CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,997 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
170,228 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-2791 EXP | BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, allows remote attackers to cause a denial of service (refuse… | Patch early | 5.0 medium | 3.1% | 2005-09-02 |
| CVE-2004-1585 EXP | Flash Messaging 5.2.0g (rev 1.1.2) and earlier allows remote attackers to cause a denial of service (application crash) via certain wide characters. | Patch early | 5.0 medium | 3.1% | 2004-12-31 |
| CVE-2004-1727 EXP | BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address. | Patch early | 5.0 medium | 3.1% | 2004-08-20 |
| CVE-2005-0568 EXP | Soldier of Fortune II 1.03 gold allows remote attackers to cause a denial of service (application crash) via a large cl_guid value, which results in a… | Patch early | 5.0 medium | 3.1% | 2005-05-02 |
| CVE-2005-0848 EXP | Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, S… | Patch early | 5.0 medium | 3.1% | 2005-05-02 |
| CVE-2023-3897 EXP | Username enumeration is possible through Bypassing CAPTCHA in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local use… | Patch early | 4.8 medium | 3.1% | 2023-07-25 |
| CVE-2020-28249 EXP | Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note. | Patch early | 6.1 medium | 3.1% | 2020-11-06 |
| CVE-2004-2045 EXP | The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (dev… | Patch early | 5.0 medium | 3.1% | 2004-12-31 |
| CVE-2004-2120 EXP | Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET requests without the HTTP versio… | Patch early | 5.0 medium | 3.1% | 2004-01-23 |
| CVE-1999-1130 EXP | Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the sourc… | Patch early | 5.0 medium | 3.1% | 1999-07-30 |
| CVE-2001-0693 EXP | WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20). | Patch early | 5.0 medium | 3.1% | 2001-09-20 |
| CVE-2013-5756 EXP | Directory traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a .. (dot dot) in the p… | Patch early | 4.0 medium | 3.1% | 2014-08-03 |
| CVE-2008-6201 EXP | Directory traversal vulnerability in help.php in the eskuel module in KwsPHP 1.3.456, as available before 20080416, allows remote attackers to execute… | Patch early | 6.8 medium | 3.1% | 2009-02-20 |
| CVE-2005-1800 EXP | Cross-site scripting (XSS) vulnerability in Jaws Glossary gadget 0.4 to 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the t… | Patch early | 4.3 medium | 3.1% | 2005-05-28 |
| CVE-2017-11330 EXP | The DivFixppCore::avi_header_fix function in DivFix++Core.cpp in DivFix++ v0.34 allows remote attackers to cause a denial of service (invalid memory w… | Patch early | 5.5 medium | 3.1% | 2017-07-31 |
| CVE-2009-2890 EXP | Cross-site scripting (XSS) vulnerability in results.php in PHP Scripts Now Riddles allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 3.1% | 2009-08-20 |
| CVE-2008-6914 EXP | Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users to execute arbitrary code by up… | Patch early | 6.5 medium | 3.1% | 2009-08-07 |
| CVE-2008-4366 EXP | Unrestricted file upload vulnerability in the image upload component in Camera Life 2.6.2b4 allows remote authenticated users to execute arbitrary cod… | Patch early | 6.5 medium | 3.1% | 2008-09-30 |
| CVE-2008-7185 EXP | GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlist (.pls) file with a long Titl… | Patch early | 4.3 medium | 3.1% | 2009-09-08 |
| CVE-2007-1127 EXP | Directory traversal vulnerability in enc/stylecss.php in shopkitplus allows remote attackers to read arbitrary files via a .. (dot dot) in the changet… | Patch early | 6.4 medium | 3.1% | 2007-02-27 |
| CVE-2008-3407 EXP | phpLinkat 0.1 allows remote attackers to bypass authentication and access unspecified pages under admin/ by sending a login=right cookie. | Patch early | 5.0 medium | 3.1% | 2008-07-31 |
| CVE-2011-1038 EXP | Multiple cross-site scripting (XSS) vulnerabilities in stconf.nsf in the server in IBM Lotus Sametime 8.0.1 allow remote attackers to inject arbitrary… | Patch early | 4.3 medium | 3.1% | 2011-02-22 |
| CVE-2007-5982 EXP | Multiple cross-site scripting (XSS) vulnerabilities in X7 Chat 2.0.4, 2.0.5, and possibly other versions allow remote attackers to inject arbitrary we… | Patch early | 4.3 medium | 3.1% | 2007-11-15 |
| CVE-2006-5306 EXP | Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow remote attackers to execute a… | Patch early | 6.8 medium | 3.1% | 2006-10-17 |
| CVE-2020-25988 EXP | UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' which leaks the credentials of '… | Patch early | 6.5 medium | 3.1% | 2020-11-17 |
| CVE-2005-3947 EXP | Directory traversal vulnerability in index.php in PHP Upload Center allows remote attackers to read arbitrary files via "../" sequences in the filenam… | Patch early | 5.0 medium | 3.1% | 2005-12-01 |
| CVE-2004-2121 EXP | Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files… | Patch early | 5.0 medium | 3.1% | 2004-12-31 |
| CVE-2008-1862 EXP | ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which allows remote attackers to bypas… | Patch early | 6.8 medium | 3.1% | 2008-04-17 |
| CVE-2006-4669 EXP | PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals is enabled, allows remote attac… | Patch early | 5.1 medium | 3.1% | 2006-09-09 |
| CVE-2006-5427 EXP | PHP remote file inclusion vulnerability in plugins/main.php in Php AMX 0.9.0, when register_globals is enabled or magic_quotes_gpc is disabled, allows… | Patch early | 5.1 medium | 3.1% | 2006-10-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt