CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,061 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
169,938 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-2501 EXP | Cross-site scripting (XSS) vulnerability in the Terillion Reviews plugin before 1.2 for WordPress allows remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 5.3% | 2013-03-22 |
| CVE-2023-36346 EXP | POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php. | Patch early | 6.1 medium | 5.3% | 2023-06-23 |
| CVE-2014-1842 EXP | Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to list all usernames via a… | Patch early | 5.0 medium | 5.3% | 2014-04-29 |
| CVE-2007-1584 EXP | Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by passing an all-whitespace string… | Patch early | 6.8 medium | 5.2% | 2007-03-21 |
| CVE-2006-6104 EXP | The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to… | Patch early | 5.0 medium | 5.2% | 2006-12-21 |
| CVE-2008-1501 EXP | The send_user_mode function in s_user.c in (1) Undernet ircu 2.10.12.12 and earlier, (2) snircd 1.3.4 and earlier, and unspecified other ircu derivati… | Patch early | 5.0 medium | 5.2% | 2008-03-25 |
| CVE-2011-1485 EXP | Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privileges by executing a setuid pro… | Patch early | 6.9 medium | 5.2% | 2011-05-31 |
| CVE-2000-1081 EXP | The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before… | Patch early | 4.6 medium | 5.2% | 2001-01-09 |
| CVE-2008-0783 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to inject arbitrary we… | Patch early | 4.3 medium | 5.2% | 2008-02-14 |
| CVE-2005-4317 EXP | Limbo CMS 1.0.4.2 and earlier, with register_globals off, does not protect the $_SERVER variable from external modification, which allows remote attac… | Patch early | 6.8 medium | 5.2% | 2005-12-17 |
| CVE-2000-0299 EXP | Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of service via an HTTP request wit… | Patch early | 5.0 medium | 5.2% | 2000-04-04 |
| CVE-2001-0380 EXP | Crosscom/Olicom XLT-F running XL 80 IM Version 5.5 Build Level 2 allows a remote attacker SNMP read and write access via a default, undocumented commu… | Patch early | 6.4 medium | 5.2% | 2001-06-18 |
| CVE-2007-1583 EXP | The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and does not disable it in certai… | Patch early | 6.8 medium | 5.2% | 2007-03-21 |
| CVE-2015-4682 EXP | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POST request… | Patch early | 6.5 medium | 5.2% | 2017-09-19 |
| CVE-2015-8725 EXP | The dissect_diameter_base_framed_ipv6_prefix function in epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.12.x before 1.12.9… | Patch early | 5.5 medium | 5.2% | 2016-01-04 |
| CVE-2007-6609 EXP | Multiple stack-based buffer overflows in the CPLI_ReadTag_OGG function in CPI_PlaylistItem.c in CoolPlayer 217 and earlier allow user-assisted remote… | Patch early | 5.0 medium | 5.2% | 2007-12-31 |
| CVE-2006-1234 EXP | SQL injection vulnerability in index.php in DSCounter 1.2, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands v… | Patch early | 5.1 medium | 5.2% | 2006-03-14 |
| CVE-2001-1289 EXP | Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins with several… | Patch early | 5.0 medium | 5.2% | 2001-07-29 |
| CVE-2000-0341 EXP | ATRIUM Cassandra NNTP Server 1.10 allows remote attackers to cause a denial of service via a long login name. | Patch early | 5.0 medium | 5.2% | 2000-05-01 |
| CVE-2000-1078 EXP | ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character. | Patch early | 5.0 medium | 5.2% | 2000-12-11 |
| CVE-2001-0647 EXP | Orange Web Server 2.1, based on GoAhead, allows a remote attacker to perform a denial of service via an HTTP GET request that does not include the HTT… | Patch early | 5.0 medium | 5.2% | 2001-08-06 |
| CVE-2001-0743 EXP | Paging function in O'Reilly WebBoard Pager 4.10 allows remote attackers to cause a denial of service via a message with an escaped ' character followe… | Patch early | 5.0 medium | 5.2% | 2001-10-18 |
| CVE-2013-2586 EXP | XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-site scripti… | Patch early | 4.3 medium | 5.2% | 2014-09-29 |
| CVE-2004-1003 EXP | Trend ScanMail allows remote attackers to obtain potentially sensitive information or disable the anti-virus capability via the smency.nsf file. | Patch early | 5.0 medium | 5.2% | 2005-03-01 |
| CVE-2005-2175 EXP | The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it eas… | Patch early | 5.0 medium | 5.2% | 2005-07-09 |
| CVE-2007-1266 EXP | Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing… | Patch early | 5.0 medium | 5.2% | 2007-03-06 |
| CVE-1999-0904 EXP | Buffer overflow in BFTelnet allows remote attackers to cause a denial of service via a long username. | Patch early | 5.0 medium | 5.2% | 1999-11-03 |
| CVE-1999-0928 EXP | Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL. | Patch early | 5.0 medium | 5.2% | 1999-05-23 |
| CVE-2005-0256 EXP | The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion)… | Patch early | 5.0 medium | 5.2% | 2005-05-02 |
| CVE-2011-0900 EXP | Stack-based buffer overflow in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150, and possibly other versions,… | Patch early | 6.8 medium | 5.2% | 2011-02-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt