CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,033 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
169,914 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-12352 EXP | Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access. | Patch early | 6.5 medium | 5.7% | 2020-11-23 |
| CVE-2006-5418 EXP | PHP remote file inclusion vulnerability in archive/archive_topic.php in pbpbb archive for search engines (SearchIndexer) (aka phpBBSEI) for phpBB allo… | Patch early | 6.8 medium | 5.7% | 2006-10-20 |
| CVE-2010-4647 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remot… | Patch early | 4.3 medium | 5.7% | 2011-01-13 |
| CVE-2001-0491 EXP | Directory traversal vulnerability in RaidenFTPD Server 2.1 before build 952 allows attackers to access files outside the ftp root via dot dot attacks,… | Patch early | 5.0 medium | 5.7% | 2001-06-27 |
| CVE-2008-0239 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote attackers to in… | Patch early | 4.3 medium | 5.7% | 2008-01-11 |
| CVE-2006-4074 EXP | PHP remote file inclusion vulnerability in lib/tpl/default/main.php in the JD-Wiki Component (com_jd-wiki) 1.0.2 and earlier for Joomla!, when registe… | Patch early | 6.8 medium | 5.7% | 2006-08-11 |
| CVE-2007-6558 EXP | TotalPlayer 3.0 allows user-assisted remote attackers to cause a denial of service (application crash) via a large .m3u file. NOTE: this might be a d… | Patch early | 4.3 medium | 5.7% | 2007-12-28 |
| CVE-2006-0663 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 5.7% | 2006-02-13 |
| CVE-2008-1353 EXP | zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum comman… | Patch early | 4.3 medium | 5.7% | 2008-03-17 |
| CVE-2014-0871 EXP | RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to obtain potentially s… | Patch early | 4.3 medium | 5.7% | 2014-07-07 |
| CVE-2010-2920 EXP | Directory traversal vulnerability in the Foobla Suggestions (com_foobla_suggestions) component 1.5.1.2 for Joomla! allows remote attackers to read arb… | Patch early | 6.8 medium | 5.7% | 2010-07-30 |
| CVE-2006-7127 EXP | Multiple PHP remote file inclusion vulnerabilities in JAF CMS 4.0 and 4.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the ma… | Patch early | 6.8 medium | 5.7% | 2007-03-06 |
| CVE-2004-2449 EXP | Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial of service (application crash)… | Patch early | 5.0 medium | 5.7% | 2004-12-31 |
| CVE-2014-6047 EXP | phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an a… | Patch early | 5.3 medium | 5.7% | 2018-08-28 |
| CVE-2014-6048 EXP | phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request. | Patch early | 5.3 medium | 5.7% | 2018-08-28 |
| CVE-2007-0059 EXP | Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem c… | Patch early | 6.8 medium | 5.7% | 2007-01-05 |
| CVE-2008-2304 EXP | Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows user-assisted attackers to execut… | Patch early | 6.8 medium | 5.7% | 2008-07-14 |
| CVE-2002-0926 EXP | Directory traversal vulnerability in Wolfram Research webMathematica 1.0.0 and 1.0.0.1 allows remote attackers to read arbitrary files via a .. (dot d… | Patch early | 5.0 medium | 5.7% | 2002-10-04 |
| CVE-2003-0153 EXP | bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.cgi, (2) cvsview2.cgi, or (3)… | Patch early | 5.0 medium | 5.7% | 2003-04-02 |
| CVE-2019-9213 EXP | In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to e… | Patch early | 5.5 medium | 5.7% | 2019-03-05 |
| CVE-2019-8924 EXP | XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued. | Patch early | 6.1 medium | 5.7% | 2019-05-17 |
| CVE-2007-6478 EXP | Stack-based buffer overflow in Rosoft Media Player 4.1.7, 4.1.8, and possibly earlier versions allows remote attackers to execute arbitrary code or ca… | Patch early | 6.8 medium | 5.7% | 2007-12-20 |
| CVE-2005-0409 EXP | CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit… | Patch early | 6.4 medium | 5.7% | 2005-02-14 |
| CVE-2018-17441 EXP | An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to sto… | Patch early | 6.1 medium | 5.7% | 2018-10-08 |
| CVE-2018-17443 EXP | An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateSite endpoint is vulnerable to… | Patch early | 6.1 medium | 5.7% | 2018-10-08 |
| CVE-2006-7141 EXP | Absolute path traversal vulnerability in Oracle Database Server, when utl_file_dir is set to a wildcard value or "CREATE ANY DIRECTORY to PUBLIC" priv… | Patch early | 6.0 medium | 5.7% | 2007-03-07 |
| CVE-2017-14085 EXP | Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to q… | Patch early | 5.3 medium | 5.7% | 2017-10-06 |
| CVE-2007-1126 EXP | Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a .. (dot dot) in the template parame… | Patch early | 5.0 medium | 5.6% | 2007-02-27 |
| CVE-1999-0746 EXP | A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service. | Patch early | 5.0 medium | 5.6% | 1999-08-16 |
| CVE-1999-0804 EXP | Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths. | Patch early | 5.0 medium | 5.6% | 1999-06-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt