CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,599 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-4460 EXP | Cross-site request forgery (CSRF) vulnerability in SecuritySetting/UserSecurity/UserManagement.aspx in B.A.S C2Box before 4.0.0 (r19171) allows remote… | Patch early | 6.8 medium | 2.7% | 2015-07-16 |
| CVE-2014-5346 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin 2.77 for WordPress allow remote attackers to hijack the… | Patch early | 6.8 medium | 2.7% | 2014-08-19 |
| CVE-2010-1734 EXP | The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (s… | Patch early | 4.9 medium | 2.7% | 2010-05-06 |
| CVE-2010-4313 EXP | Unrestricted file upload vulnerability in fileman_file_upload.php in Orbis CMS 1.0.2 allows remote authenticated users to execute arbitrary code by up… | Patch early | 6.0 medium | 2.7% | 2010-12-02 |
| CVE-2010-4258 EXP | The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users… | Patch early | 6.2 medium | 2.7% | 2010-12-30 |
| CVE-2007-1138 EXP | Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directo… | Patch early | 5.0 medium | 2.7% | 2007-03-02 |
| CVE-2006-6598 EXP | Directory traversal vulnerability in viewnfo.php in (1) TorrentFlux before 2.2 and (2) torrentflux-b4rt before 2.1-b4rt-972 allows remote authenticate… | Patch early | 6.5 medium | 2.7% | 2006-12-15 |
| CVE-2009-3662 EXP | FileCopa FTP Server 5.01 allows remote attackers to cause a denial of service (server hang) via a large number of crafted NOOP commands. | Patch early | 5.0 medium | 2.7% | 2009-10-11 |
| CVE-2008-1854 EXP | Unspecified vulnerability in SmarterMail Web Server (SMWebSvr.exe) in SmarterMail 5.0.2999 allows remote attackers to cause a denial of service (servi… | Patch early | 5.0 medium | 2.7% | 2008-04-16 |
| CVE-2002-2258 EXP | Moby NetSuite allows remote attackers to cause a denial of service (crash) via an HTTP POST request with a (1) large integer or (2) non-numeric value… | Patch early | 5.0 medium | 2.7% | 2002-12-31 |
| CVE-2006-5016 EXP | Unrestricted file upload vulnerability in admin/x_image.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, allows remote attackers to uplo… | Patch early | 5.0 medium | 2.7% | 2006-09-27 |
| CVE-2006-4721 EXP | Directory traversal vulnerability in admin.php in CCleague Pro Sports CMS 1.0.1 RC1 allows remote attackers to read and execute arbitrary local files… | Patch early | 5.1 medium | 2.7% | 2006-09-12 |
| CVE-2007-1516 EXP | PHP remote file inclusion vulnerability in functions/update.php in Cicoandcico CcMail 1.0 allows remote attackers to execute arbitrary PHP code via a… | Patch early | 6.8 medium | 2.7% | 2007-03-20 |
| CVE-2007-1907 EXP | PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attackers to execute arbitrary PHP… | Patch early | 6.8 medium | 2.7% | 2007-04-10 |
| CVE-2008-3368 EXP | PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to exe… | Patch early | 6.5 medium | 2.7% | 2008-07-30 |
| CVE-2009-0673 EXP | Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.30 allows remote authenticated… | Patch early | 6.5 medium | 2.7% | 2009-02-22 |
| CVE-2014-8674 EXP | Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and mb… | Patch early | 5.4 medium | 2.6% | 2020-01-06 |
| CVE-2002-2351 EXP | Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with names containing a trailing ".… | Patch early | 6.4 medium | 2.6% | 2002-12-31 |
| CVE-2014-9236 EXP | Cross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allows remote attackers to injec… | Patch early | 4.3 medium | 2.6% | 2014-12-03 |
| CVE-2022-2846 EXP | The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is a… | Patch early | 4.3 medium | 2.6% | 2022-08-16 |
| CVE-2011-1872 EXP | Hyper-V in Microsoft Windows Server 2008 Gold, SP2, R2, and R2 SP1 allows guest OS users to cause a denial of service (host OS infinite loop) via malf… | Patch early | 4.7 medium | 2.6% | 2011-06-16 |
| CVE-2016-6851 EXP | An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX Guard guest reader web applicat… | Patch early | 6.1 medium | 2.6% | 2016-12-15 |
| CVE-2013-6128 EXP | The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict SaveTo… | Patch early | 5.8 medium | 2.6% | 2013-10-25 |
| CVE-2007-3535 EXP | Multiple directory traversal vulnerabilities in GL-SH Deaf Forum 6.4.4 and earlier allow remote attackers to include and execute arbitrary local files… | Patch early | 6.4 medium | 2.6% | 2007-07-03 |
| CVE-2005-0936 EXP | Cross-site scripting vulnerability in products1h.php in ESMI PayPal Storefront allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 5.0 medium | 2.6% | 2005-05-02 |
| CVE-2006-2608 EXP | artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute a… | Patch early | 5.1 medium | 2.6% | 2006-05-26 |
| CVE-2009-4224 EXP | Multiple PHP remote file inclusion vulnerabilities in SweetRice 0.5.4, 0.5.3, and earlier allow remote attackers to execute arbitrary PHP code via a U… | Patch early | 6.8 medium | 2.6% | 2009-12-07 |
| CVE-2012-1900 EXP | Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authentication… | Patch early | 6.8 medium | 2.6% | 2012-10-22 |
| CVE-2014-4162 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote attackers to hijack the authentic… | Patch early | 6.8 medium | 2.6% | 2014-06-16 |
| CVE-2014-7281 EXP | Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hija… | Patch early | 6.8 medium | 2.6% | 2014-10-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt