CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,973 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
169,893 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-5765 EXP | WorkSimple 1.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the datab… | Patch early | 5.0 medium | 5.9% | 2008-12-30 |
| CVE-2008-6872 EXP | ASPThai.NET ASPThai Forums 8.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to down… | Patch early | 5.0 medium | 5.9% | 2009-07-23 |
| CVE-2023-23161 EXP | A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts o… | Patch early | 6.1 medium | 5.9% | 2023-02-10 |
| CVE-2008-5862 EXP | Directory traversal vulnerability in webcamXP 5.3.2.375 and 5.3.2.410 build 2132 allows remote attackers to read arbitrary files via a ..%2F (encoded… | Patch early | 5.0 medium | 5.9% | 2009-01-06 |
| CVE-2006-1779 EXP | Cross-site scripting (XSS) vulnerability in login.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to inject arbitrary web scr… | Patch early | 6.8 medium | 5.9% | 2006-04-13 |
| CVE-2006-3773 EXP | PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and Mambo 4.5.3+ allows remote atta… | Patch early | 6.8 medium | 5.9% | 2006-07-24 |
| CVE-2008-6770 EXP | YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to a datab… | Patch early | 5.0 medium | 5.9% | 2009-04-29 |
| CVE-2008-6771 EXP | YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a direct request to user/uploads/p… | Patch early | 5.0 medium | 5.9% | 2009-04-29 |
| CVE-2009-3646 EXP | InterVations NaviCOPA Web Server 3.01 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DAT… | Patch early | 5.0 medium | 5.9% | 2009-10-09 |
| CVE-2018-15917 EXP | Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter… | Patch early | 5.4 medium | 5.9% | 2018-09-05 |
| CVE-2002-1530 EXP | The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a req… | Patch early | 5.0 medium | 5.9% | 2003-03-31 |
| CVE-2009-2044 EXP | Mozilla Firefox 3.0.10 and earlier on Linux allows remote attackers to cause a denial of service (application crash) via a URI for a large GIF image i… | Patch early | 4.3 medium | 5.9% | 2009-06-12 |
| CVE-2013-4095 EXP | plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users… | Patch early | 6.5 medium | 5.9% | 2013-06-28 |
| CVE-2021-41318 EXP | In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthen… | Patch early | 6.1 medium | 5.9% | 2021-09-28 |
| CVE-2001-0214 EXP | Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with… | Patch early | 5.0 medium | 5.9% | 2001-06-02 |
| CVE-2013-6246 EXP | The Dell Quest One Password Manager, possibly 5.0, allows remote attackers to bypass CAPTCHA protections and obtain sensitive information (user's full… | Patch early | 5.0 medium | 5.9% | 2013-10-24 |
| CVE-2006-6042 EXP | PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 and earlier, when register_globals is enabled, allows remote attacker… | Patch early | 6.8 medium | 5.9% | 2006-11-22 |
| CVE-2003-0314 EXP | Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) via a URL that ends in a "</" sequence. | Patch early | 6.4 medium | 5.9% | 2003-06-16 |
| CVE-2005-0952 EXP | Cross-site scripting vulnerability in pafiledb.php in PaFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter… | Patch early | 5.0 medium | 5.9% | 2005-05-02 |
| CVE-2006-3774 EXP | PHP remote file inclusion vulnerability in performs.php in the perForms component (com_performs) 1.0 and earlier for Joomla! allows remote attackers t… | Patch early | 6.8 medium | 5.9% | 2006-07-24 |
| CVE-2002-2032 EXP | sql_layer.php in PHP-Nuke 5.4 and earlier does not restrict access to debugging features, which allows remote attackers to gain SQL query information… | Patch early | 5.0 medium | 5.9% | 2002-12-31 |
| CVE-2011-1956 EXP | The bytes_repr_len function in Wireshark 1.4.5 uses an incorrect pointer argument, which allows remote attackers to cause a denial of service (NULL po… | Patch early | 4.3 medium | 5.9% | 2011-06-06 |
| CVE-2007-1690 EXP | Multiple stack-based buffer overflows in Second Sight Software ActiveGS ActiveX control (ActiveGS.ocx) allow remote attackers to execute arbitrary cod… | Patch early | 6.8 medium | 5.9% | 2007-04-19 |
| CVE-2007-1691 EXP | Stack-based buffer overflow in Second Sight Software ActiveMod ActiveX control (ActiveMod.ocx) allows remote attackers to execute arbitrary code via u… | Patch early | 6.8 medium | 5.9% | 2007-04-19 |
| CVE-2008-7216 EXP | Peter's Math Anti-Spam Spinoff plugin for WordPress generates audio CAPTCHA clips by concatenating static audio files without any additional distortio… | Patch early | 4.3 medium | 5.8% | 2009-09-11 |
| CVE-2012-5470 EXP | libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted PNG file. | Patch early | 4.3 medium | 5.8% | 2012-10-26 |
| CVE-2006-1584 EXP | Unspecified vulnerability in index.php in Warcraft III Replay Parser for PHP 1.8c allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 6.4 medium | 5.8% | 2006-04-02 |
| CVE-1999-0215 EXP | Routed allows attackers to append data to files. | Patch early | 6.4 medium | 5.8% | 1998-10-26 |
| CVE-2014-3439 EXP | ConsoleServlet in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to write to arbitrary files via unspecified vect… | Patch early | 6.1 medium | 5.8% | 2014-11-07 |
| CVE-2005-3189 EXP | Directory traversal vulnerability in Qualcomm WorldMail IMAP Server allows remote attackers to read arbitrary email messages via ".." sequences in the… | Patch early | 5.0 medium | 5.8% | 2005-11-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt