CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,092 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-2653 EXP | security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote attackers to conduct phishing… | Patch early | 5.8 medium | 4.1% | 2013-11-13 |
| CVE-2009-3219 EXP | Directory traversal vulnerability in a.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to include… | Patch early | 6.8 medium | 4.1% | 2009-09-16 |
| CVE-2009-3534 EXP | Directory traversal vulnerability in index.php in LionWiki 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files v… | Patch early | 6.8 medium | 4.1% | 2009-10-02 |
| CVE-2010-2138 EXP | Multiple directory traversal vulnerabilities in ProMan 0.1.1 and earlier allow remote attackers to include and execute arbitrary local files via direc… | Patch early | 6.8 medium | 4.1% | 2010-06-02 |
| CVE-2006-4838 EXP | Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) roo… | Patch early | 4.3 medium | 4.1% | 2006-09-15 |
| CVE-2006-2019 EXP | Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a denial of service (CPU consumption and crash) via a… | Patch early | 5.0 medium | 4.1% | 2006-04-25 |
| CVE-2017-9869 EXP | The II_step_one function in layer2.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denia… | Patch early | 5.5 medium | 4.1% | 2017-06-25 |
| CVE-2009-0079 EXP | The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct proces… | Patch early | 6.9 medium | 4.1% | 2009-04-15 |
| CVE-2006-5019 EXP | Google Mini 4.4.102.M.36 and earlier allows remote attackers to obtain sensitive information via a direct request for /search with an invalid client p… | Patch early | 5.0 medium | 4.1% | 2006-09-27 |
| CVE-2008-6670 EXP | Integer overflow in Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted packet to UDP port 27… | Patch early | 5.0 medium | 4.1% | 2009-04-08 |
| CVE-2005-2192 EXP | SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords… | Patch early | 5.0 medium | 4.1% | 2005-07-11 |
| CVE-2008-7123 EXP | Static code injection vulnerability in admin/configuration/modifier.php in zKup CMS 2.0 through 2.3 allows remote attackers to inject arbitrary PHP co… | Patch early | 6.8 medium | 4.1% | 2009-08-31 |
| CVE-2006-5320 EXP | Directory traversal vulnerability in getimg.php in Album Photo Sans Nom 1.6 allows remote attackers to read arbitrary files via the img parameter. | Patch early | 5.0 medium | 4.1% | 2006-10-17 |
| CVE-2008-6619 EXP | Unrestricted file upload vulnerability in class/ApplyDB.php in ClassSystem 2.3 allows remote attackers to execute arbitrary code by uploading a file w… | Patch early | 6.8 medium | 4.1% | 2009-04-06 |
| CVE-2001-0740 EXP | 3COM OfficeConnect 812 and 840 ADSL Router 4.2, running OCR812 router software 1.1.9 and earlier, allows remote attackers to cause a denial of service… | Patch early | 5.0 medium | 4.1% | 2001-10-18 |
| CVE-2007-3703 EXP | Stack-based buffer overflow in a certain ActiveX control in sasatl.dll 1.5.0.531 in Zenturi Program Checker (ProgramChecker) Pro allows remote attacke… | Patch early | 6.8 medium | 4.1% | 2007-07-11 |
| CVE-2006-2046 EXP | Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote attackers to execute arbitrary S… | Patch early | 6.4 medium | 4% | 2006-04-26 |
| CVE-2007-1167 EXP | inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and earlier allows remote attackers to obtain MySQL data via the inc/mysql.php value of… | Patch early | 5.0 medium | 4% | 2007-03-02 |
| CVE-2004-1420 EXP | Multiple cross-site scripting (XSS) vulnerabilities in header.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 4% | 2004-12-31 |
| CVE-2023-23408 EXP | Azure Apache Ambari Spoofing Vulnerability | Patch early | 4.5 medium | 4% | 2023-03-14 |
| CVE-2009-1554 EXP | Cross-site scripting (XSS) vulnerability in ThemeServlet.java in Sun Woodstock 4.2, as used in Sun GlassFish Enterprise Server and other products, all… | Patch early | 4.3 medium | 4% | 2009-05-06 |
| CVE-2012-6522 EXP | Directory traversal vulnerability in the getContent function in codes/wcms.php in w-CMS 2.01 allows remote attackers to read arbitrary files via a ..… | Patch early | 5.0 medium | 4% | 2013-01-31 |
| CVE-2004-1384 EXP | Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 4% | 2004-12-31 |
| CVE-2009-3566 EXP | McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identi… | Patch early | 4.3 medium | 4% | 2009-11-13 |
| CVE-2021-26078 EXP | The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from vers… | Patch early | 6.1 medium | 4% | 2021-06-07 |
| CVE-2005-0791 EXP | Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers to inject ar… | Patch early | 4.3 medium | 4% | 2005-03-14 |
| CVE-2018-16061 EXP | Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php. | Patch early | 6.1 medium | 4% | 2021-10-15 |
| CVE-2004-1882 EXP | Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 4% | 2004-12-31 |
| CVE-2017-15284 EXP | Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code as… | Patch early | 5.4 medium | 4% | 2017-10-12 |
| CVE-2006-5762 EXP | PHP remote file inclusion vulnerability in forgot_pass.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 5.1 medium | 4% | 2006-11-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt