CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,185 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-6492 EXP | Unrestricted file upload vulnerability in process.php in Tizag Countdown Creator 3 allows remote attackers to execute arbitrary code by uploading a fi… | Patch early | 6.8 medium | 3.6% | 2009-03-20 |
| CVE-2008-6751 EXP | Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows remote attackers to execute a… | Patch early | 6.8 medium | 3.6% | 2009-04-24 |
| CVE-2002-1799 EXP | Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) email parameter to… | Patch early | 4.3 medium | 3.6% | 2002-12-31 |
| CVE-2005-0783 EXP | Cross-site scripting (XSS) vulnerability in Phorum before 5.0.14a allows remote attackers to inject arbitrary web script or HTML via the filename of a… | Patch early | 4.3 medium | 3.6% | 2005-05-02 |
| CVE-2017-17062 EXP | The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev1… | Patch early | 6.5 medium | 3.6% | 2018-06-16 |
| CVE-2002-2129 EXP | Cross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote attackers to execute arbitrary web script via an arbitrary fo… | Patch early | 4.3 medium | 3.6% | 2002-12-31 |
| CVE-2004-2063 EXP | Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inject arbitrary HTML or web scrip… | Patch early | 4.3 medium | 3.6% | 2004-12-31 |
| CVE-2004-2310 EXP | Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script or HTML via a… | Patch early | 4.3 medium | 3.6% | 2004-12-31 |
| CVE-2005-2077 EXP | Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the er… | Patch early | 4.3 medium | 3.6% | 2005-06-29 |
| CVE-2005-2480 EXP | Cross-site scripting (XSS) vulnerability in ColdFusion Fusebox 4.1.0 allows remote attackers to inject arbitrary web script or HTML via the fuseaction… | Patch early | 4.3 medium | 3.6% | 2005-08-05 |
| CVE-2018-5405 EXP | The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows an authenticated least privileged user with 'User Console Only' rights to potentiall… | Patch early | 5.4 medium | 3.6% | 2019-06-03 |
| CVE-2007-0620 EXP | download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions, inclu… | Patch early | 5.0 medium | 3.6% | 2007-01-31 |
| CVE-2014-8810 EXP | SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remote authenticated users to exec… | Patch early | 6.5 medium | 3.6% | 2014-12-24 |
| CVE-2014-9305 EXP | SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin before 1.5.2 for WordPress allow… | Patch early | 6.5 medium | 3.6% | 2014-12-08 |
| CVE-2011-5261 EXP | Cross-site scripting (XSS) vulnerability in serverreport.cgi in Axis M10 Series Network Cameras M1054 firmware 5.21 and earlier allows remote attacker… | Patch early | 4.3 medium | 3.6% | 2013-02-12 |
| CVE-2005-0950 EXP | Directory traversal vulnerability in FastStone 4in1 Browser 1.2 allows remote attackers to read arbitrary files via a (1) ... (triple dot) or (2) ..\… | Patch early | 5.0 medium | 3.6% | 2005-03-29 |
| CVE-2019-12905 EXP | FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman§ion=do&page=up URI. This issue has been fixed in FileRun 2019.06.01. | Patch early | 6.1 medium | 3.6% | 2019-06-20 |
| CVE-2017-2388 EXP | An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireFamily" component. It allows at… | Patch early | 5.5 medium | 3.6% | 2017-04-02 |
| CVE-2007-2440 EXP | Directory traversal vulnerability in Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to read ce… | Patch early | 5.0 medium | 3.6% | 2007-05-16 |
| CVE-2001-0760 EXP | Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the… | Patch early | 5.0 medium | 3.6% | 2001-10-18 |
| CVE-2004-2517 EXP | myServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon operation to index.html. | Patch early | 5.0 medium | 3.6% | 2004-12-31 |
| CVE-2004-1665 EXP | Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no paramete… | Patch early | 4.3 medium | 3.6% | 2004-09-05 |
| CVE-2003-1545 EXP | Absolute path traversal vulnerability in nukestyles.com viewpage.php addon for PHP-Nuke allows remote attackers to read arbitrary files via a full pat… | Patch early | 5.0 medium | 3.6% | 2003-12-31 |
| CVE-2012-2512 EXP | The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remot… | Patch early | 5.0 medium | 3.6% | 2012-05-15 |
| CVE-2012-2513 EXP | The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attac… | Patch early | 5.0 medium | 3.6% | 2012-05-15 |
| CVE-2012-2514 EXP | The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remot… | Patch early | 5.0 medium | 3.6% | 2012-05-15 |
| CVE-2012-2612 EXP | The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote at… | Patch early | 5.0 medium | 3.6% | 2012-05-15 |
| CVE-2011-5182 EXP | Cross-site scripting (XSS) vulnerability in lanoba-social-plugin/index.php in the Lanoba Social plugin 1.0 for WordPress allows remote attackers to in… | Patch early | 4.3 medium | 3.6% | 2012-09-20 |
| CVE-2011-4714 EXP | Directory traversal vulnerability in Virtual Vertex Muster before 6.20 allows remote attackers to read arbitrary files via a \.. (backslash dot dot) i… | Patch early | 5.0 medium | 3.6% | 2011-12-08 |
| CVE-2007-0872 EXP | Directory traversal vulnerability in the Plain Old Webserver (POW) add-on before 0.0.9 for Mozilla Firefox allows remote attackers to read arbitrary f… | Patch early | 5.0 medium | 3.6% | 2007-02-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt