CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,032 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-1743 EXP | Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x before 4.2.7 and 4.3.x and 4.4.x before 4.4.1 allow remo… | Patch early | 4.3 medium | 2.8% | 2013-10-24 |
| CVE-2012-0865 EXP | Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phis… | Patch early | 5.8 medium | 2.8% | 2012-02-21 |
| CVE-2013-1645 EXP | Directory traversal vulnerability in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allows remote authenticated… | Patch early | 4.0 medium | 2.8% | 2013-09-05 |
| CVE-2012-3838 EXP | Gekko before 1.2.0 allows remote attackers to obtain the installation path via a direct request to (1) admin/templates/babygekko/index.php or (2) temp… | Patch early | 5.0 medium | 2.8% | 2012-07-03 |
| CVE-2007-5782 EXP | Directory traversal vulnerability in dl.php in FireConfig 0.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter… | Patch early | 5.0 medium | 2.8% | 2007-11-01 |
| CVE-2007-5813 EXP | Multiple directory traversal vulnerabilities in download.php in ISPworker 1.21 allow remote attackers to read arbitrary files via a .. (dot dot) in th… | Patch early | 5.0 medium | 2.8% | 2007-11-05 |
| CVE-2007-6215 EXP | Multiple directory traversal vulnerabilities in play.php in Web-MeetMe 3.0.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the… | Patch early | 5.0 medium | 2.8% | 2007-12-04 |
| CVE-2007-6368 EXP | Directory traversal vulnerability in index.php in ezContents 1.4.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the link para… | Patch early | 5.0 medium | 2.8% | 2007-12-15 |
| CVE-2006-0882 EXP | Directory traversal vulnerability in include.php in Noah's Classifieds 1.3 allows remote attackers to include arbitrary local files via the otherTempl… | Patch early | 5.0 medium | 2.8% | 2006-02-24 |
| CVE-2006-4989 EXP | Patrick Michaelis Wili-CMS allows remote attackers to obtain sensitive information via a direct request for (1) thumbnail.php, (2) functions/admin/all… | Patch early | 5.0 medium | 2.8% | 2006-09-26 |
| CVE-2007-3398 EXP | LiteWEB 2.7 allows remote attackers to cause a denial of service (hang) via a large number of requests for nonexistent pages. | Patch early | 5.0 medium | 2.8% | 2007-06-26 |
| CVE-2006-0174 EXP | Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intrane… | Patch early | 4.0 medium | 2.8% | 2006-01-11 |
| CVE-2013-4015 EXP | Microsoft Internet Explorer 6 through 10 allows local users to bypass the elevation policy check in the (1) Protected Mode or (2) Enhanced Protected M… | Patch early | 6.9 medium | 2.8% | 2013-07-26 |
| CVE-2012-1009 EXP | NetSarang Xlpd 4 Build 0100 and NetSarang Xmanager Enterprise 4 Build 0186 allow remote attackers to cause a denial of service (daemon crash) via a ma… | Patch early | 5.0 medium | 2.8% | 2012-02-14 |
| CVE-2008-6815 EXP | mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a database backup by making a di… | Patch early | 5.0 medium | 2.8% | 2009-05-28 |
| CVE-2013-7209 EXP | Cross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote attackers to hijack the authenticati… | Patch early | 6.8 medium | 2.8% | 2013-12-30 |
| CVE-2012-6272 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage Server Administrator 6.5.0.1, 7.0.0.1, and 7.1.0.1 allow remote attackers to in… | Patch early | 4.3 medium | 2.8% | 2013-01-25 |
| CVE-2009-3789 EXP | Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the last_mes… | Patch early | 4.3 medium | 2.8% | 2009-10-26 |
| CVE-2001-1137 EXP | D-Link DI-704 Internet Gateway firmware earlier than V2.56b6 allows remote attackers to cause a denial of service (reboot) via malformed IP datagram f… | Patch early | 5.0 medium | 2.8% | 2001-09-06 |
| CVE-2008-0338 EXP | Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary… | Patch early | 5.0 medium | 2.8% | 2008-01-17 |
| CVE-2008-0452 EXP | Directory traversal vulnerability in articles.php in Siteman 1.1.9 allows remote attackers to read arbitrary files via directory traversal sequences i… | Patch early | 5.0 medium | 2.8% | 2008-01-25 |
| CVE-2009-2398 EXP | Directory traversal vulnerability in test/index.php in PHP-Sugar 0.80 allows remote attackers to read arbitrary files via a ..// (dot dot slash slash)… | Patch early | 5.0 medium | 2.8% | 2009-07-09 |
| CVE-2007-4964 EXP | WinImage 8.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via an invalid BPB_BytsPerSec field in the header of a… | Patch early | 5.0 medium | 2.8% | 2007-09-18 |
| CVE-2007-0300 EXP | PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 6.8 medium | 2.8% | 2007-01-18 |
| CVE-2007-0580 EXP | PHP remote file inclusion vulnerability in menu.php in Foro Domus 2.10 allows remote attackers to execute arbitrary PHP code via a URL in the sesion_i… | Patch early | 6.8 medium | 2.8% | 2007-01-30 |
| CVE-2007-1108 EXP | PHP remote file inclusion vulnerability in index.php in Christian Schneider CS-Gallery 2.0 and earlier allows remote attackers to execute arbitrary PH… | Patch early | 6.8 medium | 2.8% | 2007-02-26 |
| CVE-2006-3685 EXP | PHP remote file inclusion vulnerability in CzarNews 1.12 through 1.14 allows remote attackers to execute arbitrary PHP code via a URL in the tpath par… | Patch early | 5.1 medium | 2.8% | 2006-07-21 |
| CVE-2003-1427 EXP | Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as th… | Patch early | 6.4 medium | 2.8% | 2003-12-31 |
| CVE-2009-5093 EXP | Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in t… | Patch early | 5.0 medium | 2.8% | 2011-09-12 |
| CVE-2008-4181 EXP | Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Registe… | Patch early | 6.8 medium | 2.8% | 2008-09-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt