CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,553 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
170,396 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-0497 EXP | PHP remote file inclusion vulnerability in upload/top.php in Upload-Service 1.0, when register_globals is enabled, allows remote attackers to execute… | Patch early | 6.8 medium | 3% | 2007-01-25 |
| CVE-2002-2357 EXP | MailEnable 1.5 015 through 1.5 018 allows remote attackers to cause a denial of service (crash) via a long USER string, possibly due to a buffer overf… | Patch early | 5.0 medium | 3% | 2002-12-31 |
| CVE-2018-8814 EXP | Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that mod… | Patch early | 6.5 medium | 3% | 2018-04-04 |
| CVE-2019-16197 EXP | In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, le… | Patch early | 6.1 medium | 3% | 2019-09-16 |
| CVE-2009-2163 EXP | Cross-site scripting (XSS) vulnerability in login/default.aspx in Sitecore CMS before 6.0.2 Update-1 090507 allows remote attackers to inject arbitrar… | Patch early | 4.3 medium | 3% | 2009-06-22 |
| CVE-2005-3812 EXP | freeFTPd 1.0.10 allows remote authenticated users to cause a denial of service (null dereference and crash) via a PORT command with missing arguments. | Patch early | 6.8 medium | 3% | 2005-11-26 |
| CVE-2011-4807 EXP | Directory traversal vulnerability in main.php in phpAlbum 0.4.1.16 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in t… | Patch early | 5.0 medium | 3% | 2011-12-14 |
| CVE-2010-1453 EXP | Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3% | 2010-05-07 |
| CVE-2008-5584 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (… | Patch early | 4.3 medium | 3% | 2008-12-15 |
| CVE-2008-4532 EXP | Cross-site scripting (XSS) vulnerability in index.php in MaxiScript Website Directory allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 3% | 2008-10-09 |
| CVE-2010-5052 EXP | Cross-site scripting (XSS) vulnerability in admin/components.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3% | 2011-11-23 |
| CVE-2008-1127 EXP | Format string vulnerability in the cryactio function in Crysis 1.1.1.5879 allows remote authenticated users to execute arbitrary code via format strin… | Patch early | 6.0 medium | 3% | 2008-03-03 |
| CVE-2001-0264 EXP | Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a… | Patch early | 5.0 medium | 3% | 2001-06-18 |
| CVE-2019-14430 EXP | plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection. | Patch early | 5.3 medium | 3% | 2019-08-20 |
| CVE-2014-1401 EXP | Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) searc… | Patch early | 6.5 medium | 3% | 2014-02-11 |
| CVE-2016-5845 EXP | SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to cause a denial of service (progr… | Patch early | 5.5 medium | 3% | 2016-08-13 |
| CVE-2006-2528 EXP | PHP remote file inclusion vulnerability in classified_right.php in phpBazar 2.1.0 and earlier allows remote attackers to execute arbitrary PHP code vi… | Patch early | 6.4 medium | 3% | 2006-05-22 |
| CVE-2008-3508 EXP | LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to bypass authentication and gain administrative access by setting the ad… | Patch early | 5.0 medium | 3% | 2008-08-07 |
| CVE-2008-6660 EXP | Unrestricted file upload vulnerability in bigdump.php in Alexey Ozerov BigDump 0.29b allows remote attackers to execute arbitrary code by uploading a… | Patch early | 6.8 medium | 3% | 2009-04-07 |
| CVE-2019-6146 EXP | It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Me… | Patch early | 6.1 medium | 3% | 2020-01-22 |
| CVE-2017-9767 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Quali CloudShell before 8 allow remote authenticated users to inject arbitrary web script or HT… | Patch early | 5.4 medium | 3% | 2017-08-18 |
| CVE-2005-0404 EXP | KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTM… | Patch early | 5.0 medium | 3% | 2005-05-02 |
| CVE-2006-6086 EXP | PHP remote file inclusion vulnerability in src/ark_inc.php in e-Ark 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_pea… | Patch early | 5.1 medium | 3% | 2006-11-24 |
| CVE-2007-5113 EXP | report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified q… | Patch early | 5.0 medium | 3% | 2007-09-26 |
| CVE-2002-1488 EXP | The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) via a PART message with (1) a mis… | Patch early | 5.0 medium | 3% | 2003-04-02 |
| CVE-2018-5754 EXP | Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allow… | Patch early | 5.4 medium | 3% | 2018-06-16 |
| CVE-2006-4464 EXP | The Nokia Browser, possibly Nokia Symbian 60 Browser 3rd edition, allows remote attackers to cause a denial of service (crash) via JavaScript that con… | Patch early | 5.0 medium | 3% | 2006-08-31 |
| CVE-2005-1202 EXP | Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 6.8 medium | 3% | 2005-05-02 |
| CVE-2017-0282 EXP | Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1… | Patch early | 5.0 medium | 3% | 2017-06-15 |
| CVE-2017-0284 EXP | Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1… | Patch early | 5.0 medium | 3% | 2017-06-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt