CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,573 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
206,912 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-2182 EXP | Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP files via a t… | Patch early | 6.8 medium | 4.4% | 2007-04-24 |
| CVE-2018-7747 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow remote attackers to inject arbit… | Patch early | 4.8 medium | 4.4% | 2018-04-20 |
| CVE-2024-48841 EXP | Network access can be used to execute arbitrary code with elevated privileges. This issue affects FLXEON 9.3.4 and older. | Patch early | 10.0 critical | 4.4% | 2025-01-27 |
| CVE-2007-2437 EXP | The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to caus… | Patch early | 5.5 medium | 4.4% | 2007-05-02 |
| CVE-2015-1060 EXP | Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect users to arbitrary web sites a… | Patch early | 5.8 medium | 4.4% | 2015-01-16 |
| CVE-2005-3954 EXP | Cross-site scripting (XSS) vulnerability in blogBuddies 0.3 allows remote attackers to inject arbitrary web script or HTML via the u parameter to inde… | Patch early | 4.3 medium | 4.4% | 2005-12-01 |
| CVE-2015-8736 EXP | The mp2t_find_next_pcr function in wiretap/mp2t.c in the MP2T file parser in Wireshark 2.0.x before 2.0.1 does not reserve memory for a trailer, which… | Patch early | 5.5 medium | 4.4% | 2016-01-04 |
| CVE-2012-4771 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 4.4% | 2012-10-22 |
| CVE-2007-3569 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Oliver Library Management System allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 4.4% | 2007-07-05 |
| CVE-2012-4949 EXP | SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a query… | Patch early | 6.5 medium | 4.4% | 2012-11-14 |
| CVE-2012-4989 EXP | Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote attackers to inject arbitrary w… | Patch early | 4.3 medium | 4.4% | 2012-10-22 |
| CVE-2006-2451 EXP | The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of… | Patch early | 4.6 medium | 4.4% | 2006-07-07 |
| CVE-2005-3747 EXP | Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files… | Patch early | 5.0 medium | 4.4% | 2005-11-22 |
| CVE-2007-6110 EXP | Cross-site scripting (XSS) vulnerability in htsearch in htdig 3.2.0b6 allows remote attackers to inject arbitrary web script or HTML via the sort para… | Patch early | 4.3 medium | 4.4% | 2007-11-23 |
| CVE-2000-0698 EXP | Minicom 1.82.1 and earlier on some Linux systems allows local users to create arbitrary files owned by the uucp user via a symlink attack. | Patch early | 5.0 medium | 4.4% | 2000-10-20 |
| CVE-2006-4140 EXP | Directory traversal vulnerability in IPCheck Server Monitor before 5.3.3.639/640 allows remote attackers to read arbitrary files via modified .. (dot… | Patch early | 5.0 medium | 4.4% | 2006-08-14 |
| CVE-2007-5105 EXP | Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 and 2.0.1 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 4.4% | 2007-09-26 |
| CVE-2023-23162 EXP | Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php. | Patch early | 9.8 critical | 4.4% | 2023-02-10 |
| CVE-2023-23163 EXP | Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter. | Patch early | 9.8 critical | 4.4% | 2023-02-10 |
| CVE-2006-4923 EXP | Cross-site scripting (XSS) vulnerability in search.php in eSyndiCat Portal System allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 4.4% | 2006-09-21 |
| CVE-2020-15930 EXP | An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag. | Patch early | 6.1 medium | 4.4% | 2020-09-24 |
| CVE-2006-1995 EXP | Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via ".." sequences in the p paramet… | Patch early | 5.0 medium | 4.4% | 2006-04-25 |
| CVE-2007-4088 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) id,… | Patch early | 4.3 medium | 4.4% | 2007-07-30 |
| CVE-2013-6017 EXP | Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary web script or HTML via the bo… | Patch early | 4.3 medium | 4.4% | 2014-01-12 |
| CVE-2007-6495 EXP | inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1)… | Patch early | 6.5 medium | 4.4% | 2007-12-20 |
| CVE-2017-17591 EXP | Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter. | Patch early | 9.8 critical | 4.4% | 2017-12-13 |
| CVE-2007-5310 EXP | PHP remote file inclusion vulnerability in admin.wmtportfolio.php in the webmaster-tips.net wmtportfolio 1.0 (com_wmtportfolio) component for Joomla!… | Patch early | 6.8 medium | 4.4% | 2007-10-09 |
| CVE-2007-5390 EXP | PHP remote file inclusion vulnerability in index.php in PicoFlat CMS 0.4.14 and earlier allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 6.8 medium | 4.4% | 2007-10-12 |
| CVE-2006-6225 EXP | Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a URL in the _CONF[path] parame… | Patch early | 5.1 medium | 4.4% | 2006-12-02 |
| CVE-2004-1906 EXP | Mcafee FreeScan allows remote attackers to cause a denial of service and possibly arbitrary code via a long string in the ScanParam property of a COM… | Patch early | 5.0 medium | 4.4% | 2004-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt