CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,590 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
170,178 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-5684 EXP | Cross-site scripting (XSS) vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the inFullnam… | Patch early | 4.3 medium | 3.2% | 2014-08-14 |
| CVE-2011-5283 EXP | Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier… | Patch early | 4.3 medium | 3.2% | 2014-12-31 |
| CVE-2008-0372 EXP | 8e6 R3000 Internet Filter 2.0.05.33, and other versions before 2.0.11, allows remote attackers to bypass intended restrictions via a fragmented HTTP r… | Patch early | 5.0 medium | 3.2% | 2008-01-22 |
| CVE-2015-5999 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2.06.B09_BETA allow remote atta… | Patch early | 6.8 medium | 3.2% | 2015-11-18 |
| CVE-2007-0548 EXP | KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number of requests for nonexistent obj… | Patch early | 5.0 medium | 3.2% | 2007-01-29 |
| CVE-2011-4532 EXP | Absolute path traversal vulnerability in the ALMListView.ALMListCtrl ActiveX control in almaxcx.dll in the graphical user interface in Siemens Automat… | Patch early | 5.0 medium | 3.2% | 2012-01-08 |
| CVE-2019-1010124 EXP | WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in… | Patch early | 5.4 medium | 3.2% | 2019-07-23 |
| CVE-1999-1569 EXP | Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood of spoofed… | Patch early | 5.0 medium | 3.2% | 2001-07-17 |
| CVE-2001-0564 EXP | APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial of service v… | Patch early | 5.0 medium | 3.2% | 2001-08-22 |
| CVE-2001-0675 EXP | Rit Research Labs The Bat! 1.51 for Windows allows a remote attacker to cause a denial of service by sending an email to a user's account containing a… | Patch early | 5.0 medium | 3.2% | 2001-09-20 |
| CVE-2002-0431 EXP | XTux allows remote attackers to cause a denial of service (CPU consumption) via random inputs in the initial connection. | Patch early | 5.0 medium | 3.2% | 2002-07-26 |
| CVE-2002-1023 EXP | BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI. | Patch early | 5.0 medium | 3.2% | 2002-10-04 |
| CVE-2002-1029 EXP | Res Manager in Worldspan for Windows Gateway 4.1 allows remote attackers to cause a denial of service (crash) via a malformed request to TCP port 1799… | Patch early | 5.0 medium | 3.2% | 2002-10-04 |
| CVE-2002-1072 EXP | ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented "jolt"… | Patch early | 5.0 medium | 3.2% | 2002-10-04 |
| CVE-2004-2475 EXP | Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the Abou… | Patch early | 4.3 medium | 3.2% | 2004-12-31 |
| CVE-2007-4081 EXP | Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3.2% | 2007-07-30 |
| CVE-2013-6233 EXP | Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Descri… | Patch early | 4.3 medium | 3.2% | 2014-03-09 |
| CVE-2004-1878 EXP | LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl pr… | Patch early | 5.0 medium | 3.2% | 2004-03-30 |
| CVE-2002-1539 EXP | Buffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service via long (1) DELE or (2) UIDL a… | Patch early | 5.0 medium | 3.2% | 2003-03-31 |
| CVE-2010-0641 EXP | Cross-site scripting (XSS) vulnerability in webline/html/admin/wcs/LoginPage.jhtml in Cisco Collaboration Server (CCS) 5 allows remote attackers to in… | Patch early | 4.3 medium | 3.2% | 2010-02-17 |
| CVE-2018-18324 EXP | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter, or the admin/index.php modul… | Patch early | 6.1 medium | 3.2% | 2018-10-15 |
| CVE-2002-1982 EXP | Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine if a directory exists via a ..… | Patch early | 5.0 medium | 3.2% | 2002-12-31 |
| CVE-2004-0349 EXP | Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot dot) in the URL. | Patch early | 5.0 medium | 3.2% | 2004-11-23 |
| CVE-2013-2107 EXP | Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote attackers to hijack the authenti… | Patch early | 6.8 medium | 3.2% | 2014-05-23 |
| CVE-2003-0760 EXP | Blubster 2.5 allows remote attackers to cause a denial of service (crash) via a flood of connections to UDP port 701. | Patch early | 5.0 medium | 3.2% | 2003-09-17 |
| CVE-2001-0646 EXP | Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating a directory name of a specifi… | Patch early | 5.0 medium | 3.2% | 2001-09-20 |
| CVE-2009-2443 EXP | Siteframe 3.2.3, and other 3.2.x versions, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which call… | Patch early | 5.0 medium | 3.2% | 2009-07-13 |
| CVE-2009-3597 EXP | Digitaldesign CMS 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… | Patch early | 5.0 medium | 3.2% | 2009-10-08 |
| CVE-2022-0377 EXP | Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this process the user cro… | Patch early | 4.3 medium | 3.2% | 2022-02-28 |
| CVE-2009-2160 EXP | TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpinfo.php, which calls the phpinf… | Patch early | 5.0 medium | 3.2% | 2009-06-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt