CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,599 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
170,406 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-2600 EXP | Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitra… | Patch early | 6.8 medium | 2.8% | 2007-05-11 |
| CVE-2010-0984 EXP | Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to downl… | Patch early | 5.0 medium | 2.8% | 2010-03-16 |
| CVE-2012-2977 EXP | The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an app… | Patch early | 5.0 medium | 2.8% | 2012-07-23 |
| CVE-2006-6138 EXP | Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary directories via an absolute pathname i… | Patch early | 5.0 medium | 2.8% | 2006-11-28 |
| CVE-2011-4341 EXP | Multiple SQL injection vulnerabilities in symphony/content/content.publish.php in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow re… | Patch early | 4.3 medium | 2.8% | 2012-02-12 |
| CVE-2006-1913 EXP | Cross-site scripting (XSS) vulnerability in jax_guestbook.php in Jax Guestbook 3.1, 3.31, and 3.50 allows remote attackers to inject arbitrary web scr… | Patch early | 6.8 medium | 2.8% | 2006-04-20 |
| CVE-2006-5770 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via (1) Bloks, (2) Ne… | Patch early | 6.8 medium | 2.8% | 2006-11-06 |
| CVE-2006-6599 EXP | maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters (";" semicolon) in the ann… | Patch early | 6.0 medium | 2.8% | 2006-12-15 |
| CVE-2021-30150 EXP | Composr 10.0.36 allows XSS in an XML script. | Patch early | 6.1 medium | 2.8% | 2021-04-06 |
| CVE-2018-6940 EXP | A /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction… | Patch early | 6.1 medium | 2.8% | 2018-02-20 |
| CVE-2007-6235 EXP | A certain ActiveX control in RealNetworks RealPlayer 11 allows remote attackers to cause a denial of service (application crash) via a malformed .au f… | Patch early | 5.0 medium | 2.8% | 2007-12-04 |
| CVE-2015-8037 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers… | Patch early | 4.3 medium | 2.8% | 2015-11-02 |
| CVE-2015-8038 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers… | Patch early | 4.3 medium | 2.8% | 2015-11-02 |
| CVE-2006-1161 EXP | Absolute path traversal vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote registered users to execute arbitrary code by uploading… | Patch early | 6.5 medium | 2.8% | 2006-03-12 |
| CVE-2008-0091 EXP | Directory traversal vulnerability in download2.php in AGENCY4NET WEBFTP 1 allows remote attackers to read and delete arbitrary files via a .. (dot dot… | Patch early | 6.4 medium | 2.8% | 2008-01-04 |
| CVE-2001-0418 EXP | content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL charact… | Patch early | 5.0 medium | 2.8% | 2001-07-02 |
| CVE-2007-3973 EXP | Multiple cross-site scripting (XSS) vulnerabilities in JBlog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id paramete… | Patch early | 6.8 medium | 2.8% | 2007-07-25 |
| CVE-2010-1267 EXP | Multiple directory traversal vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to read arbitrary files via directory traver… | Patch early | 5.0 medium | 2.8% | 2010-04-06 |
| CVE-2008-0431 EXP | Directory traversal vulnerability in administrator/download.php in IDMOS (aka Phoenix) 1.0 allows remote attackers to read arbitrary files via a .. (d… | Patch early | 5.0 medium | 2.8% | 2008-01-23 |
| CVE-2008-3205 EXP | Directory traversal vulnerability in index.php in Easy-Script Wysi Wiki Wyg 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in… | Patch early | 5.0 medium | 2.8% | 2008-07-17 |
| CVE-2010-1460 EXP | The IBM BladeCenter with Advanced Management Module (AMM) firmware before bpet50g does not properly perform interrupt sharing for USB and iSCSI, which… | Patch early | 5.0 medium | 2.8% | 2010-04-16 |
| CVE-2007-4325 EXP | PHP remote file inclusion vulnerability in index.php in Gaestebuch 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the config[r… | Patch early | 6.8 medium | 2.8% | 2007-08-14 |
| CVE-2006-2946 EXP | Dmx Forum 2.1a stores _includes/bd.inc under the web root with insufficient access control, which allows remote attackers to obtain database username… | Patch early | 5.0 medium | 2.8% | 2006-06-12 |
| CVE-2009-4700 EXP | Directory traversal vulnerability in index.php in SkaDate Dating allows remote attackers to read arbitrary files via a .. (dot dot) in the layout para… | Patch early | 5.0 medium | 2.8% | 2010-03-15 |
| CVE-2009-0640 EXP | Directory traversal vulnerability in the administrative web server in Swann DVR4-SecuraNet allows remote attackers to read arbitrary files via a .. (d… | Patch early | 5.0 medium | 2.8% | 2009-02-20 |
| CVE-2007-2184 EXP | Directory traversal vulnerability in imgsrv.php in jchit counter 1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the acc p… | Patch early | 5.0 medium | 2.8% | 2007-04-24 |
| CVE-2016-9316 EXP | Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Secu… | Patch early | 5.4 medium | 2.8% | 2017-02-21 |
| CVE-2007-1224 EXP | Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from the URL and specifies the dest… | Patch early | 5.0 medium | 2.8% | 2007-03-02 |
| CVE-2008-7015 EXP | Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a denial of s… | Patch early | 5.0 medium | 2.8% | 2009-08-19 |
| CVE-2013-5058 EXP | Integer overflow in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a… | Patch early | 6.9 medium | 2.8% | 2013-12-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt