CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,121 CVEs
1,733 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
169,957 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-3793 EXP | PHP remote file inclusion vulnerability in constants.php in SiteDepth CMS 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a… | Patch early | 5.1 medium | 4.2% | 2006-07-24 |
| CVE-2015-2218 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the WonderPlugin Audio Player plugin… | Patch early | 4.3 medium | 4.2% | 2015-03-05 |
| CVE-2002-0908 EXP | Directory traversal vulnerability in the web server for Cisco IDS Device Manager before 3.1.2 allows remote attackers to read arbitrary files via a ..… | Patch early | 5.0 medium | 4.2% | 2002-10-04 |
| CVE-2015-4465 EXP | Cross-site scripting (XSS) vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to inject arbitrary… | Patch early | 4.3 medium | 4.2% | 2015-06-10 |
| CVE-2013-3535 EXP | Multiple cross-site scripting (XSS) vulnerabilities in CMSLogik 1.2.0 and 1.2.1 allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 4.2% | 2013-05-13 |
| CVE-2014-4312 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allow remote attackers to inject arbitrary… | Patch early | 4.3 medium | 4.2% | 2014-10-10 |
| CVE-2004-2072 EXP | Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute scr… | Patch early | 6.8 medium | 4.2% | 2004-12-31 |
| CVE-2008-6926 EXP | Directory traversal vulnerability in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allows remote attackers to inclu… | Patch early | 6.8 medium | 4.2% | 2009-08-10 |
| CVE-2009-2787 EXP | Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB, when regi… | Patch early | 6.8 medium | 4.2% | 2009-08-17 |
| CVE-2017-12952 EXP | The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application cra… | Patch early | 6.5 medium | 4.2% | 2017-08-28 |
| CVE-2007-6309 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in webSPELL 4.1.2 allow remote attackers to inject arbitrary web script or HTML via (… | Patch early | 4.3 medium | 4.2% | 2007-12-11 |
| CVE-2007-4143 EXP | user.php in the Billing Control Panel in phpCoupon allows remote authenticated users to obtain Premium Member status, and possibly acquire free coupon… | Patch early | 4.0 medium | 4.2% | 2007-08-03 |
| CVE-2012-6667 EXP | Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbi… | Patch early | 6.1 medium | 4.2% | 2018-01-11 |
| CVE-2012-0984 EXP | Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) to… | Patch early | 4.3 medium | 4.2% | 2014-09-11 |
| CVE-2010-1948 EXP | Directory traversal vulnerability in scr/soustab.php in openMairie Openfoncier 2.00, when register_globals is enabled, allows remote attackers to incl… | Patch early | 6.8 medium | 4.2% | 2010-05-19 |
| CVE-2017-12953 EXP | The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory wri… | Patch early | 6.5 medium | 4.2% | 2017-08-28 |
| CVE-2017-12954 EXP | The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory read a… | Patch early | 6.5 medium | 4.2% | 2017-08-28 |
| CVE-2011-3979 EXP | Cross-site scripting (XSS) vulnerability in ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme module in Zikula Application Framework… | Patch early | 4.3 medium | 4.2% | 2011-10-04 |
| CVE-2007-2716 EXP | Multiple cross-site scripting (XSS) vulnerabilities in EQdkp 1.3.2c and earlier allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 6.8 medium | 4.2% | 2007-05-16 |
| CVE-2006-1679 EXP | Cross-site scripting (XSS) vulnerability in modules/online.php in Jupiter CMS 1.1.5 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 4.2% | 2006-04-11 |
| CVE-2014-6242 EXP | Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow remote authenticated users to… | Patch early | 6.5 medium | 4.2% | 2014-10-02 |
| CVE-2015-8727 EXP | The dissect_rsvp_common function in epan/dissectors/packet-rsvp.c in the RSVP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does… | Patch early | 5.5 medium | 4.2% | 2016-01-04 |
| CVE-2014-6312 EXP | Cross-site request forgery (CSRF) vulnerability in the Login Widget With Shortcode (login-sidebar-widget) plugin before 3.2.1 for WordPress allows rem… | Patch early | 4.3 medium | 4.2% | 2014-10-15 |
| CVE-2015-8733 EXP | The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does… | Patch early | 5.5 medium | 4.2% | 2016-01-04 |
| CVE-2007-3364 EXP | Cross-site scripting (XSS) vulnerability in the cgi-bin/post.mscgi sample page in MyServer 0.8.9 allows remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 4.2% | 2007-06-22 |
| CVE-2005-0647 EXP | admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove] parameters… | Patch early | 5.0 medium | 4.2% | 2005-05-02 |
| CVE-2004-1940 EXP | sipclient.cpp in KPhone 4.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a STUN response packet with a large attrLen… | Patch early | 5.0 medium | 4.1% | 2004-12-31 |
| CVE-2009-1483 EXP | Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable from index2.php, allows remot… | Patch early | 6.8 medium | 4.1% | 2009-04-29 |
| CVE-2016-7216 EXP | The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandles permissions, which allows local users… | Patch early | 5.5 medium | 4.1% | 2016-11-10 |
| CVE-2007-6307 EXP | Multiple cross-site scripting (XSS) vulnerabilities in clickstats.php in wwwstats 3.21 allow remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 4.1% | 2007-12-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt