CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,488 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-2559 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allow remote attackers to h… | Patch early | 6.8 medium | 3.3% | 2014-10-17 |
| CVE-2006-1480 EXP | Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and execute commands by (1) injecti… | Patch early | 5.1 medium | 3.3% | 2006-03-29 |
| CVE-2006-2424 EXP | PHP remote file inclusion vulnerability in ezUserManager 1.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitra… | Patch early | 5.1 medium | 3.3% | 2006-05-17 |
| CVE-2014-4035 EXP | Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote attackers to in… | Patch early | 4.3 medium | 3.3% | 2014-06-11 |
| CVE-2014-8380 EXP | Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer Header in… | Patch early | 4.3 medium | 3.3% | 2014-10-21 |
| CVE-2015-1575 EXP | Multiple cross-site scripting (XSS) vulnerabilities in u5CMS before 3.9.4 allow remote attackers to inject arbitrary web script or HTML via the (1) c,… | Patch early | 4.3 medium | 3.3% | 2015-02-11 |
| CVE-2007-4047 EXP | geoBlog (aka BitDamaged) 1 does not require authentication for (1) deletecomment.php, (2) deleteblog.php, and (3) listcomment.php in admin/, which all… | Patch early | 6.4 medium | 3.3% | 2007-07-27 |
| CVE-2002-0879 EXP | showtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style pathname in the FILE parameter. | Patch early | 5.0 medium | 3.3% | 2002-10-04 |
| CVE-2013-4880 EXP | Cross-site scripting (XSS) vulnerability in core/admin/modules/developer/modules/views/add.php in BigTree CMS 4.0 RC2 and earlier allows remote attack… | Patch early | 4.3 medium | 3.3% | 2013-08-14 |
| CVE-2014-1944 EXP | Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the text param… | Patch early | 4.3 medium | 3.3% | 2014-03-09 |
| CVE-2000-0504 EXP | libICE in XFree86 allows remote attackers to cause a denial of service by specifying a large value which is not properly checked by the SKIP_STRING ma… | Patch early | 5.0 medium | 3.3% | 2000-06-19 |
| CVE-2002-0338 EXP | The Bat! 1.53d and 1.54beta, and possibly other versions, allows remote attackers to cause a denial of service (crash) via an attachment whose name in… | Patch early | 5.0 medium | 3.3% | 2002-06-25 |
| CVE-2002-1043 EXP | Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Subject ("\t\t"). | Patch early | 5.0 medium | 3.3% | 2002-10-04 |
| CVE-2007-6379 EXP | BadBlue 2.72b and earlier allows remote attackers to obtain sensitive information via an invalid browse parameter, which reveals the installation path… | Patch early | 5.0 medium | 3.3% | 2007-12-15 |
| CVE-2018-6230 EXP | A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an attacker to execute SQL comman… | Patch early | 6.8 medium | 3.3% | 2018-03-15 |
| CVE-2018-5688 EXP | ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in the Setup component. | Patch early | 6.1 medium | 3.3% | 2018-01-14 |
| CVE-2013-5038 EXP | The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had previously bee… | Patch early | 5.8 medium | 3.3% | 2013-12-30 |
| CVE-2002-1167 EXP | Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execut… | Patch early | 6.8 medium | 3.3% | 2002-11-04 |
| CVE-2006-2404 EXP | Directory traversal vulnerability in popup.php in RadScripts RadLance Gold 7.0 allows remote attackers to read arbitrary files via a .. (dot dot) in t… | Patch early | 6.4 medium | 3.3% | 2006-05-16 |
| CVE-2004-2520 EXP | POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a large numeric v… | Patch early | 4.0 medium | 3.3% | 2004-12-31 |
| CVE-2008-6902 EXP | Unrestricted file upload vulnerability in upload_flyer.php in 2532designs 2532|Gigs 1.2.2 Stable allows remote attackers to execute arbitrary code by… | Patch early | 6.8 medium | 3.3% | 2009-08-06 |
| CVE-2012-1936 EXP | The wp_create_nonce function in wp-includes/pluggable.php in WordPress 3.3.1 and earlier associates a nonce with a user account instead of a user sess… | Patch early | 6.8 medium | 3.3% | 2012-05-03 |
| CVE-2021-27370 EXP | The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field. | Patch early | 5.4 medium | 3.3% | 2021-02-22 |
| CVE-2000-1234 EXP | violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the… | Patch early | 5.0 medium | 3.3% | 2000-12-31 |
| CVE-2007-2441 EXP | Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to obtain the system path via certain URLs asso… | Patch early | 5.0 medium | 3.3% | 2007-05-16 |
| CVE-2014-7280 EXP | Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web servers to inject arbitrary web… | Patch early | 4.3 medium | 3.3% | 2014-10-21 |
| CVE-2013-4620 EXP | Cross-site scripting (XSS) vulnerability in interface/main/onotes/office_comments_full.php in OpenEMR 4.1.1 allows remote attackers to inject arbitrar… | Patch early | 4.3 medium | 3.3% | 2013-08-09 |
| CVE-2011-5053 EXP | The Wi-Fi Protected Setup (WPS) protocol, when the "external registrar" authentication method is used, does not properly inform clients about failed P… | Patch early | 5.8 medium | 3.3% | 2012-01-06 |
| CVE-2004-1612 EXP | Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request… | Patch early | 5.0 medium | 3.3% | 2004-10-18 |
| CVE-2004-1220 EXP | Battlefield 1942 1.6.19 and earlier, and Battlefield Vietnam 1.2 and earlier, allows a remote master server to cause a denial of service (client crash… | Patch early | 5.0 medium | 3.3% | 2005-01-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt