CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,014 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
169,903 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-2292 EXP | Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4… | Patch early | 6.5 medium | 5.8% | 2015-03-17 |
| CVE-2014-4311 EXP | Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows attackers to obtain the (1) Database Connection and (2) E-mail Connection passwords by read… | Patch early | 5.0 medium | 5.8% | 2014-11-04 |
| CVE-2008-6982 EXP | Cross-site scripting (XSS) vulnerability in index.php in devalcms 1.4a allows remote attackers to inject arbitrary web script or HTML via the currentp… | Patch early | 4.3 medium | 5.8% | 2009-08-19 |
| CVE-2009-2820 EXP | The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2)… | Patch early | 4.3 medium | 5.8% | 2009-11-10 |
| CVE-2007-1622 EXP | Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote au… | Patch early | 4.3 medium | 5.8% | 2007-03-23 |
| CVE-2008-3234 EXP | sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux role… | Patch early | 6.5 medium | 5.8% | 2008-07-18 |
| CVE-2008-6958 EXP | wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula parameter. | Patch early | 6.5 medium | 5.8% | 2009-08-12 |
| CVE-2013-7280 EXP | Buffer overflow in HansoTools Hanso Player 2.1.0, 2.5.0, and earlier allows remote attackers to cause a denial of service (crash) via a long string in… | Patch early | 4.3 medium | 5.8% | 2014-01-08 |
| CVE-2004-1745 EXP | Buffer overflow in Painkiller 1.3.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a… | Patch early | 5.0 medium | 5.8% | 2004-08-24 |
| CVE-1999-0887 EXP | FTGate web interface server allows remote attackers to read files via a .. (dot dot) attack. | Patch early | 5.0 medium | 5.8% | 1999-11-04 |
| CVE-1999-0927 EXP | NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 5.0 medium | 5.8% | 1999-05-26 |
| CVE-1999-0933 EXP | TeamTrack web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 5.0 medium | 5.8% | 1999-10-01 |
| CVE-2017-2371 EXP | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" component, which allows remote attac… | Patch early | 6.5 medium | 5.8% | 2017-02-20 |
| CVE-2006-4198 EXP | PHP remote file inclusion vulnerability in includes/session.php in Wheatblog (wB) 1.1 and earlier, when register_globals is enabled, allows remote att… | Patch early | 5.1 medium | 5.8% | 2006-08-17 |
| CVE-2004-0527 EXP | KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that poin… | Patch early | 5.0 medium | 5.8% | 2004-08-06 |
| CVE-2002-1351 EXP | Buffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and possibly execute arbitrary co… | Patch early | 5.0 medium | 5.8% | 2002-12-24 |
| CVE-2007-4321 EXP | fail2ban 0.8 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and… | Patch early | 6.8 medium | 5.7% | 2007-08-14 |
| CVE-2007-0885 EXP | Cross-site scripting (XSS) vulnerability in jira/secure/BrowseProject.jspa in Rainbow with the Zen (Rainbow.Zen) extension allows remote attackers to… | Patch early | 6.8 medium | 5.7% | 2007-02-12 |
| CVE-2004-2277 EXP | Buffer overflow in aGSM Half-Life client allows remote Half-Life servers to cause a denial of service (crash) and possibly execute arbitrary code via… | Patch early | 5.0 medium | 5.7% | 2004-12-31 |
| CVE-2012-1025 EXP | Absolute path traversal vulnerability in file in Enigma2 Webinterface 1.6.0 through 1.6.8, 1.6rc3, and 1.7.0 allows remote attackers to read arbitrary… | Patch early | 5.0 medium | 5.7% | 2012-02-08 |
| CVE-2009-4032 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web script or HTML via vectors related… | Patch early | 4.3 medium | 5.7% | 2009-11-29 |
| CVE-2011-3502 EXP | The web server in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to obtain the source code of executable files via a request with a trail… | Patch early | 5.0 medium | 5.7% | 2011-09-16 |
| CVE-2004-0763 EXP | Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunloa… | Patch early | 5.0 medium | 5.7% | 2004-08-18 |
| CVE-2005-1507 EXP | Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute arbitrary co… | Patch early | 5.0 medium | 5.7% | 2005-05-11 |
| CVE-2005-1403 EXP | Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to inject arbitrary web script or… | Patch early | 6.8 medium | 5.7% | 2005-05-03 |
| CVE-2012-0200 EXP | The server in IBM solidDB 6.5 before Interim Fix 6 does not properly initialize data structures, which allows remote authenticated users to cause a de… | Patch early | 4.0 medium | 5.7% | 2012-02-21 |
| CVE-2022-0448 EXP | The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform… | Patch early | 4.8 medium | 5.7% | 2022-03-07 |
| CVE-2005-1013 EXP | The SMTP service in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to cause a denial of service (ser… | Patch early | 5.0 medium | 5.7% | 2005-05-02 |
| CVE-2021-24245 EXP | The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an… | Patch early | 6.1 medium | 5.7% | 2021-05-06 |
| CVE-2008-1702 EXP | Absolute path traversal vulnerability in dload.php in the my_gallery 2.3 plugin for e107 allows remote attackers to obtain sensitive information via a… | Patch early | 4.3 medium | 5.7% | 2008-04-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt