CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,573 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
170,169 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-4510 EXP | Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page fault and system crash) via mu… | Patch early | 4.9 medium | 3.3% | 2008-10-09 |
| CVE-2015-7901 EXP | Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execute arbitrary OS commands via un… | Patch early | 6.5 medium | 3.3% | 2015-10-28 |
| CVE-2000-0332 EXP | UltraBoard.pl or UltraBoard.cgi CGI scripts in UltraBoard 1.6 allows remote attackers to read arbitrary files via a pathname string that includes a do… | Patch early | 5.0 medium | 3.3% | 2000-05-03 |
| CVE-2001-1107 EXP | SnapStream PVS 1.2a stores its passwords in plaintext in the file SSD.ini, which could allow a remote attacker to gain privileges on the server. | Patch early | 5.0 medium | 3.3% | 2001-07-26 |
| CVE-2001-1194 EXP | Zyxel Prestige 681 and 1600 SDSL Routers allow remote attackers to cause a denial of service via malformed packets with (1) an IP length less than act… | Patch early | 5.0 medium | 3.3% | 2001-12-14 |
| CVE-2008-0298 EXP | KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a crafted web page, possibly involvi… | Patch early | 4.3 medium | 3.3% | 2008-01-16 |
| CVE-2006-4586 EXP | The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticated users to perform unauthoriz… | Patch early | 5.5 medium | 3.3% | 2006-09-06 |
| CVE-2008-3117 EXP | Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated users to execute arbitrary code… | Patch early | 6.5 medium | 3.3% | 2008-07-10 |
| CVE-2008-7088 EXP | Unrestricted file upload vulnerability in upload.php in PhotoPost vBGallery 2.4.2 allows remote authenticated users to execute arbitrary code by uploa… | Patch early | 6.5 medium | 3.3% | 2009-08-26 |
| CVE-2013-1938 EXP | Zimbra 2013 has XSS in aspell.php | Patch early | 6.1 medium | 3.3% | 2020-02-12 |
| CVE-2000-1230 EXP | Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set… | Patch early | 5.0 medium | 3.3% | 2000-12-31 |
| CVE-2014-10078 EXP | Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerc… | Patch early | 6.1 medium | 3.3% | 2019-02-23 |
| CVE-2012-2919 EXP | Directory traversal vulnerability in Upload/engine.php in Chevereto 1.9.1 allows remote attackers to determine the existence of arbitrary files via a… | Patch early | 5.0 medium | 3.3% | 2012-05-21 |
| CVE-2021-24308 EXP | The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugi… | Patch early | 5.4 medium | 3.2% | 2021-05-24 |
| CVE-2005-0370 EXP | Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (network disconnection)… | Patch early | 5.0 medium | 3.2% | 2005-05-02 |
| CVE-2014-100030 EXP | Cross-site scripting (XSS) vulnerability in module/search/function.php in Ganesha Digital Library (GDL) 4.2 allows remote attackers to inject arbitrar… | Patch early | 4.3 medium | 3.2% | 2015-01-13 |
| CVE-2014-4965 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 3.2% | 2014-07-15 |
| CVE-2013-3538 EXP | Multiple cross-site scripting (XSS) vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3.2% | 2013-05-13 |
| CVE-2013-5092 EXP | Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 3.2% | 2014-01-29 |
| CVE-2010-0553 EXP | Geo++ GNCASTER 1.4.0.7 and earlier allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary c… | Patch early | 6.5 medium | 3.2% | 2010-02-04 |
| CVE-2016-1609 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allow remote authenti… | Patch early | 5.4 medium | 3.2% | 2016-08-01 |
| CVE-2006-4596 EXP | PHP remote file inclusion in MyBace Light Skrip, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the (1) h… | Patch early | 5.1 medium | 3.2% | 2006-09-07 |
| CVE-2013-7368 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Gnew 2013.1 allow remote attackers to inject arbitrary web script or HTML via the gnew_template… | Patch early | 4.3 medium | 3.2% | 2014-04-15 |
| CVE-2019-7541 EXP | Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring. | Patch early | 6.1 medium | 3.2% | 2019-05-07 |
| CVE-2006-4130 EXP | PHP remote file inclusion vulnerability in admin.remository.php in the Remository Component (com_remository) 3.25 and earlier for Mambo and Joomla!, w… | Patch early | 6.8 medium | 3.2% | 2006-08-14 |
| CVE-2008-0756 EXP | The LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4… | Patch early | 5.0 medium | 3.2% | 2008-02-13 |
| CVE-2004-1739 EXP | Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users. | Patch early | 5.0 medium | 3.2% | 2004-08-23 |
| CVE-2004-0264 EXP | palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the… | Patch early | 5.0 medium | 3.2% | 2004-11-23 |
| CVE-2007-4079 EXP | Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft SMS Text Messaging Enterprise allow remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 3.2% | 2007-07-30 |
| CVE-2000-0417 EXP | The HTTP administration interface to the Cayman 3220-H DSL router allows remote attackers to cause a denial of service via a long username or password… | Patch early | 5.0 medium | 3.2% | 2000-05-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt