CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,488 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
206,856 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-7402 EXP | Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager… | Patch early | 9.8 critical | 5% | 2017-04-03 |
| CVE-2007-4377 EXP | Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argument to th… | Patch early | 6.0 medium | 5% | 2007-08-16 |
| CVE-2004-1719 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 5% | 2004-08-17 |
| CVE-2006-4359 EXP | Stack-based buffer overflow in Trident Software PowerZip 7.06 Build 3895 on Windows 2000 allows remote attackers to execute arbitrary code via a ZIP a… | Patch early | 5.1 medium | 5% | 2006-08-27 |
| CVE-2008-4626 EXP | Directory traversal vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 and possibly other versi… | Patch early | 6.8 medium | 5% | 2008-10-21 |
| CVE-2008-1304 EXP | Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) invit… | Patch early | 4.3 medium | 5% | 2008-03-12 |
| CVE-2003-1136 EXP | Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web script or HTML via (1) HTML i… | Patch early | 4.3 medium | 5% | 2003-10-23 |
| CVE-2006-4553 EXP | PHP remote file inclusion vulnerability in plugin.class.php in the com_comprofiler Components 1.0 RC2 for Mambo and Joomla! allows remote attackers to… | Patch early | 6.8 medium | 5% | 2006-09-06 |
| CVE-2009-3421 EXP | login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrativ… | Patch early | 9.8 critical | 5% | 2009-09-25 |
| CVE-2017-7938 EXP | Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cause a denial of service (applic… | Patch early | 6.6 medium | 5% | 2017-04-20 |
| CVE-2013-5676 EXP | The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading th… | Patch early | 4.0 medium | 5% | 2013-12-13 |
| CVE-2014-0865 EXP | RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which a… | Patch early | 4.9 medium | 5% | 2014-07-07 |
| CVE-2010-3695 EXP | Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allows rem… | Patch early | 4.3 medium | 5% | 2011-03-31 |
| CVE-2006-4865 EXP | Walter Beschmout PhpQuiz allows remote attackers to obtain sensitive information via a direct request to cfgphpquiz/install.php and other unspecified… | Patch early | 5.0 medium | 5% | 2006-09-19 |
| CVE-2006-3748 EXP | PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and possibly other versions includi… | Patch early | 6.8 medium | 5% | 2006-07-21 |
| CVE-2004-0591 EXP | Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to… | Patch early | 6.8 medium | 5% | 2004-08-06 |
| CVE-2010-2129 EXP | Directory traversal vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.1 and 1.0.3 for Joomla! allows remote attacker… | Patch early | 6.8 medium | 5% | 2010-06-01 |
| CVE-2007-1020 EXP | Cross-site scripting (XSS) vulnerability in index.php in CedStat 1.31 allows remote attackers to inject arbitrary web script or HTML via the hier para… | Patch early | 6.8 medium | 5% | 2007-02-21 |
| CVE-2005-1380 EXP | Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server param… | Patch early | 6.8 medium | 5% | 2005-05-03 |
| CVE-2006-4608 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to inject arbitrary web script or HTML… | Patch early | 6.8 medium | 5% | 2006-09-07 |
| CVE-2008-6253 EXP | Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allows remote attackers to include… | Patch early | 6.8 medium | 5% | 2009-02-24 |
| CVE-2007-3060 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PHP Live! 3.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) sid p… | Patch early | 4.3 medium | 5% | 2007-06-06 |
| CVE-2013-4868 EXP | Karotz API 12.07.19.00: Session Token Information Disclosure | Patch early | 5.3 medium | 5% | 2019-12-27 |
| CVE-2007-6103 EXP | I Hear U (IHU) 0.5.6 and earlier allows remote attackers to cause (1) a denial of service (infinite loop) via a packet that contains zero in the size… | Patch early | 5.0 medium | 5% | 2007-11-23 |
| CVE-2017-0300 EXP | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… | Patch early | 5.0 medium | 5% | 2017-06-15 |
| CVE-2007-1702 EXP | PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote attackers to execute arbitrary… | Patch early | 6.8 medium | 5% | 2007-03-27 |
| CVE-2013-7387 EXP | Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions via the PHPSESSID cookie. | Patch early | 6.8 medium | 5% | 2014-06-02 |
| CVE-2026-26980 EXP | Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the datab… | Patch early | 9.4 critical | 5% | 2026-02-20 |
| CVE-2010-2630 EXP | The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate the data types of codec-specific tags that have an out-of-order position in… | Patch early | 4.3 medium | 5% | 2010-07-06 |
| CVE-2017-4916 EXP | VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issu… | Patch early | 6.5 medium | 5% | 2017-05-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt