CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,045 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-4684 EXP | Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated users to re… | Patch early | 6.5 medium | 4.9% | 2017-09-19 |
| CVE-2004-2078 EXP | Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss of logged events) via a long re… | Patch early | 5.0 medium | 4.9% | 2004-02-09 |
| CVE-2019-6780 EXP | The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPostFilter.php omits noopener and… | Patch early | 6.1 medium | 4.9% | 2019-01-24 |
| CVE-1999-0173 EXP | FormMail CGI program can be used by web servers other than the host server that the program resides on. | Patch early | 5.0 medium | 4.9% | 1997-01-01 |
| CVE-2014-8305 EXP | Open redirect vulnerability in the redir function in includes/function.php in C97net Cart Engine before 4.0 allows remote attackers to redirect users… | Patch early | 6.4 medium | 4.9% | 2014-10-16 |
| CVE-2000-0645 EXP | WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file… | Patch early | 6.4 medium | 4.9% | 2000-07-21 |
| CVE-2004-1705 EXP | Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username. | Patch early | 5.0 medium | 4.9% | 2004-07-30 |
| CVE-2011-0507 EXP | FTPService.exe in Blackmoon FTP 3.1 Build 1735 and Build 1736 (3.1.7.1736), and possibly other versions before 3.1.8.1737, allows remote attackers to… | Patch early | 4.3 medium | 4.9% | 2011-01-20 |
| CVE-2017-9125 EXP | The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-… | Patch early | 6.5 medium | 4.9% | 2017-06-12 |
| CVE-2012-0241 EXP | Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to a… | Patch early | 5.0 medium | 4.9% | 2012-02-21 |
| CVE-2007-5300 EXP | Off-by-one error in the do_login_loop function in libwzd-core/wzd_login.c in wzdftpd 0.8.0, 0.8.2, and possibly other versions allows remote attackers… | Patch early | 5.0 medium | 4.9% | 2007-10-09 |
| CVE-2006-4553 EXP | PHP remote file inclusion vulnerability in plugin.class.php in the com_comprofiler Components 1.0 RC2 for Mambo and Joomla! allows remote attackers to… | Patch early | 6.8 medium | 4.9% | 2006-09-06 |
| CVE-2007-5229 EXP | Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attackers to change settings and hi… | Patch early | 6.4 medium | 4.9% | 2007-10-05 |
| CVE-2013-6114 EXP | Integer overflow in the OZDocument::parseElement function in Apple Motion 5.0.7 allows remote attackers to cause a denial of service (application cras… | Patch early | 5.0 medium | 4.9% | 2013-11-04 |
| CVE-2014-1695 EXP | Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.1.x before 3.1.20, 3.2.x before 3.2.15, and 3.3.x before 3.3.5 allows… | Patch early | 4.3 medium | 4.9% | 2014-03-01 |
| CVE-2008-5288 EXP | PHP remote file inclusion vulnerability in include/header.php in Werner Hilversum FAQ Manager 1.2, when register_globals is enabled, allows remote att… | Patch early | 6.8 medium | 4.9% | 2008-12-01 |
| CVE-1999-1171 EXP | IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920. | Patch early | 4.6 medium | 4.9% | 1999-02-02 |
| CVE-2015-2321 EXP | Cross-site scripting (XSS) vulnerability in the Job Manager plugin 0.7.22 and earlier for WordPress allows remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 4.9% | 2015-08-13 |
| CVE-2008-4725 EXP | Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web script or HTML via the query strin… | Patch early | 4.3 medium | 4.9% | 2008-10-23 |
| CVE-2014-5347 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress allow remote attackers to hij… | Patch early | 6.8 medium | 4.9% | 2014-08-19 |
| CVE-1999-0193 EXP | Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option. | Patch early | 5.0 medium | 4.9% | 1997-12-01 |
| CVE-2008-1974 EXP | Cross-site scripting (XSS) vulnerability in addevent.php in Horde Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and Groupware 1.0.5 allows remote… | Patch early | 4.3 medium | 4.9% | 2008-04-27 |
| CVE-2006-0625 EXP | Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier allows remote attackers to read or include arbitrary files via ".." sequ… | Patch early | 6.4 medium | 4.9% | 2006-02-09 |
| CVE-2009-2174 EXP | GUPnP 0.12.7 allows remote attackers to cause a denial of service (crash) via an empty (1) subscription or (2) control message. | Patch early | 5.0 medium | 4.9% | 2009-06-23 |
| CVE-2006-4608 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to inject arbitrary web script or HTML… | Patch early | 6.8 medium | 4.9% | 2006-09-07 |
| CVE-2006-4794 EXP | Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the query string (… | Patch early | 4.3 medium | 4.9% | 2006-09-14 |
| CVE-2007-2576 EXP | Buffer overflow in the East Wind Software advdaudio.ocx 1.5.1.1 ActiveX control allows user-assisted remote attackers to execute arbitrary code via a… | Patch early | 6.8 medium | 4.9% | 2007-05-09 |
| CVE-2017-8490 EXP | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… | Patch early | 5.0 medium | 4.9% | 2017-06-15 |
| CVE-2002-1060 EXP | Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway 2.1.02, and… | Patch early | 4.3 medium | 4.9% | 2002-10-04 |
| CVE-2013-4092 EXP | The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent attackers to obtain sensitive inf… | Patch early | 5.0 medium | 4.9% | 2013-06-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt