CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,295 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
170,051 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-2077 EXP | Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the er… | Patch early | 4.3 medium | 3.6% | 2005-06-29 |
| CVE-2005-2480 EXP | Cross-site scripting (XSS) vulnerability in ColdFusion Fusebox 4.1.0 allows remote attackers to inject arbitrary web script or HTML via the fuseaction… | Patch early | 4.3 medium | 3.6% | 2005-08-05 |
| CVE-2018-5405 EXP | The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows an authenticated least privileged user with 'User Console Only' rights to potentiall… | Patch early | 5.4 medium | 3.6% | 2019-06-03 |
| CVE-2007-0620 EXP | download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions, inclu… | Patch early | 5.0 medium | 3.6% | 2007-01-31 |
| CVE-2014-8810 EXP | SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remote authenticated users to exec… | Patch early | 6.5 medium | 3.6% | 2014-12-24 |
| CVE-2014-9305 EXP | SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin before 1.5.2 for WordPress allow… | Patch early | 6.5 medium | 3.6% | 2014-12-08 |
| CVE-2011-5261 EXP | Cross-site scripting (XSS) vulnerability in serverreport.cgi in Axis M10 Series Network Cameras M1054 firmware 5.21 and earlier allows remote attacker… | Patch early | 4.3 medium | 3.6% | 2013-02-12 |
| CVE-2005-0950 EXP | Directory traversal vulnerability in FastStone 4in1 Browser 1.2 allows remote attackers to read arbitrary files via a (1) ... (triple dot) or (2) ..\… | Patch early | 5.0 medium | 3.6% | 2005-03-29 |
| CVE-2019-12905 EXP | FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman§ion=do&page=up URI. This issue has been fixed in FileRun 2019.06.01. | Patch early | 6.1 medium | 3.6% | 2019-06-20 |
| CVE-2017-2388 EXP | An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireFamily" component. It allows at… | Patch early | 5.5 medium | 3.6% | 2017-04-02 |
| CVE-2004-2517 EXP | myServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon operation to index.html. | Patch early | 5.0 medium | 3.6% | 2004-12-31 |
| CVE-2001-0760 EXP | Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the… | Patch early | 5.0 medium | 3.6% | 2001-10-18 |
| CVE-2007-2440 EXP | Directory traversal vulnerability in Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to read ce… | Patch early | 5.0 medium | 3.6% | 2007-05-16 |
| CVE-2004-1665 EXP | Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no paramete… | Patch early | 4.3 medium | 3.6% | 2004-09-05 |
| CVE-2003-1545 EXP | Absolute path traversal vulnerability in nukestyles.com viewpage.php addon for PHP-Nuke allows remote attackers to read arbitrary files via a full pat… | Patch early | 5.0 medium | 3.6% | 2003-12-31 |
| CVE-2012-2512 EXP | The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remot… | Patch early | 5.0 medium | 3.6% | 2012-05-15 |
| CVE-2012-2513 EXP | The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attac… | Patch early | 5.0 medium | 3.6% | 2012-05-15 |
| CVE-2012-2514 EXP | The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remot… | Patch early | 5.0 medium | 3.6% | 2012-05-15 |
| CVE-2012-2612 EXP | The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote at… | Patch early | 5.0 medium | 3.6% | 2012-05-15 |
| CVE-2011-5182 EXP | Cross-site scripting (XSS) vulnerability in lanoba-social-plugin/index.php in the Lanoba Social plugin 1.0 for WordPress allows remote attackers to in… | Patch early | 4.3 medium | 3.6% | 2012-09-20 |
| CVE-2011-4714 EXP | Directory traversal vulnerability in Virtual Vertex Muster before 6.20 allows remote attackers to read arbitrary files via a \.. (backslash dot dot) i… | Patch early | 5.0 medium | 3.6% | 2011-12-08 |
| CVE-2007-0872 EXP | Directory traversal vulnerability in the Plain Old Webserver (POW) add-on before 0.0.9 for Mozilla Firefox allows remote attackers to read arbitrary f… | Patch early | 5.0 medium | 3.6% | 2007-02-12 |
| CVE-2006-0534 EXP | Multiple cross-site scripting (XSS) vulnerabilities in default.asp in CyberShop Ultimate E-commerce allow remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 3.6% | 2006-02-04 |
| CVE-2004-1746 EXP | Cross-site scripting (XSS) vulnerability in index.php in PHP Code Snippet Library allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 3.6% | 2004-12-31 |
| CVE-2005-1498 EXP | Multiple cross-site scripting (XSS) vulnerabilities in myBloggie 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) year… | Patch early | 4.3 medium | 3.6% | 2005-05-11 |
| CVE-2007-6510 EXP | Multiple stack-based buffer overflows in ProWizard 4 PC (prowiz) 1.62 and earlier allow remote attackers to execute arbitrary code via a crafted file… | Patch early | 6.8 medium | 3.6% | 2007-12-21 |
| CVE-2004-2112 EXP | Directory traversal vulnerability in BremsServer 1.2.4 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in the URL. | Patch early | 5.0 medium | 3.6% | 2004-12-31 |
| CVE-2008-0691 EXP | Multiple cross-site scripting (XSS) vulnerabilities in admin_panel.php in the Simon Elvery WP-Footnotes 2.2 plugin for WordPress allow remote attacker… | Patch early | 4.3 medium | 3.6% | 2008-02-12 |
| CVE-1999-1485 EXP | nsd in IRIX 6.5 through 6.5.2 exports a virtual filesystem on a UDP port, which allows remote attackers to view files and cause a possible denial of s… | Patch early | 6.4 medium | 3.6% | 1999-05-31 |
| CVE-2009-0537 EXP | Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows cont… | Patch early | 4.9 medium | 3.6% | 2009-03-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt