CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,075 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
169,946 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2003-0967 EXP | rad_decode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a short RADIUS string attribute with a tag… | Patch early | 5.0 medium | 4.6% | 2003-12-15 |
| CVE-2005-2256 EXP | Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via "%2e%2e%2f" (encoded dot do… | Patch early | 5.0 medium | 4.6% | 2005-07-13 |
| CVE-2005-3334 EXP | Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 4.6% | 2005-10-27 |
| CVE-1999-1515 EXP | A non-default configuration in TenFour TFS Gateway 4.0 allows an attacker to cause a denial of service via messages with incorrect sender and recipien… | Patch early | 5.0 medium | 4.6% | 1999-08-31 |
| CVE-2004-0265 EXP | Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via… | Patch early | 6.8 medium | 4.6% | 2004-11-23 |
| CVE-2005-3544 EXP | Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3 allows remote attackers to inject arbitrary web script or HTML via the username param… | Patch early | 4.3 medium | 4.6% | 2005-11-16 |
| CVE-2013-2503 EXP | Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it eas… | Patch early | 5.8 medium | 4.6% | 2013-03-11 |
| CVE-2008-3260 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via (1) t… | Patch early | 4.3 medium | 4.6% | 2008-07-22 |
| CVE-2009-2953 EXP | Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of service (CPU consumption) via JavaScript code with a lon… | Patch early | 5.0 medium | 4.6% | 2009-08-24 |
| CVE-2018-7704 EXP | SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via the option1 parameter in a reply action to… | Patch early | 6.5 medium | 4.6% | 2018-03-15 |
| CVE-2000-0989 EXP | Buffer overflow in Intel InBusiness eMail Station 1.04.87 POP service allows remote attackers to cause a denial of service and possibly execute comman… | Patch early | 5.0 medium | 4.6% | 2000-12-19 |
| CVE-2019-11537 EXP | In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent man… | Patch early | 6.1 medium | 4.6% | 2019-04-25 |
| CVE-2007-6310 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Falt4Extreme RC4 10.9.2007 allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 4.6% | 2007-12-11 |
| CVE-2000-0500 EXP | The default configuration of BEA WebLogic 5.1.0 allows a remote attacker to view source code of programs by requesting a URL beginning with /file/, wh… | Patch early | 5.0 medium | 4.6% | 2000-06-21 |
| CVE-2011-2357 EXP | Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local applications to bypass the sa… | Patch early | 4.3 medium | 4.6% | 2011-08-12 |
| CVE-2006-6943 EXP | PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path via direct requests to (a) scripts/check_lang.php and (b) themes/dark… | Patch early | 5.0 medium | 4.6% | 2007-01-19 |
| CVE-2019-16172 EXP | LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a su… | Patch early | 5.4 medium | 4.6% | 2019-09-09 |
| CVE-2014-9331 EXP | Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authen… | Patch early | 6.8 medium | 4.6% | 2015-02-04 |
| CVE-2019-16117 EXP | Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php. | Patch early | 6.1 medium | 4.6% | 2019-09-08 |
| CVE-2022-34125 EXP | front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive information via a _log/ pathname in the… | Patch early | 6.5 medium | 4.6% | 2023-04-16 |
| CVE-2011-2975 EXP | Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a denial of… | Patch early | 6.8 medium | 4.6% | 2011-08-01 |
| CVE-2005-0613 EXP | Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files. | Patch early | 5.0 medium | 4.6% | 2005-02-28 |
| CVE-2014-1219 EXP | CA 2E Web Option r8.1.2 accepts a predictable substring of a W2E_SSNID session token in place of the entire token, which allows remote attackers to hi… | Patch early | 5.1 medium | 4.6% | 2014-02-14 |
| CVE-2003-0154 EXP | Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, r… | Patch early | 6.8 medium | 4.6% | 2003-04-02 |
| CVE-2008-0985 EXP | Heap-based buffer overflow in the GIF library in the WebKit framework for Google Android SDK m3-rc37a and earlier allows remote attackers to execute a… | Patch early | 6.8 medium | 4.6% | 2008-03-06 |
| CVE-2000-0480 EXP | Dragon telnet server allows remote attackers to cause a denial of service via a long username. | Patch early | 5.0 medium | 4.6% | 2000-06-16 |
| CVE-2004-2512 EXP | CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting attacks to spo… | Patch early | 4.3 medium | 4.6% | 2004-12-31 |
| CVE-2005-4449 EXP | verify.php in FlatNuke 2.5.6 allows remote authenticated administrators to modify arbitrary PHP files by setting the file parameter to an arbitrary fi… | Patch early | 4.0 medium | 4.6% | 2005-12-21 |
| CVE-2012-3996 EXP | TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php,… | Patch early | 5.0 medium | 4.6% | 2012-07-12 |
| CVE-2006-2928 EXP | Multiple PHP remote file inclusion vulnerabilities in CMS-Bandits 2.5 and earlier, when register_globals is enabled, allow remote attackers to execute… | Patch early | 5.1 medium | 4.6% | 2006-06-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt