CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,599 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2000-0381 EXP | The Gossamer Threads DBMan db.cgi CGI script allows remote attackers to view environmental variables and setup information by referencing a non-existi… | Patch early | 6.4 medium | 2.6% | 2000-05-05 |
| CVE-2007-3327 EXP | httpsv.exe in HTTP Server 1.6.2 allows remote attackers to obtain sensitive information (script source code) via a URI with a trailing %20 (encoded sp… | Patch early | 5.0 medium | 2.6% | 2007-06-21 |
| CVE-1999-0915 EXP | URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 5.0 medium | 2.6% | 1999-10-28 |
| CVE-2004-1551 EXP | Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbitrary web s… | Patch early | 4.3 medium | 2.6% | 2004-12-31 |
| CVE-2005-0842 EXP | Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1… | Patch early | 4.3 medium | 2.6% | 2005-05-02 |
| CVE-2017-12971 EXP | Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the account paramete… | Patch early | 6.1 medium | 2.6% | 2017-08-23 |
| CVE-2018-19041 EXP | The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI. | Patch early | 6.1 medium | 2.6% | 2019-01-31 |
| CVE-2022-47877 EXP | A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in the Logs pa… | Patch early | 5.4 medium | 2.6% | 2023-05-02 |
| CVE-2010-4330 EXP | Directory traversal vulnerability in includes/controller.php in Pulse CMS Basic before 1.2.9 allows remote attackers to include and execute arbitrary… | Patch early | 6.8 medium | 2.6% | 2010-12-07 |
| CVE-2011-4831 EXP | Directory traversal vulnerability in webFileBrowser.php in Web File Browser 0.4b14 allows remote authenticated users to read arbitrary files via a ..%… | Patch early | 4.0 medium | 2.6% | 2011-12-15 |
| CVE-2018-11443 EXP | The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0. | Patch early | 6.1 medium | 2.6% | 2018-05-25 |
| CVE-2023-23286 EXP | Cross Site Scripting (XSS) vulnerability in Provide server 14.4 allows attackers to execute arbitrary code through the server-log via username field f… | Patch early | 6.1 medium | 2.6% | 2023-02-10 |
| CVE-2006-4723 EXP | PHP remote file inclusion vulnerability in raidenhttpd-admin/slice/check.php in RaidenHTTPD 1.1.49, when register_globals and WebAdmin is enabled, all… | Patch early | 5.1 medium | 2.6% | 2006-09-12 |
| CVE-2006-4945 EXP | Multiple PHP remote file inclusion vulnerabilities in Cardway (aka Frederic Boudaud) DigitalWebShop 1.128 and earlier allow remote attackers to execut… | Patch early | 5.1 medium | 2.6% | 2006-09-23 |
| CVE-2006-4946 EXP | PHP remote file inclusion vulnerability in include/startup.inc.php in CMSDevelopment Business Card Web Builder (BCWB) 0.99, and possibly 2.5 Beta and… | Patch early | 5.1 medium | 2.6% | 2006-09-23 |
| CVE-2006-5165 EXP | PHP remote file inclusion vulnerability in inc/functions.inc.php in Skrypty PPA Gallery 1.0 and earlier allows remote attackers to execute arbitrary P… | Patch early | 5.1 medium | 2.6% | 2006-10-05 |
| CVE-2006-5284 EXP | PHP remote file inclusion vulnerability in auth/phpbb.inc.php in Shen Cheng-Da PHP News Reader (aka pnews) 2.6.4 and earlier allows remote attackers t… | Patch early | 5.1 medium | 2.6% | 2006-10-13 |
| CVE-2002-0333 EXP | Directory traversal vulnerability in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to read files with short names, an… | Patch early | 5.0 medium | 2.6% | 2002-06-25 |
| CVE-2005-2085 EXP | Buffer overflow in Inframail Advantage Server Edition 6.0 through 6.7 allows remote attackers to cause a denial of service (process crash) via a long… | Patch early | 5.0 medium | 2.6% | 2005-07-05 |
| CVE-2010-4099 EXP | ess.pm in NitroSecurity NitroView ESM 8.4.0a, when ESSPMDebug is enabled, allows remote attackers to execute arbitrary commands via shell metacharacte… | Patch early | 6.8 medium | 2.6% | 2010-10-27 |
| CVE-2018-18760 EXP | RhinOS 3.0 build 1190 allows CSRF. | Patch early | 6.5 medium | 2.6% | 2018-11-16 |
| CVE-2019-11564 EXP | A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HTML via a /protected/vendor/cod… | Patch early | 6.1 medium | 2.6% | 2019-05-08 |
| CVE-2017-8382 EXP | admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user accounts. | Patch early | 4.5 medium | 2.6% | 2017-05-16 |
| CVE-2006-6597 EXP | Argument injection vulnerability in HyperAccess 8.4 allows user-assisted remote attackers to execute arbitrary vbscript and commands via the /r option… | Patch early | 6.8 medium | 2.6% | 2006-12-15 |
| CVE-2003-1381 EXP | Format string vulnerability in AMX 0.9.2 and earlier, a plugin for Valve Software's Half-Life Server, allows remote attackers to execute arbitrary com… | Patch early | 6.8 medium | 2.6% | 2003-12-31 |
| CVE-2005-3200 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 2.6% | 2005-10-14 |
| CVE-2017-9813 EXP | In Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312), the scriptName parameter of the licenseKey… | Patch early | 6.1 medium | 2.6% | 2017-07-17 |
| CVE-2005-0632 EXP | PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the… | Patch early | 5.0 medium | 2.6% | 2005-03-01 |
| CVE-2006-0473 EXP | Cross-site scripting (XSS) vulnerability in the bbcode function in weblog.php in my little homepage my little weblog, as last modified in April 2004,… | Patch early | 4.3 medium | 2.6% | 2006-01-31 |
| CVE-2010-1544 EXP | micro_httpd on the RCA DCM425 cable modem allows remote attackers to cause a denial of service (device reboot) via a long string to TCP port 80. | Patch early | 5.0 medium | 2.6% | 2010-04-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt