CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,317 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
206,774 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-4535 EXP | The VStr::Resize function in str.cpp in Vavoom 1.24 and earlier allows remote attackers to cause a denial of service (daemon crash) via a string with… | Patch early | 4.3 medium | 5.2% | 2007-08-25 |
| CVE-2018-12981 EXP | An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability can be exploited by authenti… | Patch early | 5.4 medium | 5.2% | 2018-07-12 |
| CVE-2018-16517 EXP | asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted fi… | Patch early | 5.5 medium | 5.2% | 2018-09-06 |
| CVE-2021-37593 EXP | PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the… | Patch early | 9.1 critical | 5.2% | 2021-07-30 |
| CVE-2008-5562 EXP | ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database fil… | Patch early | 5.0 medium | 5.2% | 2008-12-15 |
| CVE-2009-2022 EXP | fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the data… | Patch early | 5.0 medium | 5.2% | 2009-06-09 |
| CVE-2007-2753 EXP | RunawaySoft Haber portal 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo… | Patch early | 5.0 medium | 5.2% | 2007-05-17 |
| CVE-2007-5508 EXP | Multiple SQL injection vulnerabilities in the CTXSYS Intermedia application for the Oracle Text component (CTX_DOC) in Oracle Database 10.1.0.5 and 10… | Patch early | 6.5 medium | 5.2% | 2007-10-17 |
| CVE-2011-2165 EXP | The STARTTLS implementation in WatchGuard XCS 9.0 and 9.1 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert… | Patch early | 6.8 medium | 5.2% | 2011-05-23 |
| CVE-2011-0961 EXP | Cross-site scripting (XSS) vulnerability in cwhp/device.center.do in the Help servlet in Cisco CiscoWorks Common Services 3.3 and earlier allows remot… | Patch early | 4.3 medium | 5.2% | 2011-05-20 |
| CVE-2007-1473 EXP | Cross-site scripting (XSS) vulnerability in framework/NLS/NLS.php in Horde Framework before 3.1.4 RC1, when the login page contains a language selecti… | Patch early | 4.3 medium | 5.2% | 2007-03-16 |
| CVE-2007-1452 EXP | The FDF support (ext/fdf) in PHP 5.2.0 and earlier does not implement the input filtering hooks for ext/filter, which allows remote attackers to bypas… | Patch early | 5.0 medium | 5.2% | 2007-03-14 |
| CVE-2015-1368 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 5.2% | 2015-01-27 |
| CVE-2008-3824 EXP | Cross-site scripting (XSS) vulnerability in (1) Text_Filter/Filter/xss.php in Horde 3.1.x before 3.1.9 and 3.2.x before 3.2.2 and (2) externalinput.ph… | Patch early | 4.3 medium | 5.2% | 2008-09-12 |
| CVE-2007-2757 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Redoable 1.2 allow remote attackers to inject arbitrary web script or HTML via the s parameter… | Patch early | 6.8 medium | 5.1% | 2007-05-18 |
| CVE-2017-5124 EXP | Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXS… | Patch early | 6.1 medium | 5.1% | 2018-02-07 |
| CVE-2010-1687 EXP | Stack-based buffer overflow in lpd.exe in Mocha W32 LPD 1.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrar… | Patch early | 5.0 medium | 5.1% | 2010-05-04 |
| CVE-2006-5519 EXP | PHP remote file inclusion vulnerability in Savant2/Savant2_Plugin_options.php in the MambWeather 1.8.1 and earlier component for Mambo allows remote a… | Patch early | 6.8 medium | 5.1% | 2006-10-26 |
| CVE-2003-0293 EXP | PalmOS allows remote attackers to cause a denial of service (CPU consumption) via a flood of ICMP echo request (ping) packets. | Patch early | 5.0 medium | 5.1% | 2003-06-16 |
| CVE-2012-2171 EXP | SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Seri… | Patch early | 6.5 medium | 5.1% | 2012-06-22 |
| CVE-2020-25901 EXP | Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host heade… | Patch early | 6.1 medium | 5.1% | 2020-12-18 |
| CVE-2007-3017 EXP | The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/applets/wysiwyg/rende… | Patch early | 4.0 medium | 5.1% | 2007-07-17 |
| CVE-2004-2040 EXP | Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 pa… | Patch early | 4.3 medium | 5.1% | 2004-05-29 |
| CVE-2004-2081 EXP | The samiftp.dll library in Sami FTP Server 1.1.3 allows local users to cause a denial of service (pmsystem.exe crash) by issuing (1) a CD command with… | Patch early | 5.0 medium | 5.1% | 2004-12-31 |
| CVE-2011-4024 EXP | Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 5.1% | 2011-10-21 |
| CVE-2005-0780 EXP | paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php… | Patch early | 5.0 medium | 5.1% | 2005-03-12 |
| CVE-2006-3009 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to inject arbitrary HTML or web… | Patch early | 5.8 medium | 5.1% | 2006-06-13 |
| CVE-2000-0185 EXP | RealMedia RealServer reveals the real IP address of a Real Server, even if the address is supposed to be private. | Patch early | 5.0 medium | 5.1% | 2000-03-08 |
| CVE-2004-1100 EXP | Cross-site scripting (XSS) vulnerability in mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote… | Patch early | 6.8 medium | 5.1% | 2005-01-10 |
| CVE-2015-4591 EXP | eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remote unauthenticated users to in… | Patch early | 6.1 medium | 5.1% | 2017-01-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt