CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,522 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-35956 EXP | Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introd… | Patch early | 5.4 medium | 3.2% | 2021-06-30 |
| CVE-2015-6100 EXP | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2,… | Patch early | 6.9 medium | 3.2% | 2015-11-11 |
| CVE-2008-0094 EXP | Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary loc… | Patch early | 6.4 medium | 3.2% | 2008-01-08 |
| CVE-2015-1057 EXP | Cross-site scripting (XSS) vulnerability in usersettings.php in e107 2.0.0 allows remote attackers to inject arbitrary web script or HTML via the "Rea… | Patch early | 4.3 medium | 3.2% | 2015-01-16 |
| CVE-2011-5028 EXP | Directory traversal vulnerability in novelllogmanager/FileDownload in Novell Sentinel Log Manager 1.2.0.1_938 and earlier, as used in Novell Sentinel… | Patch early | 4.0 medium | 3.2% | 2011-12-29 |
| CVE-2019-3759 EXP | The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerabi… | Patch early | 6.4 medium | 3.2% | 2019-09-11 |
| CVE-2017-16952 EXP | KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file. | Patch early | 5.5 medium | 3.2% | 2017-11-28 |
| CVE-2006-2211 EXP | Absolute path traversal vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to browse arbitrary directories via the path par… | Patch early | 5.0 medium | 3.2% | 2006-05-05 |
| CVE-2004-1212 EXP | Directory traversal vulnerability in btdownload.php in Blog Torrent preview 0.8 allows remote attackers to download arbitrary files via a .. (dot dot)… | Patch early | 5.0 medium | 3.2% | 2005-01-10 |
| CVE-2007-1906 EXP | Directory traversal vulnerability in richedit/keyboard.php in eCardMAX HotEditor (Hot Editor) 4.0, and the HotEditor plugin for MyBB, allows remote at… | Patch early | 6.8 medium | 3.2% | 2007-04-10 |
| CVE-2010-1921 EXP | Multiple PHP remote file inclusion vulnerabilities in OpenMairie openAnnuaire 2.00, when register_globals is enabled, allow remote attackers to execut… | Patch early | 6.8 medium | 3.2% | 2010-05-12 |
| CVE-2010-1927 EXP | Multiple PHP remote file inclusion vulnerabilities in openMairie openCourrier 2.02 and 2.03 beta, when register_globals is enabled, allow remote attac… | Patch early | 6.8 medium | 3.2% | 2010-05-12 |
| CVE-2007-6129 EXP | Directory traversal vulnerability in scripts/include/show_content.php in Amber Script 1.0 allows remote attackers to include and execute arbitrary loc… | Patch early | 5.8 medium | 3.2% | 2007-11-26 |
| CVE-2007-2166 EXP | PHP remote file inclusion vulnerability in administration/user/lib/group.inc.php in OpenSurveyPilot (osp) 1.2.1 and earlier allows remote attackers to… | Patch early | 6.8 medium | 3.2% | 2007-04-22 |
| CVE-2008-4136 EXP | Michael Roth Software Personal FTP Server (PFT) 6.0f allows remote attackers to cause a denial of service (service crash) via multiple RETR commands,… | Patch early | 5.0 medium | 3.2% | 2008-09-24 |
| CVE-2002-1021 EXP | BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte. | Patch early | 5.0 medium | 3.2% | 2002-10-04 |
| CVE-2004-0303 EXP | OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filena… | Patch early | 5.0 medium | 3.2% | 2004-11-23 |
| CVE-2009-4497 EXP | Cross-site scripting (XSS) vulnerability in LXR Cross Referencer 0.9.5 and 0.9.6 allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 3.2% | 2010-01-07 |
| CVE-2012-6312 EXP | Cross-site scripting (XSS) vulnerability in the Video Lead Form plugin for WordPress allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 3.2% | 2012-12-11 |
| CVE-2018-8813 EXP | Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbit… | Patch early | 4.8 medium | 3.2% | 2018-04-04 |
| CVE-2013-2750 EXP | Cross-site scripting (XSS) vulnerability in e107_plugins/content/handlers/content_preset.php in e107 before 1.0.3 allows remote attackers to inject ar… | Patch early | 4.3 medium | 3.2% | 2014-01-22 |
| CVE-2011-5283 EXP | Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier… | Patch early | 4.3 medium | 3.2% | 2014-12-31 |
| CVE-2012-5684 EXP | Cross-site scripting (XSS) vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the inFullnam… | Patch early | 4.3 medium | 3.2% | 2014-08-14 |
| CVE-2013-3639 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Xaraya 2.4.0-b1 and earlier allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 3.2% | 2014-02-05 |
| CVE-2013-5312 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 3.2% | 2013-08-19 |
| CVE-2013-6793 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allow remote attackers to inject arbitrary w… | Patch early | 4.3 medium | 3.2% | 2013-11-14 |
| CVE-2013-6923 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to inj… | Patch early | 4.3 medium | 3.2% | 2014-01-09 |
| CVE-2014-100017 EXP | Cross-site scripting (XSS) vulnerability in canned_opr.php in PhpOnlineChat 3.0 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 3.2% | 2015-01-13 |
| CVE-2014-1603 EXP | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) p… | Patch early | 4.3 medium | 3.2% | 2014-05-14 |
| CVE-2014-2586 EXP | Cross-site scripting (XSS) vulnerability in the login audit form in McAfee Cloud Single Sign On (SSO) allows remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 3.2% | 2014-03-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt