CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,178 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
206,676 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-0639 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (… | Patch early | 6.8 medium | 6% | 2004-08-06 |
| CVE-2015-0107 EXP | IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 an… | Patch early | 6.5 medium | 6% | 2017-04-24 |
| CVE-2018-16606 EXP | In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted papers (Title and Abstract) and the… | Patch early | 6.5 medium | 5.9% | 2018-09-06 |
| CVE-2017-14939 EXP | decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles a length calcul… | Patch early | 5.5 medium | 5.9% | 2017-09-30 |
| CVE-1999-1015 EXP | Buffer overflow in Apple AppleShare Mail Server 5.0.3 on MacOS 8.1 and earlier allows a remote attacker to cause a denial of service (crash) via a lon… | Patch early | 5.0 medium | 5.9% | 1998-04-08 |
| CVE-2019-7441 EXP | cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount paramet… | Patch early | 6.5 medium | 5.9% | 2019-03-21 |
| CVE-2006-7141 EXP | Absolute path traversal vulnerability in Oracle Database Server, when utl_file_dir is set to a wildcard value or "CREATE ANY DIRECTORY to PUBLIC" priv… | Patch early | 6.0 medium | 5.9% | 2007-03-07 |
| CVE-2009-2653 EXP | The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass… | Patch early | 4.6 medium | 5.9% | 2009-08-03 |
| CVE-2006-2119 EXP | PHP remote file inclusion vulnerability in event/index.php in Artmedic Event allows remote attackers to execute arbitrary code via a URL in the page p… | Patch early | 5.0 medium | 5.9% | 2006-05-01 |
| CVE-2009-3053 EXP | Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local… | Patch early | 6.8 medium | 5.9% | 2009-09-03 |
| CVE-2007-1582 EXP | The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting ce… | Patch early | 6.8 medium | 5.9% | 2007-03-21 |
| CVE-2019-12189 EXP | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field. | Patch early | 6.1 medium | 5.9% | 2019-05-21 |
| CVE-2000-0039 EXP | AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cgi CGI program. | Patch early | 5.0 medium | 5.9% | 1999-12-29 |
| CVE-2000-0174 EXP | StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 5.0 medium | 5.9% | 2000-03-09 |
| CVE-2000-0192 EXP | The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote attackers to determine what packages are ins… | Patch early | 5.0 medium | 5.9% | 2000-03-05 |
| CVE-2000-0236 EXP | Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web publishing tags such as ?wp-ver-… | Patch early | 5.0 medium | 5.9% | 2000-03-17 |
| CVE-2000-0430 EXP | Cart32 allows remote attackers to access sensitive debugging information by appending /expdate to the URL request. | Patch early | 5.0 medium | 5.9% | 2000-05-03 |
| CVE-2022-31062 EXP | ### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.p… | Patch early | 5.3 medium | 5.9% | 2022-06-20 |
| CVE-2008-5765 EXP | WorkSimple 1.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the datab… | Patch early | 5.0 medium | 5.9% | 2008-12-30 |
| CVE-2008-6872 EXP | ASPThai.NET ASPThai Forums 8.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to down… | Patch early | 5.0 medium | 5.9% | 2009-07-23 |
| CVE-2023-23161 EXP | A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts o… | Patch early | 6.1 medium | 5.9% | 2023-02-10 |
| CVE-2008-5862 EXP | Directory traversal vulnerability in webcamXP 5.3.2.375 and 5.3.2.410 build 2132 allows remote attackers to read arbitrary files via a ..%2F (encoded… | Patch early | 5.0 medium | 5.9% | 2009-01-06 |
| CVE-2006-1779 EXP | Cross-site scripting (XSS) vulnerability in login.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to inject arbitrary web scr… | Patch early | 6.8 medium | 5.9% | 2006-04-13 |
| CVE-2020-15363 EXP | The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection. | Patch early | 9.8 critical | 5.9% | 2020-06-28 |
| CVE-2006-3773 EXP | PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and Mambo 4.5.3+ allows remote atta… | Patch early | 6.8 medium | 5.9% | 2006-07-24 |
| CVE-2008-6770 EXP | YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to a datab… | Patch early | 5.0 medium | 5.9% | 2009-04-29 |
| CVE-2008-6771 EXP | YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a direct request to user/uploads/p… | Patch early | 5.0 medium | 5.9% | 2009-04-29 |
| CVE-2009-3646 EXP | InterVations NaviCOPA Web Server 3.01 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DAT… | Patch early | 5.0 medium | 5.9% | 2009-10-09 |
| CVE-2018-15917 EXP | Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter… | Patch early | 5.4 medium | 5.9% | 2018-09-05 |
| CVE-2002-1530 EXP | The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a req… | Patch early | 5.0 medium | 5.9% | 2003-03-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt