CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,585 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-2140 EXP | Directory traversal vulnerability in default.asp for FSboard 2.0 allows remote attackers to read arbitrary files via ".." sequences in the filename pa… | Patch early | 5.0 medium | 2.7% | 2005-07-05 |
| CVE-2015-1517 EXP | SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to execute arbitrary SQL command… | Patch early | 6.0 medium | 2.7% | 2015-02-20 |
| CVE-2010-0967 EXP | Multiple directory traversal vulnerabilities in Geekhelps ADMP 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute… | Patch early | 5.1 medium | 2.7% | 2010-03-16 |
| CVE-2010-2850 EXP | Directory traversal vulnerability in productionnu2/fileuploader.php in nuBuilder 10.04.20, and possibly other versions before 10.07.12, allows remote… | Patch early | 6.8 medium | 2.7% | 2010-07-25 |
| CVE-2012-1110 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Etano 1.22 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1… | Patch early | 4.3 medium | 2.7% | 2012-09-06 |
| CVE-2005-1672 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Help Center Live allow remote attackers to inject arbitrary web script or HTML via the (1) find… | Patch early | 4.3 medium | 2.7% | 2005-05-19 |
| CVE-1999-1235 EXP | Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information… | Patch early | 4.6 medium | 2.7% | 1999-08-25 |
| CVE-2018-6130 EXP | Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds… | Patch early | 6.5 medium | 2.7% | 2019-06-27 |
| CVE-2012-0902 EXP | AirTies Air 4450 1.1.2.18 allows remote attackers to cause a denial of service (reboot) via a direct request to cgi-bin/loader. | Patch early | 5.0 medium | 2.7% | 2012-01-20 |
| CVE-2009-2151 EXP | Directory traversal vulnerability in index.php in AdaptWeb 0.9.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the newlang par… | Patch early | 5.0 medium | 2.7% | 2009-06-22 |
| CVE-2020-35416 EXP | Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with differen… | Patch early | 6.1 medium | 2.7% | 2020-12-15 |
| CVE-2005-3547 EXP | Cross-site scripting (XSS) vulnerability in Invision Power Board 2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) adsess… | Patch early | 4.3 medium | 2.7% | 2005-11-16 |
| CVE-2007-5221 EXP | PHP remote file inclusion vulnerability in mail/childwindow.inc.php in Poppawid 2.7 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 6.8 medium | 2.7% | 2007-10-05 |
| CVE-2014-3138 EXP | SQL injection vulnerability in Xerox DocuShare before 6.53 Patch 6 Hotfix 2, 6.6.1 Update 1 before Hotfix 24, and 6.6.1 Update 2 before Hotfix 3 allow… | Patch early | 6.5 medium | 2.7% | 2014-05-02 |
| CVE-2004-1788 EXP | ASP-Nuke 1.3 and earlier places user credentials under the web document root with insufficient access control, which allows remote attackers to obtain… | Patch early | 5.0 medium | 2.7% | 2004-12-31 |
| CVE-2013-4727 EXP | DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive in… | Patch early | 5.0 medium | 2.7% | 2014-06-06 |
| CVE-2011-5184 EXP | Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i 9.10 allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 2.7% | 2012-09-20 |
| CVE-2012-6038 EXP | admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which allows remo… | Patch early | 6.5 medium | 2.7% | 2012-11-26 |
| CVE-2015-7252 EXP | Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to… | Patch early | 6.1 medium | 2.7% | 2015-12-30 |
| CVE-2007-0353 EXP | Cross-site scripting (XSS) vulnerability in (1) index.php and (2) login.php in myBloggie 2.1.5 allows remote attackers to inject arbitrary web script… | Patch early | 6.8 medium | 2.7% | 2007-01-19 |
| CVE-2018-6129 EXP | Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory acce… | Patch early | 6.5 medium | 2.7% | 2019-06-27 |
| CVE-2009-2159 EXP | backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and download… | Patch early | 6.4 medium | 2.7% | 2009-06-22 |
| CVE-2021-25679 EXP | The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. These issues impact at minimum… | Patch early | 5.4 medium | 2.7% | 2021-04-20 |
| CVE-2008-0297 EXP | PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its out… | Patch early | 5.0 medium | 2.7% | 2008-01-16 |
| CVE-2005-1402 EXP | Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows re… | Patch early | 5.0 medium | 2.7% | 2005-05-03 |
| CVE-2008-5105 EXP | KarjaSoft Sami FTP Server 2.0.x allows remote attackers to cause a denial of service (daemon crash or hang) via certain (1) APPE, (2) CWD, (3) DELE, (… | Patch early | 5.0 medium | 2.7% | 2008-11-17 |
| CVE-2008-6185 EXP | NoticeWare Email Server NG 5.1.2.2 allows remote attackers to cause a denial of service (crash) via multiple POP3 requests with a long PASS command. | Patch early | 5.0 medium | 2.7% | 2009-02-19 |
| CVE-2014-0984 EXP | The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation of a Route Permission Table en… | Patch early | 4.3 medium | 2.7% | 2014-04-17 |
| CVE-2007-6546 EXP | RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id. | Patch early | 6.4 medium | 2.7% | 2007-12-28 |
| CVE-2018-10309 EXP | The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS. | Patch early | 5.4 medium | 2.7% | 2018-04-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt