CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,267 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
206,724 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-4401 EXP | languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path… | Patch early | 5.0 medium | 5.5% | 2010-12-06 |
| CVE-2015-2841 EXP | Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type h… | Patch early | 5.0 medium | 5.5% | 2015-04-03 |
| CVE-2021-24299 EXP | The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservatio… | Patch early | 6.1 medium | 5.5% | 2021-05-17 |
| CVE-2018-10757 EXP | CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a login attempt. | Patch early | 9.8 critical | 5.5% | 2018-05-05 |
| CVE-2009-4168 EXP | Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module… | Patch early | 4.3 medium | 5.5% | 2009-12-02 |
| CVE-2013-1942 EXP | Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.20, as u… | Patch early | 4.3 medium | 5.5% | 2013-08-15 |
| CVE-2000-0152 EXP | Remote attackers can cause a denial of service in Novell BorderManager 3.5 by pressing the enter key in a telnet connection to port 2000. | Patch early | 5.0 medium | 5.5% | 2000-03-30 |
| CVE-2023-31067 EXP | An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMF… | Patch early | 9.8 critical | 5.5% | 2023-09-11 |
| CVE-2014-0866 EXP | RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext credentials over HTTP, which al… | Patch early | 4.3 medium | 5.5% | 2014-07-07 |
| CVE-2014-0869 EXP | The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics does not require a key,… | Patch early | 4.3 medium | 5.5% | 2014-07-07 |
| CVE-2013-3240 EXP | Directory traversal vulnerability in the Export feature in phpMyAdmin 4.x before 4.0.0-rc3 allows remote authenticated users to read arbitrary files o… | Patch early | 6.5 medium | 5.5% | 2013-04-26 |
| CVE-2008-3158 EXP | Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possibly related to IOCTL requests… | Patch early | 6.9 medium | 5.5% | 2008-07-11 |
| CVE-2009-0260 EXP | Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 5.5% | 2009-01-23 |
| CVE-2017-18016 EXP | Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting other websit… | Patch early | 5.3 medium | 5.5% | 2018-01-11 |
| CVE-2009-4511 EXP | Multiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before X5.1 allow re… | Patch early | 4.0 medium | 5.5% | 2010-04-13 |
| CVE-2011-3010 EXP | Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the ne… | Patch early | 4.3 medium | 5.5% | 2011-09-30 |
| CVE-2009-1232 EXP | Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption) via an XML document composed… | Patch early | 4.3 medium | 5.5% | 2009-04-02 |
| CVE-2006-1595 EXP | Cross-site scripting (XSS) vulnerability in document/rqmkhtml.php in Claroline 1.7.4 and earlier allows remote attackers to read arbitrary files via "… | Patch early | 4.3 medium | 5.5% | 2006-04-03 |
| CVE-2006-0841 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Mantis 1.00rc4 and earlier allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 5.5% | 2006-02-22 |
| CVE-2014-1564 EXP | Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which… | Patch early | 4.3 medium | 5.5% | 2014-09-03 |
| CVE-2011-4802 EXP | Multiple SQL injection vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote authenticated users to execute arbitrary SQL commands vi… | Patch early | 6.5 medium | 5.5% | 2011-12-14 |
| CVE-2013-4949 EXP | Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then a… | Patch early | 6.8 medium | 5.5% | 2013-07-29 |
| CVE-2013-5961 EXP | Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code… | Patch early | 6.8 medium | 5.5% | 2013-09-30 |
| CVE-2002-1089 EXP | rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers… | Patch early | 5.0 medium | 5.4% | 2002-10-04 |
| CVE-2008-3821 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 11.0 through 12.4 allow remote attackers to inject arbitrary web s… | Patch early | 4.3 medium | 5.4% | 2009-01-16 |
| CVE-2007-3844 EXP | Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) at… | Patch early | 4.3 medium | 5.4% | 2007-08-08 |
| CVE-2011-2641 EXP | Opera 11.11 allows remote attackers to cause a denial of service (application crash) by setting the FACE attribute of a FONT element within an IFRAME… | Patch early | 5.0 medium | 5.4% | 2011-07-01 |
| CVE-2003-1138 EXP | The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexi… | Patch early | 5.0 medium | 5.4% | 2003-10-27 |
| CVE-2007-6321 EXP | Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versions, when using Internet Explorer, allows remote at… | Patch early | 4.3 medium | 5.4% | 2007-12-12 |
| CVE-2007-5914 EXP | Direct static code injection vulnerability in dirsys/modules/config/post.php in JBC Explorer 7.20 RC1 and earlier allows remote authenticated administ… | Patch early | 6.8 medium | 5.4% | 2007-11-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt