CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,851 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-1999-0925 EXP | UnityMail allows remote attackers to conduct a denial of service via a large number of MIME headers. | Patch early | 5.0 medium | 2.4% | 1999-09-03 |
| CVE-2014-9101 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall 1.7.0 (build 7907 and 7906) and SkaDate Lite 2.0 (build 7651) allow remote attack… | Patch early | 6.8 medium | 2.4% | 2014-11-26 |
| CVE-2009-0769 EXP | QIP 2005 build 8082 allows remote attackers to cause a denial of service (CPU consumption and application hang) via a crafted Rich Text Format (RTF) I… | Patch early | 4.3 medium | 2.4% | 2009-03-06 |
| CVE-2009-1825 EXP | modules/admuser.php in myColex 1.4.2 does not require administrative authentication, which allows remote authenticated users to list user accounts via… | Patch early | 4.0 medium | 2.4% | 2009-05-29 |
| CVE-2008-7032 EXP | Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote attackers to hij… | Patch early | 6.8 medium | 2.4% | 2009-08-24 |
| CVE-2007-0499 EXP | PHP remote file inclusion vulnerability in config.php in Sangwan Kim phpIndexPage 1.0.1 and earlier allows remote attackers to execute arbitrary PHP c… | Patch early | 6.8 medium | 2.4% | 2007-01-25 |
| CVE-2017-16807 EXP | A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exists when displaying a specially… | Patch early | 5.4 medium | 2.4% | 2017-11-13 |
| CVE-2008-2943 EXP | Double free vulnerability in IBM Tivoli Directory Server (TDS) 6.1.0.0 through 6.1.0.15 allows remote authenticated administrators to cause a denial o… | Patch early | 6.0 medium | 2.4% | 2008-06-30 |
| CVE-2006-0786 EXP | Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attackers to cond… | Patch early | 5.1 medium | 2.4% | 2006-02-19 |
| CVE-2006-4065 EXP | Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko SAPID Gallery 1.0 and earlier allow remote attackers to execute arbitrary PHP code… | Patch early | 5.1 medium | 2.4% | 2006-08-10 |
| CVE-2013-5118 EXP | Cross-site scripting (XSS) vulnerability in the Good for Enterprise app before 2.2.4.1659 for iOS allows remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 2.4% | 2013-09-25 |
| CVE-2007-1514 EXP | PHP remote file inclusion vulnerability in index.php in ViperWeb Portal alpha 0.1 allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 6.8 medium | 2.4% | 2007-03-20 |
| CVE-2005-1655 EXP | AOL Instant Messenger 5.5.x and earlier allows remote attackers to cause a denial of service (client crash) via an invalid smiley icon location in the… | Patch early | 5.0 medium | 2.4% | 2005-05-18 |
| CVE-2006-2577 EXP | Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute ar… | Patch early | 5.1 medium | 2.4% | 2006-05-24 |
| CVE-2004-1828 EXP | Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and d… | Patch early | 5.0 medium | 2.4% | 2004-12-31 |
| CVE-2007-0501 EXP | PHP remote file inclusion vulnerability in index.php in Mafia Scum Tools 2.0.0 in Matthew Wardrop Advanced Random Generators (adv-random-gen) allows r… | Patch early | 6.8 medium | 2.4% | 2007-01-25 |
| CVE-2007-6547 EXP | RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords… | Patch early | 6.8 medium | 2.4% | 2007-12-28 |
| CVE-2011-4595 EXP | Pretty-Link WordPress plugin 1.5.2 has XSS | Patch early | 6.1 medium | 2.4% | 2020-01-10 |
| CVE-2002-1533 EXP | Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to… | Patch early | 5.8 medium | 2.4% | 2003-03-31 |
| CVE-2007-6501 EXP | Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type" via a re… | Patch early | 5.5 medium | 2.4% | 2007-12-20 |
| CVE-2009-4048 EXP | Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (daemon outage) via an APPE command to one so… | Patch early | 4.0 medium | 2.4% | 2009-11-23 |
| CVE-2008-6643 EXP | LokiCMS 0.3.4 and possibly earlier versions does not properly restrict access to administrative functions, which allows remote attackers to bypass int… | Patch early | 5.0 medium | 2.4% | 2009-04-07 |
| CVE-2013-1742 EXP | Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7;… | Patch early | 4.3 medium | 2.4% | 2013-10-24 |
| CVE-2005-0776 EXP | adm-photo.php in PhotoPost PHP 5.0 RC3 does not properly verify administrative privileges before manipulating photos, which could allow remote attacke… | Patch early | 5.0 medium | 2.4% | 2005-05-02 |
| CVE-2007-4089 EXP | Vikingboard 0.1.2 allows remote attackers to obtain sensitive information via the debug parameter to (1) forum.php, (2) cp.php, and possibly other uns… | Patch early | 4.3 medium | 2.4% | 2007-07-30 |
| CVE-2007-1580 EXP | FTPDMIN 0.96 allows remote attackers to cause a denial of service (daemon crash) via a LIST command for a Windows drive letter, as demonstrated using… | Patch early | 6.3 medium | 2.4% | 2007-03-21 |
| CVE-2014-2017 EXP | CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x befor… | Patch early | 6.1 medium | 2.4% | 2018-01-18 |
| CVE-2008-0724 EXP | The Everything Development Engine in The Everything Development System Pre-1.0 and earlier stores passwords in cleartext in a database, which makes it… | Patch early | 5.0 medium | 2.4% | 2008-02-12 |
| CVE-2019-18859 EXP | Digi AnywhereUSB 14 allows XSS via a link for the Digi Page. | Patch early | 6.1 medium | 2.4% | 2020-01-09 |
| CVE-2006-1323 EXP | Directory traversal vulnerability in WinHKI 1.6 and earlier allows user-assisted attackers to overwrite arbitrary files via a (1) RAR, (2) TAR, (3) ZI… | Patch early | 5.1 medium | 2.4% | 2006-03-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt