CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,546 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-0964 EXP | Half-Life Server 1.1.1.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via multiple responses to the initial… | Patch early | 5.0 medium | 3.2% | 2002-10-04 |
| CVE-2013-5672 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the IndiaNIC Testimonial plugin 2.2 for WordPress allow remote attackers to hijack the a… | Patch early | 6.8 medium | 3.2% | 2013-09-10 |
| CVE-2013-5977 EXP | Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allows remote attackers t… | Patch early | 6.8 medium | 3.2% | 2013-11-01 |
| CVE-2007-1539 EXP | Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to include arbitrary files via a .. (d… | Patch early | 4.3 medium | 3.2% | 2007-03-20 |
| CVE-2010-0757 EXP | Unrestricted file upload vulnerability in index.php/Attach in WikyBlog 1.7.3rc2 allows remote authenticated users to execute arbitrary code by uploadi… | Patch early | 6.5 medium | 3.2% | 2010-02-27 |
| CVE-2006-5191 EXP | PHP remote file inclusion vulnerability in includes/functions_static_topics.php in the Nivisec Static Topics module for phpBB 1.0 and earlier allows r… | Patch early | 5.1 medium | 3.2% | 2006-10-10 |
| CVE-2004-1801 EXP | Directory traversal vulnerability in PWebServer 0.3.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | Patch early | 5.0 medium | 3.2% | 2004-12-31 |
| CVE-2005-1493 EXP | Directory traversal vulnerability in SimpleCam 1.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URL. | Patch early | 5.0 medium | 3.2% | 2005-05-11 |
| CVE-2010-3899 EXP | IBM OmniFind Enterprise Edition 8.x and 9.x performs web crawls with an unlimited recursion depth, which allows remote web servers to cause a denial o… | Patch early | 5.0 medium | 3.1% | 2010-11-12 |
| CVE-2004-0067 EXP | Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) de… | Patch early | 4.3 medium | 3.1% | 2004-02-17 |
| CVE-2006-5094 EXP | PHP remote file inclusion vulnerability in includes/functions_kb.php in the phpBB XS 2 (Spain version) allows remote attackers to execute arbitrary PH… | Patch early | 5.1 medium | 3.1% | 2006-09-29 |
| CVE-2005-4093 EXP | Check Point VPN-1 SecureClient NG with Application Intelligence R56, NG FP1, 4.0, and 4.1 allows remote attackers to bypass security policies by modif… | Patch early | 6.5 medium | 3.1% | 2005-12-08 |
| CVE-2003-0747 EXP | wgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensitive information such as directo… | Patch early | 5.0 medium | 3.1% | 2003-10-20 |
| CVE-2008-5115 EXP | Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hijac… | Patch early | 6.8 medium | 3.1% | 2008-11-18 |
| CVE-2006-3847 EXP | PHP remote file inclusion vulnerability in (1) admin.php, and possibly (2) details.php, (3) modify.php, (4) newgroup.php, (5) newtask.php, and (6) rss… | Patch early | 5.1 medium | 3.1% | 2006-07-25 |
| CVE-2014-2587 EXP | SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated users to execute arbitrary SQL com… | Patch early | 6.5 medium | 3.1% | 2014-03-24 |
| CVE-2006-1073 EXP | Directory traversal vulnerability in index.php in Daverave Simplog 1.0.2 and earlier allows remote attackers to include or read arbitrary .txt files v… | Patch early | 6.4 medium | 3.1% | 2006-03-08 |
| CVE-2005-2083 EXP | Format string vulnerability in IMAP4 in IA eMailServer Corporate Edition 5.2.2 build 1051 allows remote attackers to cause a denial of service (applic… | Patch early | 5.0 medium | 3.1% | 2005-07-05 |
| CVE-2018-1002005 EXP | These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:43: via the filter_signup_date… | Patch early | 4.8 medium | 3.1% | 2018-12-03 |
| CVE-2006-3395 EXP | PHP remote file inclusion vulnerability in top.php in SiteBuilder-FX 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the admind… | Patch early | 5.1 medium | 3.1% | 2006-07-06 |
| CVE-2007-4382 EXP | CounterPath X-Lite 3.0 34025, and possibly eyeBeam, allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message witho… | Patch early | 5.0 medium | 3.1% | 2007-08-17 |
| CVE-2000-0570 EXP | FirstClass Internet Services server 5.770, and other versions before 6.1, allows remote attackers to cause a denial of service by sending an email wit… | Patch early | 5.0 medium | 3.1% | 2000-06-27 |
| CVE-2004-1215 EXP | Kreed 1.05 and earlier allows remote attackers to cause a denial of service (server disconnect) via a long UDP packet, which causes a "message too lon… | Patch early | 5.0 medium | 3.1% | 2005-01-10 |
| CVE-2004-1216 EXP | The scripts that handle players in Kreed 1.05 and earlier allow remote attackers to cause a denial of service (server freeze) via a long (1) nickname… | Patch early | 5.0 medium | 3.1% | 2005-01-10 |
| CVE-2005-0382 EXP | Breed patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via an empty UDP packet, which triggers a null dere… | Patch early | 5.0 medium | 3.1% | 2005-05-02 |
| CVE-2008-5956 EXP | Wbstreet (aka PHPSTREET Webboard) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers… | Patch early | 5.0 medium | 3.1% | 2009-01-23 |
| CVE-2008-4875 EXP | Directory traversal vulnerability in the web server in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote authen… | Patch early | 6.8 medium | 3.1% | 2008-11-01 |
| CVE-2006-2099 EXP | Directory traversal vulnerability in UltraISO 8.0.0.1392 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO i… | Patch early | 5.0 medium | 3.1% | 2006-04-29 |
| CVE-2006-2101 EXP | Directory traversal vulnerability in WinISO 5.3 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image. | Patch early | 5.0 medium | 3.1% | 2006-04-29 |
| CVE-2015-2803 EXP | SQL injection vulnerability in mod1/index.php in the Akronymmanager (sb_akronymmanager) extension before 7.0.0 for TYPO3 allows remote authenticated u… | Patch early | 6.0 medium | 3.1% | 2015-06-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt