CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,371 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
206,802 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-2104 EXP | cgi-bin/munin-cgi-graph in Munin 2.x writes data to a log file without sanitizing non-printable characters, which might allow user-assisted remote att… | Patch early | 6.8 medium | 5.1% | 2012-08-26 |
| CVE-2005-3818 EXP | Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1… | Patch early | 4.3 medium | 5.1% | 2005-11-26 |
| CVE-2005-2804 EXP | Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers to cause a denial of service (… | Patch early | 5.0 medium | 5.1% | 2005-10-04 |
| CVE-2007-5693 EXP | Eval injection vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to execute arbitrary PHP co… | Patch early | 6.0 medium | 5.1% | 2007-10-29 |
| CVE-2011-1547 EXP | Multiple stack consumption vulnerabilities in the kernel in NetBSD 4.0, 5.0 before 5.0.3, and 5.1 before 5.1.1, when IPsec is enabled, allow remote at… | Patch early | 6.8 medium | 5.1% | 2011-05-09 |
| CVE-2012-5452 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) mul… | Patch early | 4.3 medium | 5.1% | 2012-10-22 |
| CVE-2021-27889 EXP | Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages. | Patch early | 6.1 medium | 5.1% | 2021-03-15 |
| CVE-2008-0192 EXP | Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 5.1% | 2008-01-10 |
| CVE-2013-4883 EXP | Multiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePO Extension for the McAfee Agent (MA)… | Patch early | 4.3 medium | 5.1% | 2013-07-22 |
| CVE-2014-0867 EXP | rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote atta… | Patch early | 5.8 medium | 5.1% | 2014-07-07 |
| CVE-1999-0269 EXP | Netscape Enterprise servers may list files through the PageServices query. | Patch early | 5.0 medium | 5.1% | 1998-08-01 |
| CVE-2021-24901 EXP | The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow high privilege users to perform… | Patch early | 4.8 medium | 5.1% | 2022-02-28 |
| CVE-2021-24904 EXP | The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, w… | Patch early | 4.8 medium | 5.1% | 2022-02-14 |
| CVE-2006-3362 EXP | Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3,… | Patch early | 5.1 medium | 5.1% | 2006-07-06 |
| CVE-2009-2360 EXP | Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote attackers to inject arbitrary we… | Patch early | 4.3 medium | 5.1% | 2009-07-08 |
| CVE-2006-7169 EXP | PHP remote file inclusion vulnerability in includes/header_simple.php in Ultimate PHP Board (UPB) 2.0 and earlier allows remote attackers to execute a… | Patch early | 6.8 medium | 5.1% | 2007-03-20 |
| CVE-2018-5759 EXP | jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows remote attackers to cause a deni… | Patch early | 5.5 medium | 5.1% | 2018-01-24 |
| CVE-2005-3636 EXP | Cross-site scripting (XSS) vulnerability in SAP Web Application Server (WAS) 6.10 allows remote attackers to inject arbitrary web script or HTML via E… | Patch early | 4.3 medium | 5.1% | 2005-11-16 |
| CVE-2007-4104 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 5.1% | 2007-07-31 |
| CVE-2005-1470 EXP | Multiple unknown vulnerabilities in the (1) TZSP, (2) MGCP, (3) ISUP, (4) SMB, or (5) Bittorrent dissectors in Ethereal before 0.10.11 allow remote at… | Patch early | 5.0 medium | 5% | 2005-05-05 |
| CVE-2016-0079 EXP | The kernel in Microsoft Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to acce… | Patch early | 5.0 medium | 5% | 2016-10-14 |
| CVE-2010-1003 EXP | Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include and execu… | Patch early | 6.8 medium | 5% | 2010-03-19 |
| CVE-2010-1174 EXP | Cisco TFTP Server 1.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) read (aka RRQ) or (2) write (aka WRQ) requ… | Patch early | 5.0 medium | 5% | 2010-03-29 |
| CVE-2006-2413 EXP | GNUnet before SVN revision 2781 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an empty UDP datagram, po… | Patch early | 5.0 medium | 5% | 2006-05-16 |
| CVE-2002-1405 EXP | CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on t… | Patch early | 5.0 medium | 5% | 2003-02-19 |
| CVE-2001-0486 EXP | Remote attackers can cause a denial of service in Novell BorderManager 3.6 and earlier by sending TCP SYN flood to port 353. | Patch early | 5.0 medium | 5% | 2001-07-02 |
| CVE-2005-3635 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SAP Web Application Server (WAS) 6.10 through 7.00 allow remote attackers to inject arbitrary w… | Patch early | 4.3 medium | 5% | 2005-11-16 |
| CVE-2017-12950 EXP | The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and applica… | Patch early | 6.5 medium | 5% | 2017-08-28 |
| CVE-2012-6622 EXP | Multiple cross-site scripting (XSS) vulnerabilities in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allow… | Patch early | 4.3 medium | 5% | 2014-01-16 |
| CVE-2009-3863 EXP | Buffer overflow in the gxmim1.dll ActiveX control in Novell Groupwise Client 7.0.3.1294 allows remote attackers to cause a denial of service (applicat… | Patch early | 5.0 medium | 5% | 2009-11-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt