peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,373 CVEs 1,739 on KEV 17,299 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

171,272 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2001-0641 EXP Buffer overflow in man program in various distributions of Linux allows local user to execute arbitrary code as group man via a long -S option. Patch early 4.6 medium 1.3% 2001-09-20
CVE-2009-1337 EXP The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, w… Patch early 4.4 medium 1.3% 2009-04-22
CVE-2009-1451 EXP Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB 0.3.12 allows remote attackers to inject arbitrary web script or HTML via the PATH… Patch early 4.3 medium 1.3% 2009-04-28
CVE-2009-2153 EXP Cross-site scripting (XSS) vulnerability in index.php in Impleo Music Collection 2.0 allows remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 1.3% 2009-06-22
CVE-2007-1289 EXP SQL injection vulnerability in ViewBugs.php in Tyger Bug Tracking System (TygerBT) 1.1.3 allows remote attackers to execute arbitrary SQL commands via… Patch early 6.4 medium 1.3% 2007-03-07
CVE-2001-0595 EXP Buffer overflow in the kcsSUNWIOsolf.so library in Solaris 7 and 8 allows local attackers to execute arbitrary commands via the KCMS_PROFILES environm… Patch early 4.6 medium 1.3% 2001-08-02
CVE-2009-3256 EXP Cross-site scripting (XSS) vulnerability in include/ajax/blogInfo.php in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.3% 2009-09-18
CVE-2013-7376 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.10, possibly before revision 82710, allow remote attackers to hijack the authe… Patch early 6.8 medium 1.3% 2014-05-14
CVE-2015-4119 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication of (1) ad… Patch early 6.8 medium 1.3% 2015-06-15
CVE-2007-1159 EXP Cross-site scripting (XSS) vulnerability in modules/out.php in Pyrophobia 2.1.3.1 allows remote attackers to inject arbitrary web script or HTML via t… Patch early 4.3 medium 1.2% 2007-03-02
CVE-2002-0932 EXP SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activit… Patch early 6.4 medium 1.2% 2002-10-04
CVE-2012-4240 EXP SQL injection vulnerability in modules/calendar/json.php in Group-Office community before 4.0.90 allows remote authenticated users to execute arbitrar… Patch early 6.5 medium 1.2% 2014-09-11
CVE-2006-1572 EXP SQL injection vulnerability in post.php in Oxygen 1.1.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a newthread… Patch early 5.0 medium 1.2% 2006-04-01
CVE-2006-1419 EXP SQL injection vulnerability in the Calendar module in nuked-klan 1.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the m… Patch early 5.0 medium 1.2% 2006-03-28
CVE-2009-2178 EXP Cross-site scripting (XSS) vulnerability in website.php in phpDatingClub 3.7 allows remote attackers to inject arbitrary web script or HTML via the pa… Patch early 4.3 medium 1.2% 2009-06-23
CVE-2009-3348 EXP Cross-site scripting (XSS) vulnerability in Datavore Gyro 5.0 allows remote attackers to inject arbitrary web script or HTML via the cid parameter in… Patch early 4.3 medium 1.2% 2009-09-24
CVE-2009-3755 EXP Multiple cross-site scripting (XSS) vulnerabilities in phpBMS 0.96 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to… Patch early 4.3 medium 1.2% 2009-10-22
CVE-2009-4864 EXP Multiple cross-site scripting (XSS) vulnerabilities in escorts_search.php in I-Escorts Directory Script and Agency Script allow remote attackers to in… Patch early 4.3 medium 1.2% 2010-05-11
CVE-2006-5086 EXP Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with mo… Patch early 6.4 medium 1.2% 2006-09-29
CVE-2009-2424 EXP Cross-site scripting (XSS) vulnerability in search.php in Ebay Clone 2009 allows remote attackers to inject arbitrary web script or HTML via the mode… Patch early 4.3 medium 1.2% 2009-07-10
CVE-2014-4865 EXP Cross-site request forgery (CSRF) vulnerability in gui/password-wadmin.apl in CacheGuard OS 5.7.7 allows remote attackers to hijack the authentication… Patch early 6.8 medium 1.2% 2014-09-10
CVE-2024-11605 EXP The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, which could allow high privilege u… Patch early 4.8 medium 1.2% 2024-12-27
CVE-2012-1901 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in FlexCMS 3.2.1 and earlier allow remote attackers to (1) hijack the authentication of use… Patch early 6.8 medium 1.2% 2012-09-18
CVE-2009-0761 EXP Cross-site scripting (XSS) vulnerability in online.asp in Team Board 1.x allows remote attackers to inject arbitrary web script or HTML via the lookna… Patch early 4.3 medium 1.2% 2009-03-06
CVE-2020-8425 EXP Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php. Patch early 6.5 medium 1.2% 2020-01-28
CVE-2003-1445 EXP Stack-based buffer overflow in Far Manager 1.70beta1 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrar… Patch early 4.6 medium 1.2% 2003-12-31
CVE-2005-3566 EXP Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18… Patch early 4.3 medium 1.2% 2005-11-16
CVE-2011-5259 EXP SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM before 2.6.11.2 allows remote attackers to execute arbitrary SQL com… Patch early 6.8 medium 1.2% 2013-02-12
CVE-2019-10227 EXP openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component. Patch early 6.1 medium 1.2% 2019-12-31
CVE-2010-0709 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Limny 2.0 allow remote attackers to (1) hijack the authentication of users or administra… Patch early 6.8 medium 1.2% 2010-02-25
← previous page 312 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt