CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,488 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-7368 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Gnew 2013.1 allow remote attackers to inject arbitrary web script or HTML via the gnew_template… | Patch early | 4.3 medium | 3.2% | 2014-04-15 |
| CVE-2019-7541 EXP | Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring. | Patch early | 6.1 medium | 3.2% | 2019-05-07 |
| CVE-2006-4130 EXP | PHP remote file inclusion vulnerability in admin.remository.php in the Remository Component (com_remository) 3.25 and earlier for Mambo and Joomla!, w… | Patch early | 6.8 medium | 3.2% | 2006-08-14 |
| CVE-2008-0756 EXP | The LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4… | Patch early | 5.0 medium | 3.2% | 2008-02-13 |
| CVE-2004-0264 EXP | palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the… | Patch early | 5.0 medium | 3.2% | 2004-11-23 |
| CVE-2004-1739 EXP | Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users. | Patch early | 5.0 medium | 3.2% | 2004-08-23 |
| CVE-2007-4079 EXP | Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft SMS Text Messaging Enterprise allow remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 3.2% | 2007-07-30 |
| CVE-2000-0417 EXP | The HTTP administration interface to the Cayman 3220-H DSL router allows remote attackers to cause a denial of service via a long username or password… | Patch early | 5.0 medium | 3.2% | 2000-05-17 |
| CVE-2000-0440 EXP | NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option. | Patch early | 5.0 medium | 3.2% | 2000-05-01 |
| CVE-2013-6937 EXP | Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the name attrib… | Patch early | 6.8 medium | 3.2% | 2013-12-04 |
| CVE-2007-2068 EXP | Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 6.8 medium | 3.2% | 2007-04-18 |
| CVE-2002-0922 EXP | CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.sty… | Patch early | 5.0 medium | 3.2% | 2002-10-04 |
| CVE-2002-1248 EXP | Northern Solutions Xeneo Web Server 2.1.0.0, 2.0.759.6, and other versions before 2.1.5 allows remote attackers to cause a denial of service (crash) v… | Patch early | 5.0 medium | 3.2% | 2002-11-12 |
| CVE-2004-1109 EXP | The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption and system fre… | Patch early | 5.0 medium | 3.2% | 2005-01-10 |
| CVE-2004-1866 EXP | nstxd in Nstx 1.1 beta3 and earlier allows remote attackers to cause a denial of service (crash) via a large packet, which triggers a null dereference… | Patch early | 5.0 medium | 3.2% | 2004-03-26 |
| CVE-2005-4319 EXP | Directory traversal vulnerability in index2.php in Limbo CMS 1.0.4.2 and earlier allows remote attackers to include arbitrary PHP files via ".." seque… | Patch early | 5.0 medium | 3.2% | 2005-12-17 |
| CVE-2012-6505 EXP | Cross-site scripting (XSS) vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to inject arbitrar… | Patch early | 4.3 medium | 3.2% | 2013-01-24 |
| CVE-2014-5216 EXP | Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allow remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 3.2% | 2014-12-23 |
| CVE-2014-7200 EXP | Cross-site scripting (XSS) vulnerability in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extension 2.14.0 and earlier for TYPO… | Patch early | 4.3 medium | 3.2% | 2014-10-10 |
| CVE-2014-9412 EXP | Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.1 allow remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 3.2% | 2014-12-23 |
| CVE-2017-16951 EXP | Winamp Pro 5.66 Build 3512 allows remote attackers to cause a denial of service via a crafted WAV, WMV, AU, ASF, AIFF, or AIF file. | Patch early | 5.5 medium | 3.2% | 2017-11-28 |
| CVE-2009-1834 EXP | Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 allows remote attacke… | Patch early | 4.3 medium | 3.2% | 2009-06-12 |
| CVE-2007-4843 EXP | Directory traversal vulnerability in X-Diesel Unreal Commander 0.92 build 565 and 573 allows remote FTP servers to create or overwrite arbitrary files… | Patch early | 5.8 medium | 3.2% | 2007-09-12 |
| CVE-2008-4183 EXP | IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup… | Patch early | 5.0 medium | 3.2% | 2008-09-23 |
| CVE-2013-3082 EXP | Cross-site scripting (XSS) vulnerability in plugins/jojo_core/forgot_password.php in Jojo before 1.2.2 allows remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 3.2% | 2014-06-09 |
| CVE-2003-1540 EXP | WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authenticat… | Patch early | 5.0 medium | 3.2% | 2003-12-31 |
| CVE-2012-2584 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitrary web script or HTML via an… | Patch early | 4.3 medium | 3.2% | 2012-08-12 |
| CVE-2013-5693 EXP | Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web script or HTML via the model par… | Patch early | 4.3 medium | 3.2% | 2013-09-30 |
| CVE-2015-1373 EXP | Multiple cross-site scripting (XSS) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 3.2% | 2015-01-27 |
| CVE-2014-8375 EXP | SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administrators to execute arbitrary SQ… | Patch early | 6.5 medium | 3.2% | 2014-10-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt