CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,014 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-2587 EXP | Buffer overflow in the WebTool HTTP server component in (1) PunkBuster before 1.229, as used by multiple products including (2) America's Army 1.228 a… | Patch early | 5.0 medium | 5.1% | 2006-05-25 |
| CVE-2005-4196 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 5.1% | 2005-12-13 |
| CVE-2006-1101 EXP | The (1) sgetstr and (2) getint functions in Sauerbraten 2006_02_28, as derived from the Cube engine, allow remote attackers to cause a denial of servi… | Patch early | 5.0 medium | 5.1% | 2006-03-09 |
| CVE-2016-0073 EXP | The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain p… | Patch early | 5.0 medium | 5.1% | 2016-10-14 |
| CVE-2007-2431 EXP | Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote attackers to conduct cross-site… | Patch early | 6.8 medium | 5.1% | 2007-05-02 |
| CVE-2012-5105 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.4 allow remote attackers to inject arbitrary web script or HTML via the dbsel… | Patch early | 4.3 medium | 5.1% | 2012-09-23 |
| CVE-2015-8368 EXP | ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parame… | Patch early | 6.0 medium | 5.1% | 2015-12-17 |
| CVE-2023-29983 EXP | Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary code via the auditlog tab in the… | Patch early | 5.4 medium | 5.1% | 2023-05-12 |
| CVE-2006-4455 EXP | Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via unspecified vectors involving th… | Patch early | 5.0 medium | 5.1% | 2006-08-30 |
| CVE-2017-9127 EXP | The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buff… | Patch early | 6.5 medium | 5.1% | 2017-06-12 |
| CVE-2005-2869 EXP | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) t… | Patch early | 4.3 medium | 5.1% | 2005-09-08 |
| CVE-2010-1226 EXP | The HTTP client functionality in Apple iPhone OS 3.1 on the iPhone 2G and 3.1.3 on the iPhone 3GS allows remote attackers to cause a denial of service… | Patch early | 5.0 medium | 5.1% | 2010-04-01 |
| CVE-2007-1050 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 5.1% | 2007-02-21 |
| CVE-2005-1030 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary web script or HTML via the (1)… | Patch early | 4.3 medium | 5.1% | 2005-05-02 |
| CVE-2007-2189 EXP | PHP remote file inclusion vulnerability in admin/admin_album_otf.php in the MX Smartor Full Album Pack (FAP) 2.0 RC1 module for mxBB allows remote att… | Patch early | 6.8 medium | 5.1% | 2007-04-24 |
| CVE-2008-0068 EXP | Directory traversal vulnerability in OpenView5.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to read a… | Patch early | 5.0 medium | 5.1% | 2008-04-16 |
| CVE-2001-0390 EXP | IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0… | Patch early | 5.0 medium | 5.1% | 2001-07-02 |
| CVE-2001-0688 EXP | Broker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or CWD ("CD . .") command. | Patch early | 5.0 medium | 5.1% | 2001-09-20 |
| CVE-2009-4171 EXP | An ActiveX control in YahooBridgeLib.dll for Yahoo! Messenger 9.0.0.2162, and possibly other 9.0 versions, allows remote attackers to cause a denial o… | Patch early | 4.3 medium | 5.1% | 2009-12-02 |
| CVE-2012-2104 EXP | cgi-bin/munin-cgi-graph in Munin 2.x writes data to a log file without sanitizing non-printable characters, which might allow user-assisted remote att… | Patch early | 6.8 medium | 5.1% | 2012-08-26 |
| CVE-2005-3818 EXP | Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1… | Patch early | 4.3 medium | 5.1% | 2005-11-26 |
| CVE-2005-2804 EXP | Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers to cause a denial of service (… | Patch early | 5.0 medium | 5.1% | 2005-10-04 |
| CVE-2007-5693 EXP | Eval injection vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to execute arbitrary PHP co… | Patch early | 6.0 medium | 5.1% | 2007-10-29 |
| CVE-2011-1547 EXP | Multiple stack consumption vulnerabilities in the kernel in NetBSD 4.0, 5.0 before 5.0.3, and 5.1 before 5.1.1, when IPsec is enabled, allow remote at… | Patch early | 6.8 medium | 5.1% | 2011-05-09 |
| CVE-2012-5452 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) mul… | Patch early | 4.3 medium | 5.1% | 2012-10-22 |
| CVE-2021-27889 EXP | Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages. | Patch early | 6.1 medium | 5.1% | 2021-03-15 |
| CVE-2008-0192 EXP | Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 5.1% | 2008-01-10 |
| CVE-2013-4883 EXP | Multiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePO Extension for the McAfee Agent (MA)… | Patch early | 4.3 medium | 5.1% | 2013-07-22 |
| CVE-2014-0867 EXP | rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote atta… | Patch early | 5.8 medium | 5.1% | 2014-07-07 |
| CVE-1999-0269 EXP | Netscape Enterprise servers may list files through the PageServices query. | Patch early | 5.0 medium | 5.1% | 1998-08-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt