CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,317 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
170,063 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2003-1203 EXP | Cross-site scripting (XSS) vulnerability in index.php for Mambo Site Server 4.0.10 allows remote attackers to execute script on other clients via the… | Patch early | 4.3 medium | 3.6% | 2003-03-18 |
| CVE-2012-2234 EXP | Cross-site scripting (XSS) vulnerability in sources/users.queries.php in TeamPass before 2.1.6 allows remote authenticated users to inject arbitrary w… | Patch early | 4.3 medium | 3.6% | 2012-04-22 |
| CVE-1999-1481 EXP | Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair. | Patch early | 5.0 medium | 3.6% | 1999-12-31 |
| CVE-2022-30076 EXP | ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000… | Patch early | 5.3 medium | 3.6% | 2023-04-16 |
| CVE-2004-2727 EXP | Buffer overflow in MEHTTPS (HTTPMail) of MailEnable Professional 1.5 through 1.7 allows remote attackers to cause a denial of service (application cra… | Patch early | 4.3 medium | 3.6% | 2004-12-31 |
| CVE-2009-3716 EXP | Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file… | Patch early | 6.5 medium | 3.6% | 2009-10-16 |
| CVE-2007-1905 EXP | Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary… | Patch early | 4.3 medium | 3.6% | 2007-04-10 |
| CVE-2017-8840 EXP | Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3… | Patch early | 5.3 medium | 3.6% | 2017-06-05 |
| CVE-2008-0406 EXP | HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a denial of service (daemon crash)… | Patch early | 5.0 medium | 3.6% | 2008-01-29 |
| CVE-2020-9038 EXP | Joplin through 1.0.184 allows Arbitrary File Read via XSS. | Patch early | 5.4 medium | 3.6% | 2020-02-17 |
| CVE-2007-3098 EXP | The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a denial of service (crash) via a… | Patch early | 5.0 medium | 3.6% | 2007-06-06 |
| CVE-2006-5033 EXP | Unspecified vulnerability in StoresAndCalendarsList.cgi in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to cause a… | Patch early | 5.0 medium | 3.6% | 2006-09-27 |
| CVE-2020-27533 EXP | A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, an… | Patch early | 5.4 medium | 3.6% | 2020-10-22 |
| CVE-2001-0228 EXP | Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in an HTTP GET… | Patch early | 5.0 medium | 3.6% | 2001-05-03 |
| CVE-2011-4545 EXP | CRLF injection vulnerability in admin/displayImage.php in Prestashop 1.4.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP… | Patch early | 5.0 medium | 3.6% | 2011-12-02 |
| CVE-2005-3813 EXP | IMAP service (meimaps.exe) of MailEnable Professional 1.7 and Enterprise 1.1 allows remote authenticated attackers to cause a denial of service (appli… | Patch early | 4.0 medium | 3.6% | 2005-11-26 |
| CVE-2000-0239 EXP | Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mail_user parameter in the GET re… | Patch early | 5.0 medium | 3.6% | 2000-03-15 |
| CVE-2021-33570 EXP | Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files… | Patch early | 5.4 medium | 3.6% | 2021-05-25 |
| CVE-2007-2964 EXP | The fsmsh.dll host module in F-Secure Policy Manager Server 7.00 and earlier allows remote attackers to cause a denial of service (application crash)… | Patch early | 5.0 medium | 3.6% | 2007-05-31 |
| CVE-2003-1032 EXP | Pi3Web web server 2.0.2 Beta 1, when the Directory Index is configured to use the "Name" column and sort using the column title as a hyperlink, allows… | Patch early | 5.0 medium | 3.6% | 2004-02-17 |
| CVE-2006-5319 EXP | Directory traversal vulnerability in redir.php in Foafgen 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the foaf parameter… | Patch early | 5.0 medium | 3.6% | 2006-10-17 |
| CVE-2008-6420 EXP | Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.php, (2) webadmin/download.php… | Patch early | 5.0 medium | 3.6% | 2009-03-06 |
| CVE-2012-1001 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Chyrp before 2.1.2 and before 2.5 Beta 2 allow remote attackers to inject arbitrary web script… | Patch early | 6.1 medium | 3.6% | 2019-11-21 |
| CVE-2006-6827 EXP | Flash8b.ocx in Macromedia Flash 8 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the Flash8b.Al… | Patch early | 5.0 medium | 3.6% | 2006-12-31 |
| CVE-2008-0631 EXP | Multiple ActiveX controls in MailBee.dll in MailBee Objects 5.5 allow remote attackers to (1) overwrite arbitrary files via the SaveToDisk method, or… | Patch early | 4.3 medium | 3.6% | 2008-02-06 |
| CVE-2012-4267 EXP | Cross-site scripting (XSS) vulnerability in user/register in Sockso 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 3.6% | 2012-08-13 |
| CVE-2013-2760 EXP | Buffer overflow in Groovy Media Player 3.2.0 allows remote attackers to execute arbitrary code via a long string in a .m3u file. | Patch early | 6.8 medium | 3.6% | 2013-04-16 |
| CVE-2006-5034 EXP | Directory traversal vulnerability in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to read arbitrary files via a ..… | Patch early | 5.0 medium | 3.6% | 2006-09-27 |
| CVE-2014-4944 EXP | Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress allow remote authenticated users… | Patch early | 6.5 medium | 3.6% | 2014-07-14 |
| CVE-2007-2423 EXP | Cross-site scripting (XSS) vulnerability in index.php in MoinMoin 1.5.7 allows remote attackers to inject arbitrary web script or HTML via the do para… | Patch early | 5.8 medium | 3.6% | 2007-05-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt