CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,458 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-3502 EXP | The web server in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to obtain the source code of executable files via a request with a trail… | Patch early | 5.0 medium | 5.7% | 2011-09-16 |
| CVE-2004-0763 EXP | Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunloa… | Patch early | 5.0 medium | 5.7% | 2004-08-18 |
| CVE-2005-1507 EXP | Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute arbitrary co… | Patch early | 5.0 medium | 5.7% | 2005-05-11 |
| CVE-2005-1403 EXP | Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to inject arbitrary web script or… | Patch early | 6.8 medium | 5.7% | 2005-05-03 |
| CVE-2012-0200 EXP | The server in IBM solidDB 6.5 before Interim Fix 6 does not properly initialize data structures, which allows remote authenticated users to cause a de… | Patch early | 4.0 medium | 5.7% | 2012-02-21 |
| CVE-2022-0448 EXP | The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform… | Patch early | 4.8 medium | 5.7% | 2022-03-07 |
| CVE-2005-1013 EXP | The SMTP service in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to cause a denial of service (ser… | Patch early | 5.0 medium | 5.7% | 2005-05-02 |
| CVE-2021-24245 EXP | The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an… | Patch early | 6.1 medium | 5.7% | 2021-05-06 |
| CVE-2008-1702 EXP | Absolute path traversal vulnerability in dload.php in the my_gallery 2.3 plugin for e107 allows remote attackers to obtain sensitive information via a… | Patch early | 4.3 medium | 5.7% | 2008-04-08 |
| CVE-2020-12352 EXP | Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access. | Patch early | 6.5 medium | 5.7% | 2020-11-23 |
| CVE-2006-5418 EXP | PHP remote file inclusion vulnerability in archive/archive_topic.php in pbpbb archive for search engines (SearchIndexer) (aka phpBBSEI) for phpBB allo… | Patch early | 6.8 medium | 5.7% | 2006-10-20 |
| CVE-2010-4647 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remot… | Patch early | 4.3 medium | 5.7% | 2011-01-13 |
| CVE-2001-0491 EXP | Directory traversal vulnerability in RaidenFTPD Server 2.1 before build 952 allows attackers to access files outside the ftp root via dot dot attacks,… | Patch early | 5.0 medium | 5.7% | 2001-06-27 |
| CVE-2008-0239 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote attackers to in… | Patch early | 4.3 medium | 5.7% | 2008-01-11 |
| CVE-2006-4074 EXP | PHP remote file inclusion vulnerability in lib/tpl/default/main.php in the JD-Wiki Component (com_jd-wiki) 1.0.2 and earlier for Joomla!, when registe… | Patch early | 6.8 medium | 5.7% | 2006-08-11 |
| CVE-2007-6558 EXP | TotalPlayer 3.0 allows user-assisted remote attackers to cause a denial of service (application crash) via a large .m3u file. NOTE: this might be a d… | Patch early | 4.3 medium | 5.7% | 2007-12-28 |
| CVE-2008-1353 EXP | zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum comman… | Patch early | 4.3 medium | 5.7% | 2008-03-17 |
| CVE-2014-0871 EXP | RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to obtain potentially s… | Patch early | 4.3 medium | 5.7% | 2014-07-07 |
| CVE-2006-0663 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 5.7% | 2006-02-13 |
| CVE-2010-2920 EXP | Directory traversal vulnerability in the Foobla Suggestions (com_foobla_suggestions) component 1.5.1.2 for Joomla! allows remote attackers to read arb… | Patch early | 6.8 medium | 5.7% | 2010-07-30 |
| CVE-2004-2449 EXP | Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial of service (application crash)… | Patch early | 5.0 medium | 5.7% | 2004-12-31 |
| CVE-2014-6047 EXP | phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an a… | Patch early | 5.3 medium | 5.7% | 2018-08-28 |
| CVE-2014-6048 EXP | phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request. | Patch early | 5.3 medium | 5.7% | 2018-08-28 |
| CVE-2007-0059 EXP | Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem c… | Patch early | 6.8 medium | 5.7% | 2007-01-05 |
| CVE-2008-2304 EXP | Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows user-assisted attackers to execut… | Patch early | 6.8 medium | 5.7% | 2008-07-14 |
| CVE-2002-0926 EXP | Directory traversal vulnerability in Wolfram Research webMathematica 1.0.0 and 1.0.0.1 allows remote attackers to read arbitrary files via a .. (dot d… | Patch early | 5.0 medium | 5.7% | 2002-10-04 |
| CVE-2003-0153 EXP | bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.cgi, (2) cvsview2.cgi, or (3)… | Patch early | 5.0 medium | 5.7% | 2003-04-02 |
| CVE-2019-9213 EXP | In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to e… | Patch early | 5.5 medium | 5.7% | 2019-03-05 |
| CVE-2019-8924 EXP | XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued. | Patch early | 6.1 medium | 5.7% | 2019-05-17 |
| CVE-2007-6478 EXP | Stack-based buffer overflow in Rosoft Media Player 4.1.7, 4.1.8, and possibly earlier versions allows remote attackers to execute arbitrary code or ca… | Patch early | 6.8 medium | 5.7% | 2007-12-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt