CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,553 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-3442 EXP | Winamp 5.666 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) via a malformed .FLV file, related to f263… | Patch early | 4.3 medium | 2.8% | 2014-05-23 |
| CVE-2007-3451 EXP | PHP remote file inclusion vulnerability in admin/index.php in 6ALBlog allows remote authenticated administrators to execute arbitrary PHP code via a U… | Patch early | 6.5 medium | 2.8% | 2007-06-27 |
| CVE-2007-4904 EXP | RealNetworks RealPlayer 10.1.0.3114 and earlier, and Helix Player 1.0.6.778 on Fedora Core 6 (FC6) and possibly other platforms, allow user-assisted r… | Patch early | 4.3 medium | 2.8% | 2007-09-17 |
| CVE-2008-2878 EXP | Open redirect vulnerability in rss_getfile.php in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allows remote attackers to redirect… | Patch early | 6.4 medium | 2.8% | 2008-06-26 |
| CVE-2009-4175 EXP | CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an invalid date value in the from_date… | Patch early | 5.0 medium | 2.8% | 2009-12-02 |
| CVE-2015-7904 EXP | Unrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated user… | Patch early | 6.5 medium | 2.8% | 2015-10-28 |
| CVE-2007-6056 EXP | frame.html in Aida-Web (Aida Web) allows remote attackers to bypass a protection mechanism and obtain comment and task details via modified values to… | Patch early | 5.0 medium | 2.8% | 2007-11-20 |
| CVE-2007-2471 EXP | Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrary files via a full pathname in… | Patch early | 5.0 medium | 2.8% | 2007-05-02 |
| CVE-2007-2600 EXP | Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitra… | Patch early | 6.8 medium | 2.8% | 2007-05-11 |
| CVE-2010-0984 EXP | Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to downl… | Patch early | 5.0 medium | 2.8% | 2010-03-16 |
| CVE-2012-2977 EXP | The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an app… | Patch early | 5.0 medium | 2.8% | 2012-07-23 |
| CVE-2006-6138 EXP | Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary directories via an absolute pathname i… | Patch early | 5.0 medium | 2.8% | 2006-11-28 |
| CVE-2011-4341 EXP | Multiple SQL injection vulnerabilities in symphony/content/content.publish.php in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow re… | Patch early | 4.3 medium | 2.8% | 2012-02-12 |
| CVE-2006-1913 EXP | Cross-site scripting (XSS) vulnerability in jax_guestbook.php in Jax Guestbook 3.1, 3.31, and 3.50 allows remote attackers to inject arbitrary web scr… | Patch early | 6.8 medium | 2.8% | 2006-04-20 |
| CVE-2006-5770 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via (1) Bloks, (2) Ne… | Patch early | 6.8 medium | 2.8% | 2006-11-06 |
| CVE-2006-6599 EXP | maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters (";" semicolon) in the ann… | Patch early | 6.0 medium | 2.8% | 2006-12-15 |
| CVE-2018-6940 EXP | A /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction… | Patch early | 6.1 medium | 2.8% | 2018-02-20 |
| CVE-2021-30150 EXP | Composr 10.0.36 allows XSS in an XML script. | Patch early | 6.1 medium | 2.8% | 2021-04-06 |
| CVE-2007-6235 EXP | A certain ActiveX control in RealNetworks RealPlayer 11 allows remote attackers to cause a denial of service (application crash) via a malformed .au f… | Patch early | 5.0 medium | 2.8% | 2007-12-04 |
| CVE-2015-8037 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers… | Patch early | 4.3 medium | 2.8% | 2015-11-02 |
| CVE-2015-8038 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers… | Patch early | 4.3 medium | 2.8% | 2015-11-02 |
| CVE-2006-1161 EXP | Absolute path traversal vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote registered users to execute arbitrary code by uploading… | Patch early | 6.5 medium | 2.8% | 2006-03-12 |
| CVE-2008-0091 EXP | Directory traversal vulnerability in download2.php in AGENCY4NET WEBFTP 1 allows remote attackers to read and delete arbitrary files via a .. (dot dot… | Patch early | 6.4 medium | 2.8% | 2008-01-04 |
| CVE-2001-0418 EXP | content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL charact… | Patch early | 5.0 medium | 2.8% | 2001-07-02 |
| CVE-2007-3973 EXP | Multiple cross-site scripting (XSS) vulnerabilities in JBlog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id paramete… | Patch early | 6.8 medium | 2.8% | 2007-07-25 |
| CVE-2010-1267 EXP | Multiple directory traversal vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to read arbitrary files via directory traver… | Patch early | 5.0 medium | 2.8% | 2010-04-06 |
| CVE-2008-0431 EXP | Directory traversal vulnerability in administrator/download.php in IDMOS (aka Phoenix) 1.0 allows remote attackers to read arbitrary files via a .. (d… | Patch early | 5.0 medium | 2.8% | 2008-01-23 |
| CVE-2008-3205 EXP | Directory traversal vulnerability in index.php in Easy-Script Wysi Wiki Wyg 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in… | Patch early | 5.0 medium | 2.8% | 2008-07-17 |
| CVE-2010-1460 EXP | The IBM BladeCenter with Advanced Management Module (AMM) firmware before bpet50g does not properly perform interrupt sharing for USB and iSCSI, which… | Patch early | 5.0 medium | 2.8% | 2010-04-16 |
| CVE-2007-4325 EXP | PHP remote file inclusion vulnerability in index.php in Gaestebuch 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the config[r… | Patch early | 6.8 medium | 2.8% | 2007-08-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt