CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,045 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
169,914 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-1571 EXP | PHP remote file inclusion vulnerability in includes/base.php in Radical Designs Activist Mobilization Platform (AMP) 3.2, when register_globals is ena… | Patch early | 6.8 medium | 5.6% | 2007-03-21 |
| CVE-2007-2089 EXP | Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and Joomla! allow remote attacker… | Patch early | 6.8 medium | 5.6% | 2007-04-18 |
| CVE-2018-12095 EXP | A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod para… | Patch early | 5.4 medium | 5.6% | 2018-06-11 |
| CVE-2006-3751 EXP | PHP remote file inclusion vulnerability in popups/ImageManager/config.inc.php in the HTMLArea3 Addon Component (com_htmlarea3_xtd-c) for ImageManager… | Patch early | 6.8 medium | 5.6% | 2006-07-21 |
| CVE-2012-1933 EXP | Multiple PHP remote file inclusion vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4 before RC4, when register_globals is enabled, allow remote att… | Patch early | 6.8 medium | 5.6% | 2012-08-27 |
| CVE-2011-4614 EXP | PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x before 4.5.9, 4… | Patch early | 6.8 medium | 5.6% | 2012-02-18 |
| CVE-2013-4094 EXP | The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated… | Patch early | 6.5 medium | 5.6% | 2013-06-28 |
| CVE-2008-3493 EXP | vncviewer.exe in RealVNC Windows Client 4.1.2.0 allows remote VNC servers to cause a denial of service (application crash) via a crafted frame buffer… | Patch early | 5.0 medium | 5.6% | 2008-08-06 |
| CVE-2022-39291 EXP | ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are subject to a vulnerability which… | Patch early | 5.4 medium | 5.6% | 2022-10-07 |
| CVE-2021-35323 EXP | Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login. | Patch early | 6.1 medium | 5.6% | 2021-10-19 |
| CVE-2005-2787 EXP | comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter. | Patch early | 5.0 medium | 5.6% | 2005-09-02 |
| CVE-1999-0116 EXP | Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka S… | Patch early | 5.0 medium | 5.6% | 1996-09-19 |
| CVE-2008-5272 EXP | Multiple directory traversal vulnerabilities in Fred Stuurman SyndeoCMS 2.6.0 allow remote authenticated users to read arbitrary files via a .. (dot d… | Patch early | 4.0 medium | 5.6% | 2008-11-28 |
| CVE-2005-3301 EXP | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via c… | Patch early | 4.3 medium | 5.6% | 2005-10-24 |
| CVE-2008-6884 EXP | Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to include and execute arbitrary… | Patch early | 6.8 medium | 5.6% | 2009-07-31 |
| CVE-2007-4902 EXP | Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allows remote attacker… | Patch early | 6.4 medium | 5.6% | 2007-09-17 |
| CVE-2010-3906 EXP | Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) f an… | Patch early | 4.3 medium | 5.6% | 2010-12-17 |
| CVE-2009-4775 EXP | Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash) via format str… | Patch early | 4.3 medium | 5.6% | 2010-04-21 |
| CVE-2016-1415 EXP | Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of service (application crash) via a c… | Patch early | 5.5 medium | 5.6% | 2016-09-03 |
| CVE-2007-5294 EXP | PHP remote file inclusion vulnerability in core/aural.php in IDMOS 1.0-beta (aka Phoenix) allows remote attackers to execute arbitrary PHP code via a… | Patch early | 6.8 medium | 5.6% | 2007-10-09 |
| CVE-2006-7055 EXP | PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in… | Patch early | 6.8 medium | 5.6% | 2007-02-24 |
| CVE-2008-3714 EXP | Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_str… | Patch early | 4.3 medium | 5.6% | 2008-08-19 |
| CVE-2013-2182 EXP | The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a crafted URI, as d… | Patch early | 5.8 medium | 5.6% | 2014-06-13 |
| CVE-2007-1280 EXP | Cross-site scripting (XSS) vulnerability in Adobe RoboHelp X5, 6, and Server 6 allows remote attackers to inject arbitrary web script or HTML via a UR… | Patch early | 4.3 medium | 5.6% | 2007-05-10 |
| CVE-2007-4734 EXP | Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a long file path in an m3u file. | Patch early | 4.3 medium | 5.6% | 2007-09-06 |
| CVE-2018-5756 EXP | The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev2… | Patch early | 4.3 medium | 5.6% | 2018-06-16 |
| CVE-2006-6062 EXP | Unspecified vulnerability in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a ma… | Patch early | 5.1 medium | 5.6% | 2006-11-22 |
| CVE-2016-6186 EXP | Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.j… | Patch early | 6.1 medium | 5.6% | 2016-08-05 |
| CVE-2005-3955 EXP | Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, al… | Patch early | 4.3 medium | 5.6% | 2005-12-01 |
| CVE-2007-4850 EXP | curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir rest… | Patch early | 5.0 medium | 5.6% | 2008-01-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt