CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,121 CVEs
1,733 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2001-1045 EXP | Directory traversal vulnerability in basilix.php3 in Basilix Webmail 1.0.3beta and earlier allows remote attackers to read arbitrary files via a .. (d… | Patch early | 5.0 medium | 3.8% | 2001-07-06 |
| CVE-2006-7222 EXP | Buffer overflow in the CFLICStream::_deltachunk function in FLICSource.cpp in Media Player Classic (MPC) 6.4.9.0 allows user-assisted remote attackers… | Patch early | 6.8 medium | 3.8% | 2007-08-28 |
| CVE-2002-2359 EXP | Cross-site scripting (XSS) vulnerability in the FTP view feature in Mozilla 1.0 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 3.8% | 2002-12-31 |
| CVE-2013-0192 EXP | File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config. | Patch early | 4.9 medium | 3.8% | 2020-02-07 |
| CVE-2015-5066 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 3.8% | 2015-06-24 |
| CVE-2006-2241 EXP | PHP remote file inclusion vulnerability in show.php in Fast Click SQL Lite 1.1.3 and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 6.4 medium | 3.8% | 2006-05-09 |
| CVE-2006-2393 EXP | The client_cmd function in Empire 4.3.2 and earlier allows remote attackers to cause a denial of service (application crash) by causing long text stri… | Patch early | 5.0 medium | 3.8% | 2006-05-16 |
| CVE-2020-15038 EXP | The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS. | Patch early | 5.4 medium | 3.8% | 2020-06-24 |
| CVE-2001-0463 EXP | Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter. | Patch early | 5.0 medium | 3.8% | 2001-06-27 |
| CVE-2001-0467 EXP | Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a \... (modified dot… | Patch early | 5.0 medium | 3.8% | 2001-06-27 |
| CVE-2002-0946 EXP | Directory traversal vulnerability in SeaNox Devwex before 1.2002.0601 allows remote attackers to read arbitrary files via ..\ (dot dot) sequences in a… | Patch early | 5.0 medium | 3.8% | 2002-10-04 |
| CVE-2012-2913 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Leaflet plugin 0.0.1 for WordPress allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 3.8% | 2012-05-21 |
| CVE-2013-7190 EXP | Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitrary files via the (1) tmpid pa… | Patch early | 5.0 medium | 3.8% | 2013-12-20 |
| CVE-2007-5304 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) r… | Patch early | 4.3 medium | 3.8% | 2007-10-09 |
| CVE-2007-3607 EXP | Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) v… | Patch early | 5.0 medium | 3.8% | 2007-07-06 |
| CVE-2014-8800 EXP | Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before 1.5.1 for WordPress allows rem… | Patch early | 4.3 medium | 3.8% | 2014-12-05 |
| CVE-2012-3830 EXP | Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.3 allows remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 3.8% | 2012-07-03 |
| CVE-2012-6624 EXP | Cross-site scripting (XSS) vulnerability in the SoundCloud Is Gold plugin 2.1 for WordPress allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 3.8% | 2014-01-16 |
| CVE-2009-3469 EXP | Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows remote attackers to inject arbitrary w… | Patch early | 4.3 medium | 3.7% | 2009-09-29 |
| CVE-2008-0919 EXP | Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 and earlier allows remo… | Patch early | 4.3 medium | 3.7% | 2008-02-22 |
| CVE-2014-4963 EXP | Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.customerId parameter to shop/pro… | Patch early | 6.8 medium | 3.7% | 2014-07-15 |
| CVE-2018-10310 EXP | A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Consent plugin before 2.3.10 for Wo… | Patch early | 5.4 medium | 3.7% | 2018-04-25 |
| CVE-2014-2976 EXP | Directory traversal vulnerability in Sixnet SixView Manager 2.4.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET re… | Patch early | 5.0 medium | 3.7% | 2014-04-23 |
| CVE-2004-1838 EXP | Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the URL. | Patch early | 5.0 medium | 3.7% | 2004-03-22 |
| CVE-2007-2250 EXP | admin.php in Phorum before 5.1.22 allows remote attackers to obtain the full path via the module[] parameter. | Patch early | 5.0 medium | 3.7% | 2007-04-25 |
| CVE-2006-1278 EXP | SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) function… | Patch early | 6.8 medium | 3.7% | 2006-03-19 |
| CVE-2006-2242 EXP | acFTP 1.4 allows remote attackers to cause a denial of service (application crash) via a long string with "{" (brace) characters to the USER command. | Patch early | 5.0 medium | 3.7% | 2006-05-09 |
| CVE-2007-2643 EXP | Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to read arbitrary files via a ..… | Patch early | 5.0 medium | 3.7% | 2007-05-13 |
| CVE-2007-6651 EXP | Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive information (script source code) vi… | Patch early | 5.0 medium | 3.7% | 2008-01-04 |
| CVE-2005-0325 EXP | Xpand Rally 1.0.0.0 allows remote attackers or remote malicious game servers to cause a denial of service (application crash) via a packet with large… | Patch early | 5.0 medium | 3.7% | 2005-05-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt