CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,660 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
170,427 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-2769 EXP | Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 2.7% | 2005-09-02 |
| CVE-2012-2275 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in TestLink 1.9.3 and earlier allow remote attackers to hijack the authentication of users… | Patch early | 6.8 medium | 2.7% | 2012-09-15 |
| CVE-2015-2701 EXP | Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that chang… | Patch early | 6.8 medium | 2.7% | 2015-03-25 |
| CVE-2005-4485 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 2.7% | 2005-12-22 |
| CVE-2003-0736 EXP | Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the… | Patch early | 6.8 medium | 2.7% | 2003-10-20 |
| CVE-2007-4726 EXP | Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | Patch early | 5.0 medium | 2.7% | 2007-09-05 |
| CVE-2008-6870 EXP | Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) co… | Patch early | 5.0 medium | 2.7% | 2009-07-23 |
| CVE-2011-1838 EXP | Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 2.7% | 2011-05-20 |
| CVE-2005-2327 EXP | Cross-site scripting (XSS) vulnerability in e107 0.617 and earlier allows remote attackers to inject arbitrary web script or HTML via nested [url] BBC… | Patch early | 4.3 medium | 2.7% | 2005-07-20 |
| CVE-2007-4895 EXP | Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the f parameter. | Patch early | 5.0 medium | 2.7% | 2007-09-14 |
| CVE-2009-1519 EXP | Directory traversal vulnerability in index.php in Pecio CMS 1.1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the language p… | Patch early | 5.0 medium | 2.7% | 2009-05-04 |
| CVE-2009-3151 EXP | Directory traversal vulnerability in actions/downloadFile.php in Ultrize TimeSheet 1.2.2 allows remote attackers to read arbitrary files via a .. (dot… | Patch early | 5.0 medium | 2.7% | 2009-09-10 |
| CVE-2006-0731 EXP | WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolu… | Patch early | 4.0 medium | 2.7% | 2006-02-16 |
| CVE-2007-5739 EXP | Directory traversal vulnerability in component/flashupload/download.jsp in the FlashUpload component in Korean GHBoard allows remote attackers to read… | Patch early | 5.0 medium | 2.7% | 2007-10-30 |
| CVE-2009-4816 EXP | Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files via a .. (do… | Patch early | 5.0 medium | 2.7% | 2010-04-27 |
| CVE-2008-0489 EXP | Directory traversal vulnerability in install.php in Clansphere 2007.4.4 allows remote attackers to include and execute arbitrary local files via a ..… | Patch early | 5.0 medium | 2.7% | 2008-01-30 |
| CVE-2008-0559 EXP | Multiple directory traversal vulnerabilities in Nilson's Blogger 0.11 allow remote attackers to include and execute arbitrary local files via a .. (do… | Patch early | 5.0 medium | 2.7% | 2008-02-04 |
| CVE-2010-4858 EXP | Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the… | Patch early | 5.0 medium | 2.7% | 2011-10-05 |
| CVE-2006-2747 EXP | Directory traversal vulnerability in index.php in PhpMyDesktop|arcade 1.0 FINAL allows remote attackers to read arbitrary files or execute PHP code vi… | Patch early | 5.1 medium | 2.7% | 2006-06-01 |
| CVE-2008-6586 EXP | Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attackers to (1) hijack the authenti… | Patch early | 6.8 medium | 2.7% | 2009-04-03 |
| CVE-2009-1750 EXP | Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by uploading a file with an executab… | Patch early | 6.0 medium | 2.7% | 2009-05-22 |
| CVE-2004-2287 EXP | Directory traversal vulnerability in explorer.php in DSM Light Web File Browser 2.0 allows remote attackers to read arbitrary files via .. (dot dot) i… | Patch early | 5.0 medium | 2.7% | 2004-12-31 |
| CVE-2005-2140 EXP | Directory traversal vulnerability in default.asp for FSboard 2.0 allows remote attackers to read arbitrary files via ".." sequences in the filename pa… | Patch early | 5.0 medium | 2.7% | 2005-07-05 |
| CVE-2015-1517 EXP | SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to execute arbitrary SQL command… | Patch early | 6.0 medium | 2.7% | 2015-02-20 |
| CVE-2010-0967 EXP | Multiple directory traversal vulnerabilities in Geekhelps ADMP 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute… | Patch early | 5.1 medium | 2.7% | 2010-03-16 |
| CVE-2010-2850 EXP | Directory traversal vulnerability in productionnu2/fileuploader.php in nuBuilder 10.04.20, and possibly other versions before 10.07.12, allows remote… | Patch early | 6.8 medium | 2.7% | 2010-07-25 |
| CVE-2012-1110 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Etano 1.22 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1… | Patch early | 4.3 medium | 2.7% | 2012-09-06 |
| CVE-2005-1672 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Help Center Live allow remote attackers to inject arbitrary web script or HTML via the (1) find… | Patch early | 4.3 medium | 2.7% | 2005-05-19 |
| CVE-1999-1235 EXP | Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information… | Patch early | 4.6 medium | 2.7% | 1999-08-25 |
| CVE-2018-6130 EXP | Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds… | Patch early | 6.5 medium | 2.7% | 2019-06-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt