CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,620 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-0404 EXP | KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTM… | Patch early | 5.0 medium | 3% | 2005-05-02 |
| CVE-2006-6086 EXP | PHP remote file inclusion vulnerability in src/ark_inc.php in e-Ark 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_pea… | Patch early | 5.1 medium | 3% | 2006-11-24 |
| CVE-2007-5113 EXP | report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified q… | Patch early | 5.0 medium | 3% | 2007-09-26 |
| CVE-2002-1488 EXP | The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) via a PART message with (1) a mis… | Patch early | 5.0 medium | 3% | 2003-04-02 |
| CVE-2018-5754 EXP | Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allow… | Patch early | 5.4 medium | 3% | 2018-06-16 |
| CVE-2006-4464 EXP | The Nokia Browser, possibly Nokia Symbian 60 Browser 3rd edition, allows remote attackers to cause a denial of service (crash) via JavaScript that con… | Patch early | 5.0 medium | 3% | 2006-08-31 |
| CVE-2005-1202 EXP | Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 6.8 medium | 3% | 2005-05-02 |
| CVE-2017-0282 EXP | Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1… | Patch early | 5.0 medium | 3% | 2017-06-15 |
| CVE-2017-0284 EXP | Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1… | Patch early | 5.0 medium | 3% | 2017-06-15 |
| CVE-2017-0285 EXP | Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1… | Patch early | 5.0 medium | 3% | 2017-06-15 |
| CVE-2017-0286 EXP | Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 16… | Patch early | 5.0 medium | 3% | 2017-06-15 |
| CVE-2017-0288 EXP | Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 16… | Patch early | 5.0 medium | 3% | 2017-06-15 |
| CVE-2003-0481 EXP | Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script, as demonstrated using the msg… | Patch early | 4.3 medium | 3% | 2003-08-07 |
| CVE-2006-4884 EXP | Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 allow remote attackers to inject arbitrary web script or HTML via (1) the… | Patch early | 4.3 medium | 3% | 2006-09-19 |
| CVE-2008-5770 EXP | Cross-site scripting (XSS) vulnerability in config/make_config.php in PHP Weather 2.2.2 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3% | 2008-12-30 |
| CVE-2004-2487 EXP | Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) "..",… | Patch early | 4.0 medium | 3% | 2004-12-31 |
| CVE-2009-3666 EXP | Cross-site scripting (XSS) vulnerability in index.php in Nullam Blog 0.1.2 allows remote attackers to inject arbitrary web script or HTML via the e pa… | Patch early | 4.3 medium | 3% | 2009-10-11 |
| CVE-2008-0218 EXP | Cross-site scripting (XSS) vulnerability in admin/index.html in Merak IceWarp Mail Server allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 3% | 2008-01-10 |
| CVE-2010-3462 EXP | Cross-site scripting (XSS) vulnerability in backend/plugin/Registration/index.php in Mollify 1.6, 1.6.5.5, and possibly other versions allows remote a… | Patch early | 4.3 medium | 3% | 2010-09-17 |
| CVE-2006-1581 EXP | Directory traversal vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the _path par… | Patch early | 6.4 medium | 3% | 2006-04-02 |
| CVE-2006-1821 EXP | Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing… | Patch early | 6.4 medium | 3% | 2006-04-18 |
| CVE-2005-4074 EXP | Directory traversal vulnerability in index.cfm in CF_Nuke 4.6 and earlier, when Sandbox Security is disabled, allows remote attackers to include arbit… | Patch early | 5.0 medium | 3% | 2005-12-08 |
| CVE-2000-0453 EXP | XFree86 3.3.x and 4.0 allows a user to cause a denial of service via a negative counter value in a malformed TCP packet that is sent to port 6000. | Patch early | 5.0 medium | 3% | 2000-05-18 |
| CVE-2004-0616 EXP | The BT Voyager 2000 Wireless ADSL Router has a default public SNMP community name, which allows remote attackers to obtain sensitive information such… | Patch early | 5.0 medium | 3% | 2004-12-06 |
| CVE-2008-2032 EXP | The FTP service in Acritum Femitter Server 1.03 allows remote attackers to cause a denial of service (crash) by sending multiple crafted RETR commands… | Patch early | 5.0 medium | 3% | 2008-04-30 |
| CVE-2008-4601 EXP | Cross-site scripting (XSS) vulnerability in the login feature in Habari CMS 0.5.1 allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 3% | 2008-10-18 |
| CVE-2010-2316 EXP | Multiple cross-site scripting (XSS) vulnerabilities in default.asp in WmsCms 2.0 and earlier allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 3% | 2010-06-17 |
| CVE-2000-0903 EXP | Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read arbitrary files via a .. (… | Patch early | 5.0 medium | 3% | 2000-12-19 |
| CVE-2000-0914 EXP | OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests. | Patch early | 5.0 medium | 3% | 2000-12-19 |
| CVE-2001-0074 EXP | Directory traversal vulnerability in print.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the board para… | Patch early | 5.0 medium | 3% | 2001-02-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt