CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,997 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-4030 EXP | Cross-site request forgery (CSRF) vulnerability in the JW Player plugin before 2.1.4 for WordPress allows remote attackers to hijack the authenticatio… | Patch early | 6.8 medium | 2.9% | 2014-06-25 |
| CVE-2020-14073 EXP | XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can create a map, and then use the… | Patch early | 5.4 medium | 2.9% | 2020-06-23 |
| CVE-2006-0691 EXP | edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbi… | Patch early | 5.0 medium | 2.9% | 2006-02-15 |
| CVE-2007-6603 EXP | Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator… | Patch early | 5.0 medium | 2.9% | 2007-12-31 |
| CVE-2010-1652 EXP | Directory traversal vulnerability in the HelpCenter module in Help Center Live (HCL) 2.0.6 and 2.1.7 allows remote attackers to read arbitrary files a… | Patch early | 5.0 medium | 2.9% | 2010-05-03 |
| CVE-2007-0983 EXP | PHP remote file inclusion vulnerability in _admin/nav.php in AT Contenator 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a… | Patch early | 6.8 medium | 2.9% | 2007-02-16 |
| CVE-2007-3404 EXP | Directory traversal vulnerability in ShowImage.php in SiteDepth CMS 3.44 allows remote attackers to read arbitrary files via a .. (dot dot) in the nam… | Patch early | 5.0 medium | 2.9% | 2007-06-26 |
| CVE-2009-1663 EXP | Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to execute arbitrary code b… | Patch early | 6.8 medium | 2.9% | 2009-05-18 |
| CVE-2002-0331 EXP | Directory traversal vulnerability in the HTTP server for BPM Studio Pro 4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the… | Patch early | 5.0 medium | 2.9% | 2002-06-25 |
| CVE-2008-5608 EXP | ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the databas… | Patch early | 5.0 medium | 2.9% | 2008-12-16 |
| CVE-2021-33561 EXP | A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via custome… | Patch early | 4.8 medium | 2.9% | 2021-05-24 |
| CVE-2021-3294 EXP | CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a cookie to perform user redirecti… | Patch early | 5.4 medium | 2.8% | 2021-02-09 |
| CVE-2003-0757 EXP | Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote request… | Patch early | 5.0 medium | 2.8% | 2003-10-20 |
| CVE-2006-1292 EXP | Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary lo… | Patch early | 5.0 medium | 2.8% | 2006-03-19 |
| CVE-2021-3318 EXP | attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter. | Patch early | 6.1 medium | 2.8% | 2021-01-27 |
| CVE-2006-3051 EXP | Cross-site scripting (XSS) vulnerability in list.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to inject arbitrary… | Patch early | 5.1 medium | 2.8% | 2006-06-16 |
| CVE-2004-2176 EXP | The Internet Connection Firewall (ICF) in Microsoft Windows XP SP2 is configured by default to trust sessmgr.exe, which allows local users to use sess… | Patch early | 4.6 medium | 2.8% | 2004-12-31 |
| CVE-2007-4358 EXP | Zoidcom 0.6.7 and earlier allows remote attackers to cause a denial of service (application crash) via a JOIN packet (aka connection packet) containin… | Patch early | 4.3 medium | 2.8% | 2007-08-15 |
| CVE-2006-5725 EXP | The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which ret… | Patch early | 5.0 medium | 2.8% | 2006-11-04 |
| CVE-2006-6759 EXP | A certain ActiveX control in rpau3260.dll in RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer cras… | Patch early | 5.0 medium | 2.8% | 2006-12-27 |
| CVE-2011-4670 EXP | Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 5.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 2.8% | 2011-12-02 |
| CVE-2014-2340 EXP | Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication… | Patch early | 6.8 medium | 2.8% | 2014-04-03 |
| CVE-2009-0678 EXP | images/captcha.php in RavenNuke 2.30 allows remote attackers to obtain sensitive information via an aFonts array parameter value that does not corresp… | Patch early | 5.0 medium | 2.8% | 2009-02-22 |
| CVE-2000-0835 EXP | search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory i… | Patch early | 5.0 medium | 2.8% | 2000-11-14 |
| CVE-2000-0958 EXP | HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window. | Patch early | 5.0 medium | 2.8% | 2000-12-19 |
| CVE-2001-0399 EXP | Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an H… | Patch early | 5.0 medium | 2.8% | 2001-06-18 |
| CVE-2005-1754 EXP | JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument t… | Patch early | 5.0 medium | 2.8% | 2005-12-31 |
| CVE-2007-0138 EXP | formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with (1) AbfrageForm or (2) EingabeForm, allows remote attackers to cause a de… | Patch early | 5.0 medium | 2.8% | 2007-01-09 |
| CVE-2008-5980 EXP | Ocean12 Mailing List Manager Gold stores sensitive data under the web root with insufficient access control, which allows remote attackers to download… | Patch early | 5.0 medium | 2.8% | 2009-01-27 |
| CVE-2002-1886 EXP | TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain the database… | Patch early | 5.0 medium | 2.8% | 2002-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt