CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,133 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
206,670 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-3304 EXP | BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct reque… | Patch early | 5.0 medium | 6.1% | 2008-07-25 |
| CVE-2006-4731 EXP | Multiple directory traversal vulnerabilities in (1) login.pl and (2) admin.pl in (a) SQL-Ledger before 2.6.19 and (b) LedgerSMB before 1.0.0p1 allow r… | Patch early | 5.0 medium | 6.1% | 2006-09-13 |
| CVE-2015-5285 EXP | CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting atta… | Patch early | 5.0 medium | 6.1% | 2015-10-29 |
| CVE-2007-6344 EXP | Directory traversal vulnerability in modules/cms/index.php in Mcms Easy Web Make 1.3, allows remote attackers to include and execute arbitrary local f… | Patch early | 6.8 medium | 6.1% | 2007-12-13 |
| CVE-2009-4367 EXP | The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers t… | Patch early | 6.8 medium | 6.1% | 2009-12-21 |
| CVE-2022-24181 EXP | Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the… | Patch early | 6.1 medium | 6.1% | 2022-04-01 |
| CVE-2004-2198 EXP | account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId par… | Patch early | 6.4 medium | 6.1% | 2004-12-31 |
| CVE-2008-6175 EXP | SilverSHielD 1.0.2.34 allows remote attackers to cause a denial of service (application crash) via a crafted argument to the opendir SFTP command. | Patch early | 5.0 medium | 6.1% | 2009-02-19 |
| CVE-2006-5673 EXP | PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled, allows remote attackers to e… | Patch early | 6.8 medium | 6.1% | 2006-11-03 |
| CVE-2006-5108 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 6.8 medium | 6.1% | 2006-10-03 |
| CVE-2015-4633 EXP | Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1)… | Patch early | 9.8 critical | 6.1% | 2018-10-18 |
| CVE-2006-6564 EXP | FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a malformed argument to the STOR command, which result… | Patch early | 4.0 medium | 6.1% | 2006-12-15 |
| CVE-2006-2929 EXP | PHP remote file inclusion vulnerability in contrib/forms/evaluation/C_FormEvaluation.class.php in OpenEMR 2.8.1 and earlier, when register_globals is… | Patch early | 6.8 medium | 6.1% | 2006-06-09 |
| CVE-2019-12543 EXP | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter. | Patch early | 6.1 medium | 6.1% | 2019-06-05 |
| CVE-2011-0405 EXP | Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc is disabled, allows remote atta… | Patch early | 6.8 medium | 6.1% | 2011-01-11 |
| CVE-2004-1564 EXP | CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify ex… | Patch early | 5.0 medium | 6.1% | 2004-12-31 |
| CVE-2023-26918 EXP | Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as… | Patch early | 9.8 critical | 6.1% | 2023-04-14 |
| CVE-2000-0992 EXP | Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack. | Patch early | 5.0 medium | 6.1% | 2000-12-19 |
| CVE-2000-0056 EXP | IMail IMONITOR status.cgi CGI script allows remote attackers to cause a denial of service with many calls to status.cgi. | Patch early | 5.0 medium | 6% | 2000-01-05 |
| CVE-2004-1101 EXP | mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash), leak sensitive p… | Patch early | 5.8 medium | 6% | 2005-01-10 |
| CVE-2014-8606 EXP | Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files… | Patch early | 4.0 medium | 6% | 2015-06-10 |
| CVE-2007-6317 EXP | Multiple directory traversal vulnerabilities in BarracudaDrive Web Server before 3.8 allow (1) remote attackers to read arbitrary files via certain ..… | Patch early | 5.5 medium | 6% | 2007-12-12 |
| CVE-2002-2416 EXP | Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request. | Patch early | 5.0 medium | 6% | 2002-12-31 |
| CVE-2015-3632 EXP | Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a c… | Patch early | 4.3 medium | 6% | 2015-05-01 |
| CVE-2015-7707 EXP | Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp. | Patch early | 6.5 medium | 6% | 2015-10-05 |
| CVE-2019-12538 EXP | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field. | Patch early | 6.1 medium | 6% | 2019-06-05 |
| CVE-2019-12541 EXP | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter. | Patch early | 6.1 medium | 6% | 2019-06-05 |
| CVE-2019-12542 EXP | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter. | Patch early | 6.1 medium | 6% | 2019-06-05 |
| CVE-2000-1075 EXP | Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary fil… | Patch early | 5.0 medium | 6% | 2000-12-11 |
| CVE-2008-5824 EXP | Heap-based buffer overflow in msadpcm.c in libaudiofile in audiofile 0.2.6 allows context-dependent attackers to cause a denial of service (applicatio… | Patch early | 6.8 medium | 6% | 2009-01-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt