CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,212 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
206,689 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-42566 EXP | myfactory.FMS before 7.1-912 allows XSS via the Error parameter. | Patch early | 6.1 medium | 5.8% | 2021-10-18 |
| CVE-2006-4000 EXP | Directory traversal vulnerability in cgi-bin/preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote authentica… | Patch early | 4.0 medium | 5.8% | 2006-08-05 |
| CVE-2007-4507 EXP | Multiple buffer overflows in the php_ntuser component for PHP 5.2.3 allow context-dependent attackers to cause a denial of service or execute arbitrar… | Patch early | 6.8 medium | 5.8% | 2007-08-23 |
| CVE-1999-0844 EXP | Denial of service in MDaemon WorldClient and WebConfig services via a long URL. | Patch early | 5.0 medium | 5.8% | 1999-11-24 |
| CVE-2010-4480 EXP | error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a cr… | Patch early | 4.3 medium | 5.8% | 2010-12-08 |
| CVE-2014-2341 EXP | Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter. | Patch early | 6.8 medium | 5.8% | 2014-04-22 |
| CVE-2018-10832 EXP | ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files,… | Patch early | 5.5 medium | 5.8% | 2018-05-11 |
| CVE-2009-2108 EXP | git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request contain… | Patch early | 5.0 medium | 5.8% | 2009-06-18 |
| CVE-2019-10887 EXP | A reflected HTML injection vulnerability on Salicru SLC-20-cube3(5) devices running firmware version cs121-SNMP v4.54.82.130611 allows remote attacker… | Patch early | 6.1 medium | 5.8% | 2019-04-05 |
| CVE-2006-3750 EXP | PHP remote file inclusion vulnerability in server.php in the Hashcash Component (com_hashcash) 1.2.1 for Joomla! allows remote attackers to execute ar… | Patch early | 6.8 medium | 5.8% | 2006-07-21 |
| CVE-2006-4195 EXP | PHP remote file inclusion vulnerability in param.peoplebook.php in the Peoplebook Component for Mambo (com_peoplebook) 1.0 and earlier, and possibly 1… | Patch early | 6.8 medium | 5.8% | 2006-08-17 |
| CVE-2006-4288 EXP | PHP remote file inclusion vulnerability in admin.a6mambocredits.php in the a6mambocredits component (com_a6mambocredits) 2.0.0 and earlier for Mambo a… | Patch early | 6.8 medium | 5.8% | 2006-08-22 |
| CVE-2008-5752 EXP | Directory traversal vulnerability in getConfig.php in the Page Flip Image Gallery plugin 0.2.2 and earlier for WordPress, when magic_quotes_gpc is dis… | Patch early | 4.3 medium | 5.8% | 2008-12-30 |
| CVE-2009-0753 EXP | Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files via a leading "//" (double slash… | Patch early | 5.0 medium | 5.8% | 2009-03-03 |
| CVE-2019-11429 EXP | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro) is vulnerable to Reflected XS… | Patch early | 4.8 medium | 5.8% | 2019-05-13 |
| CVE-2007-4186 EXP | PHP remote file inclusion vulnerability in admin.tour_toto.php in the Tour de France Pool (com_tour_toto) 1.0.1 module for Joomla! allows remote attac… | Patch early | 6.8 medium | 5.8% | 2007-08-08 |
| CVE-2018-9115 EXP | Systematic SitaWare 6.4 SP2 does not validate input from other sources sufficiently. e.g., information utilizing the NVG interface. An attacker can fr… | Patch early | 5.3 medium | 5.8% | 2018-04-04 |
| CVE-2012-4751 EXP | Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x before 3.0.17, and 3.1.x before 3.1… | Patch early | 4.3 medium | 5.8% | 2012-10-22 |
| CVE-2007-5446 EXP | Absolute path traversal vulnerability in a certain ActiveX control in PBEmail7Ax.dll in PBEmail 7 ActiveX Edition allows remote attackers to create or… | Patch early | 6.4 medium | 5.8% | 2007-10-14 |
| CVE-2007-5309 EXP | PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Jooml… | Patch early | 6.8 medium | 5.8% | 2007-10-09 |
| CVE-2007-6057 EXP | PHP remote file inclusion vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execut… | Patch early | 6.8 medium | 5.8% | 2007-11-20 |
| CVE-2015-2292 EXP | Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4… | Patch early | 6.5 medium | 5.8% | 2015-03-17 |
| CVE-2014-4311 EXP | Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows attackers to obtain the (1) Database Connection and (2) E-mail Connection passwords by read… | Patch early | 5.0 medium | 5.8% | 2014-11-04 |
| CVE-2008-6982 EXP | Cross-site scripting (XSS) vulnerability in index.php in devalcms 1.4a allows remote attackers to inject arbitrary web script or HTML via the currentp… | Patch early | 4.3 medium | 5.8% | 2009-08-19 |
| CVE-2023-31714 EXP | Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities. | Patch early | 9.8 critical | 5.8% | 2023-08-30 |
| CVE-2009-2820 EXP | The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2)… | Patch early | 4.3 medium | 5.8% | 2009-11-10 |
| CVE-2007-1622 EXP | Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote au… | Patch early | 4.3 medium | 5.8% | 2007-03-23 |
| CVE-2017-5496 EXP | Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash. | Patch early | 9.8 critical | 5.8% | 2017-03-15 |
| CVE-2008-3234 EXP | sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux role… | Patch early | 6.5 medium | 5.8% | 2008-07-18 |
| CVE-2008-6958 EXP | wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula parameter. | Patch early | 6.5 medium | 5.8% | 2009-08-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt