CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,185 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-0534 EXP | Multiple cross-site scripting (XSS) vulnerabilities in default.asp in CyberShop Ultimate E-commerce allow remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 3.6% | 2006-02-04 |
| CVE-2004-1746 EXP | Cross-site scripting (XSS) vulnerability in index.php in PHP Code Snippet Library allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 3.6% | 2004-12-31 |
| CVE-2005-1498 EXP | Multiple cross-site scripting (XSS) vulnerabilities in myBloggie 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) year… | Patch early | 4.3 medium | 3.6% | 2005-05-11 |
| CVE-2007-6510 EXP | Multiple stack-based buffer overflows in ProWizard 4 PC (prowiz) 1.62 and earlier allow remote attackers to execute arbitrary code via a crafted file… | Patch early | 6.8 medium | 3.6% | 2007-12-21 |
| CVE-2004-2112 EXP | Directory traversal vulnerability in BremsServer 1.2.4 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in the URL. | Patch early | 5.0 medium | 3.6% | 2004-12-31 |
| CVE-2008-0691 EXP | Multiple cross-site scripting (XSS) vulnerabilities in admin_panel.php in the Simon Elvery WP-Footnotes 2.2 plugin for WordPress allow remote attacker… | Patch early | 4.3 medium | 3.6% | 2008-02-12 |
| CVE-1999-1485 EXP | nsd in IRIX 6.5 through 6.5.2 exports a virtual filesystem on a UDP port, which allows remote attackers to view files and cause a possible denial of s… | Patch early | 6.4 medium | 3.6% | 1999-05-31 |
| CVE-2009-0537 EXP | Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows cont… | Patch early | 4.9 medium | 3.6% | 2009-03-09 |
| CVE-2008-3305 EXP | Cross-site scripting (XSS) vulnerability in mensaje.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 3.6% | 2008-07-25 |
| CVE-2006-4681 EXP | Directory traversal vulnerability in Redirect.bat in IBM Director before 5.10 allows remote attackers to read arbitrary files via a .. (dot dot) seque… | Patch early | 5.0 medium | 3.6% | 2006-09-11 |
| CVE-2017-8471 EXP | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,… | Patch early | 5.0 medium | 3.6% | 2017-06-15 |
| CVE-2017-8473 EXP | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allow an… | Patch early | 5.0 medium | 3.6% | 2017-06-15 |
| CVE-2017-8485 EXP | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… | Patch early | 5.0 medium | 3.6% | 2017-06-15 |
| CVE-2017-10803 EXP | In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database An… | Patch early | 6.5 medium | 3.6% | 2017-07-04 |
| CVE-2018-18548 EXP | ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager. | Patch early | 6.1 medium | 3.6% | 2018-10-24 |
| CVE-2008-1403 EXP | Stack-based buffer overflow in the TFTP server in BootManage TFTPD 1.99 and earlier in BootManage Administrator 7.1 and earlier allows remote attacker… | Patch early | 6.8 medium | 3.6% | 2008-03-20 |
| CVE-2004-1659 EXP | Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Administrator, Editor, Journalist or… | Patch early | 4.3 medium | 3.6% | 2004-09-02 |
| CVE-2014-3210 EXP | SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenti… | Patch early | 6.5 medium | 3.6% | 2014-05-22 |
| CVE-2004-1207 EXP | The Serious engine, as used in (1) Alpha Black Zero Intrepid Protocol 1.04 and earlier, (2) Nitro family, and (3) Serious Sam Second Encounter 1.07 al… | Patch early | 5.0 medium | 3.6% | 2005-01-10 |
| CVE-2002-0502 EXP | Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page. | Patch early | 5.0 medium | 3.6% | 2002-08-12 |
| CVE-2006-2395 EXP | PHP remote file inclusion vulnerability in resources/includes/popp.config.loader.inc.php in PopSoft Digital PopPhoto Studio 3.5.4 and earlier allows r… | Patch early | 5.0 medium | 3.6% | 2006-05-16 |
| CVE-2014-9581 EXP | Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read arbitrary files via a .. (dot… | Patch early | 5.0 medium | 3.6% | 2015-01-08 |
| CVE-2014-6070 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3.6% | 2014-09-11 |
| CVE-2000-0975 EXP | Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrary files via a .. (dot dot) att… | Patch early | 5.0 medium | 3.6% | 2000-12-19 |
| CVE-2001-0217 EXP | Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the do… | Patch early | 5.0 medium | 3.6% | 2001-06-02 |
| CVE-2002-1529 EXP | Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allow… | Patch early | 4.3 medium | 3.6% | 2003-03-31 |
| CVE-2002-1922 EXP | Cross-site scripting (XSS) vulnerability in global.php in Jelsoft vBulletin 2.0.0 through 2.2.8 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 3.6% | 2002-12-31 |
| CVE-2004-2574 EXP | Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 3.6% | 2004-12-31 |
| CVE-2018-17997 EXP | LayerBB 1.1.1 allows XSS via the titles of conversations (PMs). | Patch early | 6.1 medium | 3.6% | 2019-03-21 |
| CVE-2006-5077 EXP | PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Chris Smith Minerva Build 238 and earlier allows remote attackers t… | Patch early | 5.1 medium | 3.6% | 2006-09-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt