CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,620 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
170,185 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-0135 EXP | Netopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of connections to one of the ports (1… | Patch early | 5.0 medium | 3.2% | 2002-03-25 |
| CVE-2006-2866 EXP | PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 5.1 medium | 3.2% | 2006-06-06 |
| CVE-2012-1024 EXP | Directory traversal vulnerability in file in Enigma2 Webinterface 1.5rc1 and 1.5beta4 allows remote attackers to read arbitrary files via a .. (dot do… | Patch early | 5.0 medium | 3.2% | 2012-02-08 |
| CVE-2010-2334 EXP | Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote attacker… | Patch early | 5.0 medium | 3.2% | 2010-06-18 |
| CVE-2012-6644 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat pa… | Patch early | 4.3 medium | 3.2% | 2014-04-08 |
| CVE-2013-1775 EXP | sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions a… | Patch early | 6.9 medium | 3.2% | 2013-03-05 |
| CVE-2017-3898 EXP | A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allow… | Patch early | 5.9 medium | 3.2% | 2017-09-01 |
| CVE-2007-1240 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS 3.0.3 through 3.0.5 allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 3.2% | 2007-03-03 |
| CVE-2016-6283 EXP | Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 6.1 medium | 3.2% | 2017-01-18 |
| CVE-2002-0812 EXP | Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default SN… | Patch early | 6.4 medium | 3.2% | 2002-08-12 |
| CVE-2011-1099 EXP | Multiple directory traversal vulnerabilities in FocalMedia.Net Quick Polls before 1.0.2 allow remote attackers to (1) read arbitrary files via a .. (d… | Patch early | 5.8 medium | 3.2% | 2011-03-09 |
| CVE-2020-8777 EXP | Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT el… | Patch early | 5.4 medium | 3.2% | 2020-03-02 |
| CVE-2002-2370 EXP | SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request that does not end with a newline. | Patch early | 5.0 medium | 3.2% | 2002-12-31 |
| CVE-2018-11564 EXP | Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileg… | Patch early | 4.8 medium | 3.2% | 2018-06-02 |
| CVE-2008-1401 EXP | Format string vulnerability in the Net Inspector HTTP server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attack… | Patch early | 4.3 medium | 3.2% | 2008-03-20 |
| CVE-2005-0847 EXP | Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections. | Patch early | 5.0 medium | 3.2% | 2005-05-02 |
| CVE-2007-2015 EXP | PHP remote file inclusion vulnerability in index.php in Request It 1.0b allows remote attackers to execute arbitrary PHP code via a URL in the id para… | Patch early | 6.8 medium | 3.2% | 2007-04-12 |
| CVE-2005-0621 EXP | Scrapland 1.0 and earlier allows remote attackers to cause a denial of service (server termination) by triggering an error, which is treated as a fata… | Patch early | 5.0 medium | 3.2% | 2005-05-02 |
| CVE-2005-1618 EXP | The YMSGR URL handler in Yahoo! Messenger 5.x through 6.0 allows remote attackers to cause a denial of service (disconnect) via a room login or a room… | Patch early | 5.0 medium | 3.2% | 2005-05-16 |
| CVE-2004-0245 EXP | Web Crossing 4.x and 5.x allows remote attackers to cause a denial of service (crash) by sending a HTTP POST request with a large or negative Content-… | Patch early | 5.0 medium | 3.2% | 2004-11-23 |
| CVE-2002-0964 EXP | Half-Life Server 1.1.1.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via multiple responses to the initial… | Patch early | 5.0 medium | 3.2% | 2002-10-04 |
| CVE-1999-0970 EXP | The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporar… | Patch early | 5.0 medium | 3.2% | 1999-06-05 |
| CVE-2002-0256 EXP | The telnet port in Arescom NetDSL 1000 router allows remote attackers to cause a denial of service via a series of connections with long strings, whic… | Patch early | 5.0 medium | 3.2% | 2002-05-29 |
| CVE-2013-5672 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the IndiaNIC Testimonial plugin 2.2 for WordPress allow remote attackers to hijack the a… | Patch early | 6.8 medium | 3.2% | 2013-09-10 |
| CVE-2013-5977 EXP | Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allows remote attackers t… | Patch early | 6.8 medium | 3.2% | 2013-11-01 |
| CVE-2007-1539 EXP | Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to include arbitrary files via a .. (d… | Patch early | 4.3 medium | 3.2% | 2007-03-20 |
| CVE-2010-0757 EXP | Unrestricted file upload vulnerability in index.php/Attach in WikyBlog 1.7.3rc2 allows remote authenticated users to execute arbitrary code by uploadi… | Patch early | 6.5 medium | 3.2% | 2010-02-27 |
| CVE-2006-5191 EXP | PHP remote file inclusion vulnerability in includes/functions_static_topics.php in the Nivisec Static Topics module for phpBB 1.0 and earlier allows r… | Patch early | 5.1 medium | 3.2% | 2006-10-10 |
| CVE-2004-1801 EXP | Directory traversal vulnerability in PWebServer 0.3.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | Patch early | 5.0 medium | 3.2% | 2004-12-31 |
| CVE-2005-1493 EXP | Directory traversal vulnerability in SimpleCam 1.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URL. | Patch early | 5.0 medium | 3.2% | 2005-05-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt