CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,295 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
206,761 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-24610 EXP | The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' functio… | Patch early | 4.8 medium | 5.4% | 2021-09-27 |
| CVE-2015-1059 EXP | Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute arbitrary PHP code by uploadi… | Patch early | 6.5 medium | 5.4% | 2015-01-16 |
| CVE-2014-8391 EXP | The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive information fr… | Patch early | 4.0 medium | 5.4% | 2015-06-02 |
| CVE-2023-31068 EXP | An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMF… | Patch early | 9.8 critical | 5.4% | 2023-09-11 |
| CVE-2017-17970 EXP | Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to login.php… | Patch early | 9.8 critical | 5.4% | 2018-01-12 |
| CVE-2013-5573 EXP | Cross-site scripting (XSS) vulnerability in the default markup formatter in Jenkins 1.523 allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 5.4% | 2013-12-31 |
| CVE-2004-2523 EXP | Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to exe… | Patch early | 6.5 medium | 5.4% | 2004-12-31 |
| CVE-2008-3303 EXP | admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication and obtain administrative acces… | Patch early | 6.8 medium | 5.4% | 2008-07-25 |
| CVE-2019-14339 EXP | The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly restrict canon.ij.printer.capabil… | Patch early | 5.5 medium | 5.4% | 2019-09-05 |
| CVE-2006-2465 EXP | Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. NOTE: if mp3info is not installed setui… | Patch early | 5.1 medium | 5.4% | 2006-05-19 |
| CVE-2011-4880 EXP | Directory traversal vulnerability in the web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to read arbitrary file… | Patch early | 5.0 medium | 5.4% | 2012-04-13 |
| CVE-2011-4074 EXP | Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 5.4% | 2011-11-02 |
| CVE-2007-4517 EXP | Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remote authenticated users to execute arbitrary code v… | Patch early | 6.0 medium | 5.4% | 2007-11-08 |
| CVE-2007-6623 EXP | Absolute path traversal vulnerability in ZeusCMS 0.3 and earlier might allow remote attackers to list arbitrary directories via a full pathname in the… | Patch early | 5.0 medium | 5.4% | 2008-01-04 |
| CVE-2020-18662 EXP | SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php. | Patch early | 9.8 critical | 5.4% | 2021-06-24 |
| CVE-2008-5266 EXP | Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Applic… | Patch early | 4.3 medium | 5.4% | 2008-11-28 |
| CVE-2002-0886 EXP | Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a large… | Patch early | 5.0 medium | 5.4% | 2002-10-04 |
| CVE-2022-22836 EXP | CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request. | Patch early | 6.5 medium | 5.4% | 2022-01-10 |
| CVE-2001-1064 EXP | Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the route… | Patch early | 5.0 medium | 5.4% | 2001-08-31 |
| CVE-2007-5410 EXP | PHP remote file inclusion vulnerability in admin.wmtrssreader.php in the webmaster-tips.net Flash RSS Reader (com_wmtrssreader) 1.0 component for Joom… | Patch early | 6.8 medium | 5.4% | 2007-10-12 |
| CVE-2004-2736 EXP | Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cookie. | Patch early | 5.0 medium | 5.4% | 2004-12-31 |
| CVE-2015-2678 EXP | Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 5.4% | 2015-03-23 |
| CVE-2024-30896 EXP | InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access… | Patch early | 9.1 critical | 5.4% | 2024-11-21 |
| CVE-2000-0278 EXP | The SalesLogix Eviewer allows remote attackers to cause a denial of service by accessing the URL for the slxweb.dll administration program, which does… | Patch early | 5.0 medium | 5.4% | 2000-08-03 |
| CVE-2009-0162 EXP | Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7 and Windows allows remote att… | Patch early | 4.3 medium | 5.4% | 2009-05-13 |
| CVE-2000-0212 EXP | InterAccess TelnetD Server 4.0 allows remote attackers to conduct a denial of service via malformed terminal client configuration information. | Patch early | 5.0 medium | 5.4% | 2000-02-24 |
| CVE-2000-0451 EXP | The Intel express 8100 ISDN router allows remote attackers to cause a denial of service via oversized or fragmented ICMP packets. | Patch early | 5.0 medium | 5.4% | 2000-05-19 |
| CVE-2022-40347 EXP | SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allow… | Patch early | 9.8 critical | 5.3% | 2023-02-17 |
| CVE-2015-6970 EXP | The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML… | Patch early | 9.8 critical | 5.3% | 2020-02-18 |
| CVE-2006-1960 EXP | Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express… | Patch early | 5.8 medium | 5.3% | 2006-04-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt