CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,556 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
207,231 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-1973 EXP | DiGi Web Server allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request that contains a large number of / (slas… | Patch early | 5.0 medium | 3.8% | 2004-04-27 |
| CVE-2004-2029 EXP | The Util_DecodeHTTPAuth function in BNBT BitTorrent Tracker Beta 7.5 Release 2 and earlier allows remote attackers to cause a denial of service (crash… | Patch early | 5.0 medium | 3.8% | 2004-05-22 |
| CVE-2004-2035 EXP | MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of tra… | Patch early | 5.0 medium | 3.8% | 2004-05-26 |
| CVE-2007-4442 EXP | Stack-based buffer overflow in the logging function in the Unreal engine, possibly 2003 and 2004, as used in the internal web server, allows remote at… | Patch early | 5.0 medium | 3.8% | 2007-08-21 |
| CVE-2006-1219 EXP | Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include arbitrary PHP files via ".."… | Patch early | 5.0 medium | 3.8% | 2006-03-14 |
| CVE-2012-4867 EXP | Directory traversal vulnerability in modules/com_vtiger_workflow/sortfieldsjson.php in vtiger CRM 5.1.0 allows remote attackers to read arbitrary file… | Patch early | 5.0 medium | 3.8% | 2012-09-06 |
| CVE-2006-3396 EXP | PHP remote file inclusion vulnerability in galleria.html.php in Galleria Mambo Module 1.0 and earlier for Mambo allows remote attackers to execute arb… | Patch early | 6.8 medium | 3.8% | 2006-07-06 |
| CVE-2018-11339 EXP | An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment. | Patch early | 6.1 medium | 3.8% | 2018-05-22 |
| CVE-2019-12460 EXP | Web Port 1.19.1 allows XSS via the /access/setup type parameter. | Patch early | 6.1 medium | 3.8% | 2019-05-30 |
| CVE-2023-33592 EXP | Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/con… | Patch early | 9.8 critical | 3.8% | 2023-06-28 |
| CVE-2006-2144 EXP | PHP remote file inclusion vulnerability in kopf.php in DMCounter 0.9.2-b allows remote attackers to execute arbitrary PHP code via a URL in the rootdi… | Patch early | 6.4 medium | 3.8% | 2006-05-02 |
| CVE-2007-5772 EXP | Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrators to inject arbitrary PHP cod… | Patch early | 6.0 medium | 3.8% | 2007-11-01 |
| CVE-2017-9123 EXP | The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (invalid memory read and… | Patch early | 6.5 medium | 3.8% | 2017-06-12 |
| CVE-2017-9124 EXP | The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NULL pointer dereference and app… | Patch early | 6.5 medium | 3.8% | 2017-06-12 |
| CVE-2017-9128 EXP | The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer ov… | Patch early | 6.5 medium | 3.8% | 2017-06-12 |
| CVE-2007-2048 EXP | Directory traversal vulnerability in /console in the Management Console in webMethods Glue 6.5.1 and earlier allows remote attackers to read arbitrary… | Patch early | 5.0 medium | 3.8% | 2007-04-16 |
| CVE-2006-1497 EXP | Directory traversal vulnerability in index.php in ViHor Design allows remote attackers to read arbitrary files via the page parameter. | Patch early | 5.0 medium | 3.8% | 2006-03-30 |
| CVE-2004-2617 EXP | Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the web root via a .. (dot dot) di… | Patch early | 5.0 medium | 3.8% | 2004-12-31 |
| CVE-2015-4064 EXP | SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users… | Patch early | 6.5 medium | 3.8% | 2015-05-27 |
| CVE-2007-4482 EXP | Cross-site scripting (XSS) vulnerability in index.php in the Pool 1.0.7 theme for WordPress allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 3.8% | 2007-08-22 |
| CVE-2022-4681 EXP | The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action a… | Patch early | 9.8 critical | 3.8% | 2023-02-06 |
| CVE-2007-4032 EXP | Buffer overflow in CrystalPlayer Pro 1.98 allows user-assisted remote attackers to execute arbitrary code via a long string in a .mls Playlist file. | Patch early | 6.8 medium | 3.8% | 2007-07-27 |
| CVE-2006-2141 EXP | Cross-site scripting (XSS) vulnerability in popup_image in Collaborative Portal Server (CPS) 3.4.0 and earlier allows remote attackers to inject arbit… | Patch early | 4.3 medium | 3.8% | 2006-05-02 |
| CVE-2006-2892 EXP | Cross-site scripting (XSS) vulnerability in index.php in GANTTy 1.0.3 allows remote attackers to inject arbitrary HTML and web script via the message… | Patch early | 4.3 medium | 3.8% | 2006-06-07 |
| CVE-2010-1131 EXP | JavaScriptCore.dll, as used in Apple Safari 4.0.5 on Windows XP SP3, allows remote attackers to cause a denial of service (application crash) via an H… | Patch early | 4.3 medium | 3.8% | 2010-03-27 |
| CVE-2010-0475 EXP | Cross-site scripting (XSS) vulnerability in esp/editUser.esp in the Palo Alto Networks firewall 3.0.x before 3.0.9 and 3.1.x before 3.1.1 allows remot… | Patch early | 4.3 medium | 3.8% | 2010-05-14 |
| CVE-2004-1395 EXP | The Lithtech engine, as used in (1) Contract Jack 1.1 and earlier, (2) No one lives forever 2 1.3 and earlier, (3) Tron 2.0 1.042 and earlier, (4) F.E… | Patch early | 5.0 medium | 3.8% | 2004-12-31 |
| CVE-2024-31777 EXP | File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoin… | Patch early | 9.8 critical | 3.8% | 2024-06-13 |
| CVE-2004-1887 EXP | Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a trailing %00 (null). | Patch early | 5.0 medium | 3.8% | 2004-12-31 |
| CVE-2024-23346 EXP | Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFa… | Patch early | 9.3 critical | 3.8% | 2024-02-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt