CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,556 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
170,398 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-12234 EXP | A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied input containing JavaScript is… | Patch early | 6.1 medium | 2.9% | 2018-09-06 |
| CVE-2006-2402 EXP | Buffer overflow in the changeRegistration function in servernet.cpp for Outgun 1.0.3 bot 2 and earlier allows remote attackers to change the registrat… | Patch early | 5.0 medium | 2.9% | 2006-05-16 |
| CVE-2015-7900 EXP | Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote attackers to obtain sensitive debugging information by enter… | Patch early | 4.3 medium | 2.9% | 2015-10-28 |
| CVE-2009-4154 EXP | Directory traversal vulnerability in includes/feedcreator.class.php in Elxis CMS allows remote attackers to read arbitrary files via a .. (dot dot) in… | Patch early | 5.0 medium | 2.9% | 2009-12-02 |
| CVE-2006-0875 EXP | Cross-site scripting vulnerability in ratefile.php in RunCMS 1.3a5 allows remote attackers to inject arbitrary web script or HTML via the lid paramete… | Patch early | 5.0 medium | 2.9% | 2006-02-24 |
| CVE-2010-4120 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the TAM console in IBM Tivoli Access Manager for e-business 6.1.0 before 6.1.0-TIV-TAM-FP0006 a… | Patch early | 4.3 medium | 2.9% | 2010-10-28 |
| CVE-2006-4004 EXP | Directory traversal vulnerability in index.php in vbPortal 3.0.2 through 3.6.0 Beta 1, when magic_quotes_gpc is disabled, allows remote attackers to i… | Patch early | 6.4 medium | 2.9% | 2006-08-07 |
| CVE-2006-5390 EXP | PHP remote file inclusion vulnerability in includes/functions_mod_user.php in the ACP User Registration (MMW) 1.00 module for phpBB allows remote atta… | Patch early | 6.8 medium | 2.9% | 2006-10-18 |
| CVE-2018-1513 EXP | IBM Sterling B2B Integrator Standard Edition 5.2.0 through 5.2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit… | Patch early | 5.4 medium | 2.9% | 2018-07-23 |
| CVE-2005-4371 EXP | Acidcat 2.1.13 and earlier stores the database under the web root with insufficient access control, which allows remote attackers to obtain sensitive… | Patch early | 5.0 medium | 2.9% | 2005-12-20 |
| CVE-2002-1837 EXP | The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary dir… | Patch early | 5.0 medium | 2.9% | 2002-12-31 |
| CVE-2004-0665 EXP | csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the web server i… | Patch early | 5.0 medium | 2.9% | 2004-08-06 |
| CVE-2004-1223 EXP | The Management Agent in F-Secure Policy Manager 5.11.2810 allows remote attackers to gain sensitive information, such as the absolute path for the web… | Patch early | 5.0 medium | 2.9% | 2005-01-10 |
| CVE-2004-1968 EXP | The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by modifying the… | Patch early | 5.0 medium | 2.9% | 2004-04-26 |
| CVE-2012-1221 EXP | Directory traversal vulnerability in the telnet server in RabidHamster R2/Extreme 1.65 and earlier allows remote attackers to read arbitrary files via… | Patch early | 5.0 medium | 2.9% | 2012-02-21 |
| CVE-2011-3501 EXP | Integer overflow in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to cause a denial of service (crash) via a negative or large Content-L… | Patch early | 5.0 medium | 2.9% | 2011-09-16 |
| CVE-2013-0126 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.19.36 allo… | Patch early | 6.8 medium | 2.9% | 2013-03-21 |
| CVE-2011-0545 EXP | Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to hijack… | Patch early | 6.8 medium | 2.9% | 2011-03-28 |
| CVE-2023-32751 EXP | Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are generated using the Amazon AWS SDK f… | Patch early | 5.4 medium | 2.9% | 2023-06-08 |
| CVE-2017-9130 EXP | The faacEncOpen function in libfaac/frame.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (invalid… | Patch early | 5.5 medium | 2.9% | 2017-06-21 |
| CVE-2002-2191 EXP | Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obtain potential sensitive inform… | Patch early | 5.0 medium | 2.9% | 2002-12-31 |
| CVE-2006-0312 EXP | create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1. | Patch early | 5.0 medium | 2.9% | 2006-01-19 |
| CVE-2006-5618 EXP | Directory traversal vulnerability in script/cat_for_aff.php in Netref 4 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in… | Patch early | 5.0 medium | 2.9% | 2006-10-31 |
| CVE-2006-6781 EXP | HLstats 1.20 through 1.34 allows remote attackers to obtain sensitive information via playinfo mode, with certain values of the player and playerdata[… | Patch early | 5.0 medium | 2.9% | 2006-12-28 |
| CVE-2006-5789 EXP | War FTP Daemon (WarFTPd) 1.82.00-RC11 allows remote authenticated users to cause a denial of service via a large number of "%s" format strings in (1)… | Patch early | 4.0 medium | 2.9% | 2006-11-07 |
| CVE-2008-0438 EXP | Cross-site scripting (XSS) vulnerability in the font rendering functionality in Novemberborn sIFR 2.0.2 allows remote attackers to inject arbitrary we… | Patch early | 4.3 medium | 2.9% | 2008-01-23 |
| CVE-2018-0975 EXP | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel… | Patch early | 5.5 medium | 2.9% | 2018-04-12 |
| CVE-2022-47880 EXP | An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify datab… | Patch early | 5.3 medium | 2.9% | 2023-05-12 |
| CVE-2005-3579 EXP | ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to access arbitrary local files via the querystring. | Patch early | 5.0 medium | 2.9% | 2005-11-16 |
| CVE-2011-4712 EXP | Directory traversal vulnerability in Oxide WebServer allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in an HTTP request. | Patch early | 5.0 medium | 2.9% | 2011-12-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt