peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,247 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

171,177 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-4588 EXP Cross-site scripting (XSS) vulnerability in Koobi 5 allows remote attackers to inject arbitrary web script or HTML via nested, malformed url BBCode ta… Patch early 4.3 medium 1.4% 2005-12-30
CVE-2004-2288 EXP Cross-site scripting (XSS) vulnerability in index.php in Jelsoft vBulletin allows remote attackers to spoof parts of a website via the loc parameter. Patch early 4.3 medium 1.4% 2004-12-31
CVE-2006-1535 EXP Cross-site scripting (XSS) vulnerability in login.php in Phoetux.net PhxContacts 0.93.1 beta and earlier allows remote attackers to inject arbitrary w… Patch early 4.3 medium 1.4% 2006-03-30
CVE-2017-17752 EXP Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka… Patch early 6.1 medium 1.4% 2017-12-20
CVE-2014-0981 EXP VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4… Patch early 4.4 medium 1.4% 2014-03-31
CVE-2020-35687 EXP PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in vic… Patch early 4.3 medium 1.4% 2021-01-13
CVE-2006-6410 EXP Buffer overflow in an ActiveX control in VMWare 5.5.1 allows local users to execute arbitrary code via a long VmdbDb parameter to the Initialize funct… Patch early 4.6 medium 1.4% 2006-12-10
CVE-2006-1001 EXP SQL injection vulnerability in the board module in LanSuite LanParty Intranet System 2.0.6 and 2.1.0 beta allows remote attackers to execute arbitrary… Patch early 5.0 medium 1.4% 2006-03-06
CVE-2012-3872 EXP Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrary web script or HTML via (1) t… Patch early 4.3 medium 1.4% 2012-12-28
CVE-2023-1998 EXP The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which disables the speculation feature… Patch early 5.6 medium 1.4% 2023-04-21
CVE-2008-2087 EXP SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to e… Patch early 6.8 medium 1.4% 2008-05-06
CVE-2006-0903 EXP MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handl… Patch early 4.6 medium 1.4% 2006-02-27
CVE-2009-3805 EXP gpg2.exe in Gpg4win 2.0.1, as used in KDE Kleopatra 2.0.11, allows remote attackers to cause a denial of service (application crash) via a long certif… Patch early 4.3 medium 1.4% 2009-10-27
CVE-2013-4888 EXP Cross-site scripting (XSS) vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.4% 2014-01-29
CVE-2005-1076 EXP Cross-site scripting (XSS) vulnerability in the discussion board functionality for WebCT Campus Edition 4.1 allows remote attackers to inject arbitrar… Patch early 4.3 medium 1.4% 2005-05-02
CVE-2025-26263 EXP GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to credentials disclosure due to impr… Patch early 5.1 medium 1.4% 2025-02-28
CVE-2000-0338 EXP Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creatin… Patch early 5.5 medium 1.4% 2000-04-23
CVE-2014-2987 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition befor… Patch early 6.8 medium 1.4% 2014-10-26
CVE-2000-0987 EXP Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter. Patch early 4.6 medium 1.4% 2000-12-19
CVE-2009-1623 EXP Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary web script or HTML via the PI… Patch early 4.3 medium 1.4% 2009-05-12
CVE-2018-10507 EXP A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or render the OfficeScan Unauthor… Patch early 4.4 medium 1.4% 2018-06-12
CVE-2007-5923 EXP Cross-site scripting (XSS) vulnerability in forms/smpwservices.fcc in CA (formerly Computer Associates) eTrust SiteMinder Agent allows remote attacker… Patch early 4.3 medium 1.4% 2007-11-10
CVE-2017-7620 EXP MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpreta… Patch early 6.5 medium 1.4% 2017-05-21
CVE-2006-0455 EXP gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature fi… Patch early 4.6 medium 1.4% 2006-02-15
CVE-2013-6922 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attac… Patch early 6.8 medium 1.4% 2014-01-21
CVE-2008-3937 EXP Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web sc… Patch early 6.1 medium 1.4% 2008-09-05
CVE-2008-0787 EXP SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via t… Patch early 6.5 medium 1.4% 2008-02-15
CVE-2011-4806 EXP Multiple cross-site scripting (XSS) vulnerabilities in main.php in phpAlbum 0.4.1.16 and earlier allow remote attackers to inject arbitrary web script… Patch early 4.3 medium 1.4% 2011-12-14
CVE-2004-2102 EXP Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.4% 2004-12-31
CVE-2005-0889 EXP Cross-site scripting (XSS) vulnerability in index.php for Dream4 Koobi CMS 4.2.3 allows remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 1.4% 2005-03-24
← previous page 308 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt