CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,098 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
169,951 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-5210 EXP | Directory traversal vulnerability in IronWebMail before 6.1.1 HotFix-17 allows remote attackers to read arbitrary files via a GET request to the IM_FI… | Patch early | 5.0 medium | 4.3% | 2006-10-16 |
| CVE-2004-2099 EXP | Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary cod… | Patch early | 5.1 medium | 4.3% | 2004-12-31 |
| CVE-2011-5049 EXP | MySQL 5.5.8, when running on Windows, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted packet to TCP port… | Patch early | 4.3 medium | 4.3% | 2012-01-04 |
| CVE-2003-1368 EXP | Buffer overflow in the 32bit FTP client 9.49.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a… | Patch early | 6.4 medium | 4.3% | 2003-12-31 |
| CVE-2008-1467 EXP | CenterIM 4.22.3 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URI, related to "receive… | Patch early | 6.8 medium | 4.3% | 2008-03-24 |
| CVE-2016-5740 EXP | An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical attachments within scheduling E-Ma… | Patch early | 6.1 medium | 4.3% | 2016-12-15 |
| CVE-2002-1480 EXP | Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which i… | Patch early | 6.8 medium | 4.3% | 2003-04-22 |
| CVE-2017-2445 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 6.1 medium | 4.3% | 2017-04-02 |
| CVE-2017-8684 EXP | Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1, allows… | Patch early | 5.5 medium | 4.3% | 2017-09-13 |
| CVE-2012-5858 EXP | Samsung Kies Air 2.1.207051 and 2.1.210161 relies on the IP address for authentication, which allows remote man-in-the-middle attackers to read arbitr… | Patch early | 4.3 medium | 4.3% | 2012-12-03 |
| CVE-2004-1196 EXP | Cross-site scripting (XSS) vulnerability in inmail.pl in Insite Inmail allows remote attackers to inject arbitrary web script or HTML via the acao par… | Patch early | 6.8 medium | 4.3% | 2005-01-10 |
| CVE-2014-0868 EXP | RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which a… | Patch early | 4.9 medium | 4.3% | 2014-07-07 |
| CVE-2015-1058 EXP | Multiple cross-site scripting (XSS) vulnerabilities in AdaptCMS 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) data[C… | Patch early | 4.3 medium | 4.3% | 2015-01-16 |
| CVE-2003-0416 EXP | Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML or script via (1) the year para… | Patch early | 6.8 medium | 4.3% | 2003-06-30 |
| CVE-2003-0492 EXP | Cross-site scripting (XSS) vulnerability in search.asp for Snitz Forums 3.4.03 and earlier allows remote attackers to execute arbitrary web script via… | Patch early | 6.8 medium | 4.3% | 2003-08-07 |
| CVE-2006-6962 EXP | PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for Joomla! allows attackers to ex… | Patch early | 6.8 medium | 4.3% | 2007-01-29 |
| CVE-2002-1708 EXP | Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting scrip… | Patch early | 6.8 medium | 4.3% | 2002-12-31 |
| CVE-2002-1727 EXP | Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows remote attackers to execute arbi… | Patch early | 6.8 medium | 4.3% | 2002-12-31 |
| CVE-2003-1516 EXP | The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violate… | Patch early | 6.8 medium | 4.3% | 2003-12-31 |
| CVE-1999-0986 EXP | The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option. | Patch early | 5.0 medium | 4.3% | 1999-12-08 |
| CVE-2008-7061 EXP | The tooltip manager (chrome/views/tooltip_manager.cc) in Google Chrome 0.2.149.29 Build 1798 and possibly other versions before 0.2.149.30 allows remo… | Patch early | 4.3 medium | 4.3% | 2009-08-24 |
| CVE-2007-6367 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the guestbook in SineCMS 2.3.4 and earlier allow remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 4.3% | 2007-12-15 |
| CVE-2012-2316 EXP | Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows remote atta… | Patch early | 6.8 medium | 4.3% | 2012-09-09 |
| CVE-2012-0873 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 4.3% | 2012-02-23 |
| CVE-2011-3850 EXP | Cross-site scripting (XSS) vulnerability in the Atahualpa theme before 3.6.8 for WordPress allows remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 4.3% | 2011-09-28 |
| CVE-2008-0616 EXP | SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote authenticated administrators to e… | Patch early | 6.5 medium | 4.3% | 2008-02-06 |
| CVE-2004-1442 EXP | Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 4.3% | 2004-12-31 |
| CVE-2006-4425 EXP | Multiple PHP remote file inclusion vulnerabilities in phpCOIN 1.2.3 allow remote attackers to execute arbitrary PHP code via the _CCFG[_PKG_PATH_INCL]… | Patch early | 5.1 medium | 4.3% | 2006-08-29 |
| CVE-2005-0984 EXP | Buffer overflow in the G_Printf function in Star Wars Jedi Knight: Jedi Academy 1.011 and earlier allows remote attackers to execute arbitrary code vi… | Patch early | 5.0 medium | 4.3% | 2005-05-02 |
| CVE-2012-4000 EXP | Cross-site scripting (XSS) vulnerability in the print_textinputs_var function in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellcheck… | Patch early | 4.3 medium | 4.3% | 2012-07-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt