CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,585 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
170,402 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2003-1550 EXP | XOOPS 2.0, and possibly earlier versions, allows remote attackers to obtain sensitive information via an invalid xoopsOption parameter, which reveals… | Patch early | 5.0 medium | 2.9% | 2003-12-31 |
| CVE-2008-6126 EXP | Multiple directory traversal vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the… | Patch early | 5.0 medium | 2.9% | 2009-02-13 |
| CVE-2009-3828 EXP | The web interface for Everfocus EDR1600 DVR allows remote attackers to bypass authentication and access live cams via certain vectors. | Patch early | 5.0 medium | 2.9% | 2009-10-30 |
| CVE-2007-1392 EXP | Directory traversal vulnerability in down.php in netForo! 0.1g allows remote attackers to read arbitrary files via a .. (dot dot) in the file_to_downl… | Patch early | 5.0 medium | 2.9% | 2007-03-10 |
| CVE-1999-0700 EXP | Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file. | Patch early | 6.2 medium | 2.9% | 1999-07-29 |
| CVE-2013-6043 EXP | The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on whether the u… | Patch early | 5.0 medium | 2.9% | 2014-12-27 |
| CVE-2007-6055 EXP | Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Portal 4.1.0 and 4.1.1 allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 2.9% | 2007-11-20 |
| CVE-2009-1624 EXP | Directory traversal vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the show p… | Patch early | 5.0 medium | 2.9% | 2009-05-12 |
| CVE-2013-6797 EXP | Cross-site request forgery (CSRF) vulnerability in bluewrench-video-widget.php in the Blue Wrench Video Widget plugin before 2.0.0 for WordPress allow… | Patch early | 6.8 medium | 2.9% | 2013-11-19 |
| CVE-2010-2631 EXP | LibTIFF 3.9.0 ignores tags in certain situations during the first stage of TIFF file processing and does not properly handle this during the second st… | Patch early | 4.3 medium | 2.9% | 2010-07-06 |
| CVE-2017-2516 EXP | An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" component. It allows attackers to… | Patch early | 5.0 medium | 2.9% | 2017-05-22 |
| CVE-2006-2490 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other versions before 2.2.3.18 for M… | Patch early | 4.3 medium | 2.9% | 2006-05-19 |
| CVE-2008-5335 EXP | SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows remote attackers to execute ar… | Patch early | 6.8 medium | 2.9% | 2008-12-05 |
| CVE-2007-3459 EXP | A certain ActiveX control in Avaxswf.dll 1.0.0.1 in Civitech Avax Vector 1.3 allows remote attackers to create or overwrite arbitrary files via a full… | Patch early | 6.4 medium | 2.9% | 2007-06-27 |
| CVE-2006-2002 EXP | PHP remote file inclusion vulnerability in stats.php in MyGamingLadder 7.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir[… | Patch early | 5.0 medium | 2.9% | 2006-04-25 |
| CVE-2009-1615 EXP | Unrestricted file upload vulnerability in Leap CMS 0.1.4 allows remote attackers to execute arbitrary code by uploading a file with an executable exte… | Patch early | 6.8 medium | 2.9% | 2009-05-11 |
| CVE-2007-0118 EXP | Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an absolute pathname in the file pa… | Patch early | 4.3 medium | 2.9% | 2007-01-09 |
| CVE-2008-1537 EXP | Directory traversal vulnerability in pb_inc/admincenter/index.php in PowerScripts PowerBook 1.21 allows remote attackers to include and execute arbitr… | Patch early | 6.8 medium | 2.9% | 2008-03-28 |
| CVE-2007-3633 EXP | Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to creat… | Patch early | 6.4 medium | 2.9% | 2007-07-10 |
| CVE-2007-6133 EXP | PHP remote file inclusion vulnerability in admin/kfm/initialise.php in DevMass Shopping Cart 1.0 and earlier allows remote attackers to execute arbitr… | Patch early | 5.8 medium | 2.9% | 2007-11-27 |
| CVE-2008-1478 EXP | Home FTP Server 1.4.5.89 allows remote attackers to cause a denial of service (crash) by opening a FTP passive mode connection, then closing the origi… | Patch early | 5.0 medium | 2.9% | 2008-03-24 |
| CVE-2009-0828 EXP | QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain sensitive database informatio… | Patch early | 5.0 medium | 2.9% | 2009-03-05 |
| CVE-2007-6459 EXP | Anon Proxy Server 0.100, and probably 0.101, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the host parameter… | Patch early | 6.8 medium | 2.9% | 2007-12-20 |
| CVE-2006-5811 EXP | PHP remote file inclusion vulnerability in library/translation.inc.php in OpenEMR 2.8.1, with register_globals enabled, allows remote attackers to exe… | Patch early | 6.8 medium | 2.9% | 2006-11-08 |
| CVE-2014-8654 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway hardware 1.0 with f… | Patch early | 6.8 medium | 2.9% | 2014-11-06 |
| CVE-2018-15918 EXP | An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive… | Patch early | 5.4 medium | 2.9% | 2018-09-05 |
| CVE-2011-4813 EXP | Directory traversal vulnerability in clientarea.php in WHMCompleteSolution (WHMCS) 3.x.x allows remote attackers to read arbitrary files via an invali… | Patch early | 5.0 medium | 2.9% | 2011-12-14 |
| CVE-2003-1089 EXP | index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names, which reveals the path in a PH… | Patch early | 5.0 medium | 2.9% | 2003-12-31 |
| CVE-2003-1162 EXP | index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id, forum_id, and… | Patch early | 5.0 medium | 2.9% | 2003-12-31 |
| CVE-2004-2636 EXP | TinyWeb 1.9 allows remote attackers to read source code of scripts via "/./" in the URL. | Patch early | 5.0 medium | 2.9% | 2004-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt