CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,955 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-4814 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 5.5% | 2011-12-14 |
| CVE-2002-0770 EXP | Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server… | Patch early | 5.0 medium | 5.5% | 2002-08-12 |
| CVE-2007-5821 EXP | Multiple directory traversal vulnerabilities in DM Guestbook 0.4.1 and earlier allow remote attackers to include and execute arbitrary local files via… | Patch early | 6.8 medium | 5.5% | 2007-11-05 |
| CVE-1999-0441 EXP | Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service. | Patch early | 5.0 medium | 5.5% | 1999-02-22 |
| CVE-1999-1113 EXP | Buffer overflow in Eudora Internet Mail Server (EIMS) 2.01 and earlier on MacOS systems allows remote attackers to cause a denial of service via a lon… | Patch early | 5.0 medium | 5.5% | 1998-04-14 |
| CVE-2020-5191 EXP | PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities. | Patch early | 6.1 medium | 5.5% | 2020-01-06 |
| CVE-2012-5991 EXP | screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to cause a… | Patch early | 6.3 medium | 5.5% | 2012-12-19 |
| CVE-2017-11663 EXP | The _WM_SetupMidiEvent function in internal_midi.c:2315 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) vi… | Patch early | 6.5 medium | 5.5% | 2017-08-17 |
| CVE-2020-16171 EXP | An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/ accept an additional custom S… | Patch early | 6.5 medium | 5.5% | 2020-09-21 |
| CVE-2015-2841 EXP | Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type h… | Patch early | 5.0 medium | 5.5% | 2015-04-03 |
| CVE-2010-4401 EXP | languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path… | Patch early | 5.0 medium | 5.5% | 2010-12-06 |
| CVE-2021-24299 EXP | The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservatio… | Patch early | 6.1 medium | 5.5% | 2021-05-17 |
| CVE-2009-4168 EXP | Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module… | Patch early | 4.3 medium | 5.5% | 2009-12-02 |
| CVE-2013-1942 EXP | Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.20, as u… | Patch early | 4.3 medium | 5.5% | 2013-08-15 |
| CVE-2000-0152 EXP | Remote attackers can cause a denial of service in Novell BorderManager 3.5 by pressing the enter key in a telnet connection to port 2000. | Patch early | 5.0 medium | 5.5% | 2000-03-30 |
| CVE-2014-0866 EXP | RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext credentials over HTTP, which al… | Patch early | 4.3 medium | 5.5% | 2014-07-07 |
| CVE-2014-0869 EXP | The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics does not require a key,… | Patch early | 4.3 medium | 5.5% | 2014-07-07 |
| CVE-2013-3240 EXP | Directory traversal vulnerability in the Export feature in phpMyAdmin 4.x before 4.0.0-rc3 allows remote authenticated users to read arbitrary files o… | Patch early | 6.5 medium | 5.5% | 2013-04-26 |
| CVE-2008-3158 EXP | Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possibly related to IOCTL requests… | Patch early | 6.9 medium | 5.5% | 2008-07-11 |
| CVE-2009-0260 EXP | Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 5.5% | 2009-01-23 |
| CVE-2017-18016 EXP | Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting other websit… | Patch early | 5.3 medium | 5.5% | 2018-01-11 |
| CVE-2009-4511 EXP | Multiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before X5.1 allow re… | Patch early | 4.0 medium | 5.5% | 2010-04-13 |
| CVE-2011-3010 EXP | Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the ne… | Patch early | 4.3 medium | 5.5% | 2011-09-30 |
| CVE-2009-1232 EXP | Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption) via an XML document composed… | Patch early | 4.3 medium | 5.5% | 2009-04-02 |
| CVE-2006-1595 EXP | Cross-site scripting (XSS) vulnerability in document/rqmkhtml.php in Claroline 1.7.4 and earlier allows remote attackers to read arbitrary files via "… | Patch early | 4.3 medium | 5.5% | 2006-04-03 |
| CVE-2006-0841 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Mantis 1.00rc4 and earlier allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 5.5% | 2006-02-22 |
| CVE-2014-1564 EXP | Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which… | Patch early | 4.3 medium | 5.5% | 2014-09-03 |
| CVE-2011-4802 EXP | Multiple SQL injection vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote authenticated users to execute arbitrary SQL commands vi… | Patch early | 6.5 medium | 5.5% | 2011-12-14 |
| CVE-2013-4949 EXP | Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then a… | Patch early | 6.8 medium | 5.5% | 2013-07-29 |
| CVE-2013-5961 EXP | Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code… | Patch early | 6.8 medium | 5.5% | 2013-09-30 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt