CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,317 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
170,063 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-3305 EXP | Cross-site scripting (XSS) vulnerability in mensaje.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 3.6% | 2008-07-25 |
| CVE-2006-4681 EXP | Directory traversal vulnerability in Redirect.bat in IBM Director before 5.10 allows remote attackers to read arbitrary files via a .. (dot dot) seque… | Patch early | 5.0 medium | 3.6% | 2006-09-11 |
| CVE-2017-8471 EXP | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,… | Patch early | 5.0 medium | 3.6% | 2017-06-15 |
| CVE-2017-8473 EXP | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allow an… | Patch early | 5.0 medium | 3.6% | 2017-06-15 |
| CVE-2017-8485 EXP | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… | Patch early | 5.0 medium | 3.6% | 2017-06-15 |
| CVE-2017-10803 EXP | In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database An… | Patch early | 6.5 medium | 3.6% | 2017-07-04 |
| CVE-2018-18548 EXP | ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager. | Patch early | 6.1 medium | 3.6% | 2018-10-24 |
| CVE-2008-1403 EXP | Stack-based buffer overflow in the TFTP server in BootManage TFTPD 1.99 and earlier in BootManage Administrator 7.1 and earlier allows remote attacker… | Patch early | 6.8 medium | 3.6% | 2008-03-20 |
| CVE-2004-1659 EXP | Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Administrator, Editor, Journalist or… | Patch early | 4.3 medium | 3.6% | 2004-09-02 |
| CVE-2014-3210 EXP | SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenti… | Patch early | 6.5 medium | 3.6% | 2014-05-22 |
| CVE-2004-1207 EXP | The Serious engine, as used in (1) Alpha Black Zero Intrepid Protocol 1.04 and earlier, (2) Nitro family, and (3) Serious Sam Second Encounter 1.07 al… | Patch early | 5.0 medium | 3.6% | 2005-01-10 |
| CVE-2002-0502 EXP | Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page. | Patch early | 5.0 medium | 3.6% | 2002-08-12 |
| CVE-2006-2395 EXP | PHP remote file inclusion vulnerability in resources/includes/popp.config.loader.inc.php in PopSoft Digital PopPhoto Studio 3.5.4 and earlier allows r… | Patch early | 5.0 medium | 3.6% | 2006-05-16 |
| CVE-2014-9581 EXP | Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read arbitrary files via a .. (dot… | Patch early | 5.0 medium | 3.6% | 2015-01-08 |
| CVE-2014-6070 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3.6% | 2014-09-11 |
| CVE-2000-0975 EXP | Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrary files via a .. (dot dot) att… | Patch early | 5.0 medium | 3.6% | 2000-12-19 |
| CVE-2001-0217 EXP | Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the do… | Patch early | 5.0 medium | 3.6% | 2001-06-02 |
| CVE-2004-2574 EXP | Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 3.6% | 2004-12-31 |
| CVE-2002-1529 EXP | Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allow… | Patch early | 4.3 medium | 3.6% | 2003-03-31 |
| CVE-2002-1922 EXP | Cross-site scripting (XSS) vulnerability in global.php in Jelsoft vBulletin 2.0.0 through 2.2.8 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 3.6% | 2002-12-31 |
| CVE-2018-17997 EXP | LayerBB 1.1.1 allows XSS via the titles of conversations (PMs). | Patch early | 6.1 medium | 3.6% | 2019-03-21 |
| CVE-2006-5077 EXP | PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Chris Smith Minerva Build 238 and earlier allows remote attackers t… | Patch early | 5.1 medium | 3.6% | 2006-09-29 |
| CVE-2004-2242 EXP | Cross-site scripting (XSS) vulnerability in search.php in Phorum, possibly 5.0.7 beta and earlier, allows remote attackers to inject arbitrary HTML or… | Patch early | 4.3 medium | 3.6% | 2004-12-31 |
| CVE-2005-2649 EXP | Cross-site scripting (XSS) vulnerability in ATutor 1.5.1 allows remote attackers to inject arbitrary web script or HTML via (1) course parameter in lo… | Patch early | 4.3 medium | 3.6% | 2005-08-23 |
| CVE-2005-4167 EXP | Cross-site scripting (XSS) vulnerability in eFiction 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the let parameter… | Patch early | 4.3 medium | 3.6% | 2005-12-11 |
| CVE-2007-6037 EXP | Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 3.6% | 2007-11-20 |
| CVE-2004-1691 EXP | The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of data. | Patch early | 5.0 medium | 3.6% | 2004-09-18 |
| CVE-2007-4231 EXP | PHP remote file inclusion vulnerability in order/login.php in IDevSpot PhpHostBot 1.06 and earlier allows remote attackers to execute arbitrary PHP co… | Patch early | 6.8 medium | 3.6% | 2007-08-08 |
| CVE-2004-1688 EXP | Pigeon Server 3.02.0143 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a long login name sen… | Patch early | 5.0 medium | 3.6% | 2004-09-16 |
| CVE-2002-1829 EXP | Cross-site scripting (XSS) vulnerability in codeparse.php in Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 3.6% | 2002-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt