CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,899 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-5072 EXP | vsfilter.dll in K-Lite Mega Codec Pack 3.5.7.0 allows remote attackers to cause a denial of service (application crash) via a malformed FLV file. | Patch early | 4.3 medium | 2.4% | 2008-11-14 |
| CVE-2018-7198 EXP | October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page. | Patch early | 6.1 medium | 2.3% | 2018-02-18 |
| CVE-2009-3167 EXP | Directory traversal vulnerability in index.php in Anantasoft Gazelle CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbit… | Patch early | 4.3 medium | 2.3% | 2009-09-11 |
| CVE-2008-4041 EXP | The IMAP server in Softalk Mail Server (formerly WorkgroupMail) 8.5.1.431 allows remote authenticated users to cause a denial of service (resource con… | Patch early | 4.0 medium | 2.3% | 2008-09-11 |
| CVE-2004-2128 EXP | Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as other users via the query string… | Patch early | 6.8 medium | 2.3% | 2004-12-31 |
| CVE-2012-5331 EXP | Directory traversal vulnerability in asaanCart 0.9 allows remote attackers to include arbitrary local files via a .. (dot dot) in the page parameter t… | Patch early | 6.8 medium | 2.3% | 2012-10-08 |
| CVE-2009-3823 EXP | Directory traversal vulnerability in myhtml.php in Mobilelib GOLD 3.0, when magic_quotes_gpc is enabled, allows remote attackers to read arbitrary fil… | Patch early | 4.3 medium | 2.3% | 2009-10-28 |
| CVE-2007-5796 EXP | Cross-site scripting (XSS) vulnerability in the management console in Blue Coat ProxySG before 4.2.6.1, and 5.x before 5.2.2.5, allows remote attacker… | Patch early | 4.3 medium | 2.3% | 2007-11-03 |
| CVE-2008-4187 EXP | Directory traversal vulnerability in index.php in ProActive CMS allows remote attackers to read arbitrary files via a .. (dot dot) in the template par… | Patch early | 4.3 medium | 2.3% | 2008-09-23 |
| CVE-2009-4426 EXP | Multiple directory traversal vulnerabilities in Ignition 1.2, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitra… | Patch early | 6.8 medium | 2.3% | 2009-12-28 |
| CVE-2005-1951 EXP | Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web… | Patch early | 5.0 medium | 2.3% | 2005-06-16 |
| CVE-2009-0392 EXP | Directory traversal vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to read arbitrary files via a .. (d… | Patch early | 6.8 medium | 2.3% | 2009-02-03 |
| CVE-2014-9344 EXP | Cross-site request forgery (CSRF) vulnerability in Snowfox CMS before 1.0.10 allows remote attackers to hijack the authentication of administrators fo… | Patch early | 6.8 medium | 2.3% | 2014-12-08 |
| CVE-2009-4553 EXP | Stack-based buffer overflow in iRehearse allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other i… | Patch early | 5.0 medium | 2.3% | 2010-01-04 |
| CVE-2018-0832 EXP | The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Serv… | Patch early | 4.7 medium | 2.3% | 2018-02-15 |
| CVE-2018-0894 EXP | The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold… | Patch early | 4.7 medium | 2.3% | 2018-03-14 |
| CVE-2018-0897 EXP | The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold… | Patch early | 4.7 medium | 2.3% | 2018-03-14 |
| CVE-2008-1564 EXP | Directory traversal vulnerability in Dan Costin File Transfer before 1.2f allows remote attackers to read arbitrary files via a "..\" (dot dot backsla… | Patch early | 4.3 medium | 2.3% | 2008-03-31 |
| CVE-2013-3961 EXP | SQL injection vulnerability in edit_event.php in Simple PHP Agenda before 2.2.9 allows remote authenticated users to execute arbitrary SQL commands vi… | Patch early | 6.5 medium | 2.3% | 2014-03-11 |
| CVE-2011-3393 EXP | Multiple cross-site scripting (XSS) vulnerabilities in findagent.php in MYRE Real Estate Software allow remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 2.3% | 2011-09-15 |
| CVE-2019-10261 EXP | CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fields via a "DNS Functions" "Edit… | Patch early | 4.8 medium | 2.3% | 2019-04-03 |
| CVE-2007-2086 EXP | Multiple PHP remote file inclusion vulnerabilities in CNStats 2.9 allow remote attackers to execute arbitrary PHP code via a URL in the bj parameter t… | Patch early | 6.8 medium | 2.3% | 2007-04-18 |
| CVE-2010-4835 EXP | Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via d… | Patch early | 4.0 medium | 2.3% | 2011-09-14 |
| CVE-2007-5321 EXP | Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers to include arbitrary files via… | Patch early | 6.8 medium | 2.3% | 2007-10-09 |
| CVE-2002-1704 EXP | Zeroboard 4.1, when the "allow_url_fopen" and "register_globals" variables are enabled, allows remote attackers to execute arbitrary PHP code by modif… | Patch early | 5.0 medium | 2.3% | 2002-12-31 |
| CVE-2004-0528 EXP | Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to th… | Patch early | 5.0 medium | 2.3% | 2004-08-06 |
| CVE-2007-0371 EXP | A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a… | Patch early | 4.3 medium | 2.3% | 2007-01-19 |
| CVE-2007-6270 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Absolute News Manager.NET 5.1 allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 2.3% | 2007-12-07 |
| CVE-2006-6563 EXP | Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1.3.1rc1 allows local users to… | Patch early | 6.6 medium | 2.3% | 2006-12-15 |
| CVE-2006-5838 EXP | PHP remote file inclusion vulnerability in lib/class.Database.php in NewP News Publication System 1.0.0, when register_globals is enabled, allows remo… | Patch early | 5.1 medium | 2.3% | 2006-11-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt