CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,546 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
170,147 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-1114 EXP | Multiple directory traversal vulnerabilities in Loudblog before 0.42 allow remote attackers to read or include arbitrary files via a .. (dot dot) and… | Patch early | 6.4 medium | 3.3% | 2006-03-09 |
| CVE-2012-3551 EXP | Cross-site scripting (XSS) vulnerability in crowbar_framework/app/views/support/index.html.haml in the Crowbar barclamp in Crowbar, possibly 1.4 and e… | Patch early | 4.3 medium | 3.3% | 2012-09-05 |
| CVE-2003-1371 EXP | Nuked-Klan 1.3b, and possibly earlier versions, allows remote attackers to obtain sensitive server information via an op parameter set to phpinfo for… | Patch early | 4.3 medium | 3.3% | 2003-12-31 |
| CVE-2007-0335 EXP | Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .… | Patch early | 6.8 medium | 3.3% | 2007-01-18 |
| CVE-2002-0209 EXP | Nortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled, allows remote attackers to de… | Patch early | 5.0 medium | 3.3% | 2002-05-16 |
| CVE-2008-0760 EXP | Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.0.4.0 and earlier, allows remo… | Patch early | 5.0 medium | 3.3% | 2008-02-13 |
| CVE-2000-0897 EXP | Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL that references a directory tha… | Patch early | 5.0 medium | 3.3% | 2001-01-09 |
| CVE-2001-0122 EXP | Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote atta… | Patch early | 5.0 medium | 3.3% | 2001-03-13 |
| CVE-2001-0386 EXP | AnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory. | Patch early | 5.0 medium | 3.3% | 2001-07-02 |
| CVE-2002-0894 EXP | NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to cause a denial of service (crash) via (1) a request for a long .jsp file, or (2) a long UR… | Patch early | 5.0 medium | 3.3% | 2002-10-04 |
| CVE-2002-1071 EXP | ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the… | Patch early | 5.0 medium | 3.3% | 2002-10-04 |
| CVE-2008-4087 EXP | Stack-based buffer overflow in Acoustica Beatcraft 1.02 Build 19 allows user-assisted attackers to cause a denial of service or execute arbitrary code… | Patch early | 6.8 medium | 3.3% | 2008-09-15 |
| CVE-2018-19749 EXP | DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field. | Patch early | 4.8 medium | 3.3% | 2018-11-29 |
| CVE-2018-19751 EXP | DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields. | Patch early | 4.8 medium | 3.3% | 2018-11-29 |
| CVE-2018-19752 EXP | DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar. | Patch early | 4.8 medium | 3.3% | 2018-11-29 |
| CVE-2018-19914 EXP | DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field. | Patch early | 4.8 medium | 3.3% | 2018-12-06 |
| CVE-2003-1219 EXP | Cross-site scripting (XSS) vulnerability in the tep_href_link function in html_output.php for osCommerce before 2.2-MS3 allows remote attackers to inj… | Patch early | 4.3 medium | 3.3% | 2003-12-31 |
| CVE-2006-3363 EXP | PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via a… | Patch early | 5.1 medium | 3.3% | 2006-07-06 |
| CVE-2005-4723 EXP | D-Link DI-524 Wireless Router, DI-624 Wireless Router, and DI-784 allow remote attackers to cause a denial of service (device reboot) via a series of… | Patch early | 5.0 medium | 3.3% | 2005-12-31 |
| CVE-2012-5967 EXP | SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote authenticated users to execut… | Patch early | 6.5 medium | 3.3% | 2012-12-19 |
| CVE-2007-4911 EXP | JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a long .mp3 URI to TCP port 8000.… | Patch early | 5.0 medium | 3.3% | 2007-09-17 |
| CVE-2009-3856 EXP | Cross-site scripting (XSS) vulnerability in the default URI in news/ in Twilight CMS before 4.1 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 3.3% | 2009-11-04 |
| CVE-2015-4665 EXP | Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 3.3% | 2015-08-13 |
| CVE-2012-3845 EXP | Buffer overflow in LAN Messenger 1.2.28 and earlier allows remote attackers to cause a denial of service (crash) via a long string in an initiation re… | Patch early | 5.0 medium | 3.3% | 2012-07-03 |
| CVE-2000-0569 EXP | Sybergen Sygate allows remote attackers to cause a denial of service by sending a malformed DNS UDP packet to its internal interface. | Patch early | 5.0 medium | 3.3% | 2000-06-30 |
| CVE-2000-1193 EXP | Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhausti… | Patch early | 5.0 medium | 3.3% | 2001-08-31 |
| CVE-2014-4014 EXP | The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows… | Patch early | 6.2 medium | 3.3% | 2014-06-23 |
| CVE-2020-9371 EXP | Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input… | Patch early | 4.8 medium | 3.3% | 2020-03-04 |
| CVE-2004-1953 EXP | phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error… | Patch early | 5.0 medium | 3.3% | 2004-12-31 |
| CVE-2005-1552 EXP | GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0, when set to create JPEG images, does not properly protect an image even when a password… | Patch early | 5.0 medium | 3.3% | 2005-05-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt