262 EXP Multiple cross-site scripting (XSS) vulnerabilities in myCare2x allow remote attackers to inject arbitrary web script or HTML via the (1) name_last, (… Patch early 4.3 medium 2.4% 2012-08-13
CVE-2007-4115 EXP Multiple cross-site scripting (XSS) vulnerabilities in IT!CMS (itcms) 0.2 allow remote attackers to inject arbitrary web script or HTML via the wndtit… Patch early 4.3 medium 2.4% 2007-07-31
CVE-2010-1497 EXP Cross-site scripting (XSS) vulnerability in download_proc.php in dl_stats before 2.0 allows remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 2.4% 2010-04-23
CVE-2025-54589 EXP Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results usin… Patch early 6.3 medium 2.4% 2025-07-31
CVE-2002-2134 EXP haut.php in PEEL 1.0b allows remote attackers to execute arbitrary PHP code by modifying the dirroot parameter to reference a URL on a remote web serv… Patch early 5.0 medium 2.4% 2002-12-31
CVE-2002-2169 EXP Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activ… Patch early 5.0 medium 2.4% 2002-12-31
CVE-2007-5314 EXP PHP remote file inclusion vulnerability in system/funcs/xkurl.php in xKiosk WEB 3.0.1i, when register_globals is enabled, allows remote attackers to e… Patch early 6.8 medium 2.4% 2007-10-09
CVE-2010-1216 EXP PHP remote file inclusion vulnerability in templates/template.php in notsoPureEdit 1.4.1 and earlier, when register_globals is enabled, allows remote… Patch early 6.8 medium 2.4% 2010-03-30
CVE-2007-3681 EXP The IOCTL 9031 (BIOCGSTATS) handler in the NPF.SYS device driver in WinPcap before 4.0.1 allows local users to overwrite memory and execute arbitrary… Patch early 6.6 medium 2.4% 2007-07-11
CVE-2006-5625 EXP PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Management System (WCMS) 4.1 and earli… Patch early 5.1 medium 2.4% 2006-10-31
CVE-2005-1597 EXP Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers… Patch early 4.3 medium 2.4% 2005-05-16
CVE-2012-5350 EXP SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with certain permissions to execut… Patch early 6.0 medium 2.4% 2012-10-09
CVE-2003-0376 EXP Buffer overflow in Eudora 5.2.1 allows remote attackers to cause a denial of service (crash and failed restart) and possibly execute arbitrary code vi… Patch early 5.0 medium 2.4% 2003-06-16
CVE-2006-6756 EXP The code function in install.fct.php in Ixprim 1.2 produces a guessable value of the confidential IXP_CODE in mainfile.php, which might allow remote a… Patch early 5.1 medium 2.4% 2006-12-27
CVE-2003-1535 EXP Justice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the path in an er… Patch early 5.0 medium 2.4% 2003-12-31
← previous page 281 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt