CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,208 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-6862 EXP | V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page i… | Patch early | 5.3 medium | 6.3% | 2020-01-17 |
| CVE-2013-6796 EXP | The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, which triggers an LDAP anonymous b… | Patch early | 5.0 medium | 6.3% | 2014-10-26 |
| CVE-2001-0778 EXP | OmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20). | Patch early | 5.0 medium | 6.3% | 2001-10-18 |
| CVE-2019-15083 EXP | Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Usi… | Patch early | 6.1 medium | 6.3% | 2020-05-14 |
| CVE-2005-1006 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SonicWALL SOHO 5.1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) th… | Patch early | 4.3 medium | 6.3% | 2005-05-02 |
| CVE-2007-0649 EXP | Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variable… | Patch early | 4.3 medium | 6.3% | 2007-02-01 |
| CVE-2009-0250 EXP | Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… | Patch early | 5.0 medium | 6.3% | 2009-01-22 |
| CVE-2008-5885 EXP | The Net Guys ASPired2Quote stores sensitive information under the web root with insufficient access control, which allows remote attackers to download… | Patch early | 5.0 medium | 6.3% | 2009-01-12 |
| CVE-2009-0645 EXP | Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) l… | Patch early | 6.5 medium | 6.3% | 2009-02-18 |
| CVE-2009-0858 EXP | The response_addname function in response.c in Daniel J. Bernstein djbdns 1.05 and earlier does not constrain offsets in the required manner, which al… | Patch early | 5.8 medium | 6.3% | 2009-03-09 |
| CVE-2005-3550 EXP | Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the i… | Patch early | 5.0 medium | 6.3% | 2005-11-16 |
| CVE-2006-0125 EXP | Unspecified vulnerability in appserv/main.php in AppServ 2.4.5 allows remote attackers to include arbitrary files via the appserv_root parameter. NOT… | Patch early | 5.0 medium | 6.3% | 2006-01-09 |
| CVE-2020-7656 EXP | jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that… | Patch early | 6.1 medium | 6.3% | 2020-05-19 |
| CVE-2007-0148 EXP | Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary c… | Patch early | 6.8 medium | 6.3% | 2007-01-09 |
| CVE-2008-6537 EXP | LightNEasy/lightneasy.php in LightNEasy No database version 1.2 allows remote attackers to obtain the hash of the administrator password via the setup… | Patch early | 5.0 medium | 6.3% | 2009-03-30 |
| CVE-2011-0745 EXP | SugarCRM before 6.1.3 does not properly handle reloads and direct requests for a warning page produced by a certain duplicate check, which allows remo… | Patch early | 4.0 medium | 6.3% | 2011-03-16 |
| CVE-2010-0496 EXP | FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch, allows remote attackers to cause a denial of service (daemon crash) v… | Patch early | 5.0 medium | 6.3% | 2010-02-03 |
| CVE-2008-7245 EXP | Opera 9.52 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "… | Patch early | 5.0 medium | 6.3% | 2009-09-18 |
| CVE-2015-1480 EXP | ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getT… | Patch early | 4.0 medium | 6.3% | 2015-02-04 |
| CVE-2014-5115 EXP | Absolute path traversal vulnerability in DirPHP 1.0 allows remote attackers to read arbitrary files via a full pathname in the phpfile parameter to in… | Patch early | 5.0 medium | 6.3% | 2014-07-29 |
| CVE-2009-2334 EXP | wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin,… | Patch early | 4.9 medium | 6.3% | 2009-07-10 |
| CVE-2004-1267 EXP | Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code… | Patch early | 6.5 medium | 6.3% | 2005-01-10 |
| CVE-2006-5714 EXP | Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary files under the web root by app… | Patch early | 5.0 medium | 6.3% | 2006-11-04 |
| CVE-2006-5715 EXP | Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrary files under the web root by… | Patch early | 5.0 medium | 6.3% | 2006-11-04 |
| CVE-2005-3894 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow… | Patch early | 4.3 medium | 6.3% | 2005-11-29 |
| CVE-2006-3530 EXP | PHP remote file inclusion vulnerability in com_pccookbook/pccookbook.php in the PccookBook Component for Mambo and Joomla 0.3 and possibly up to 1.3.1… | Patch early | 6.8 medium | 6.2% | 2006-07-12 |
| CVE-2006-3980 EXP | PHP remote file inclusion vulnerability in administrator/components/com_mgm/help.mgm.php in Mambo Gallery Manager (MGM) 0.95r2 and earlier for Mambo 4… | Patch early | 6.8 medium | 6.2% | 2006-08-05 |
| CVE-2007-5063 EXP | Adam Scheinberg Flip 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers t… | Patch early | 5.0 medium | 6.2% | 2007-09-24 |
| CVE-2007-6395 EXP | Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obta… | Patch early | 5.0 medium | 6.2% | 2007-12-17 |
| CVE-2009-1171 EXP | The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary… | Patch early | 4.3 medium | 6.2% | 2009-03-30 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt