CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,674 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
170,469 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-1975 EXP | Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality, integrity, and… | Patch early | 6.8 medium | 2.7% | 2009-07-14 |
| CVE-2008-5218 EXP | ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext p… | Patch early | 5.0 medium | 2.7% | 2008-11-25 |
| CVE-2008-5560 EXP | PostEcards stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database fi… | Patch early | 5.0 medium | 2.7% | 2008-12-15 |
| CVE-2008-1557 EXP | BolinOS 4.6.1 allows remote attackers to obtain sensitive information via a direct request to system/actionspages/_b/contentFiles/gBphpInfo.php, which… | Patch early | 5.0 medium | 2.7% | 2008-03-31 |
| CVE-2007-3714 EXP | Directory traversal vulnerability in Ada Image Server (ImgSvr) 0.6.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the templat… | Patch early | 5.0 medium | 2.7% | 2007-07-11 |
| CVE-1999-0975 EXP | The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and m… | Patch early | 4.6 medium | 2.7% | 1999-12-10 |
| CVE-2006-1367 EXP | The Motorola PEBL U6 08.83.76R, the Motorola V600, and possibly the Motorola E398 and other Motorola P2K-based phones does not require pairing for a c… | Patch early | 6.8 medium | 2.7% | 2006-03-23 |
| CVE-2014-9099 EXP | Cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to hijack the authentication… | Patch early | 6.8 medium | 2.7% | 2014-11-26 |
| CVE-2007-4092 EXP | Directory traversal vulnerability in index.php in iFoto 1.0.1 and earlier allows remote attackers to list arbitrary directories, and possibly download… | Patch early | 5.0 medium | 2.7% | 2007-07-30 |
| CVE-2005-3514 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Forum script allow remote attackers to inject arbitrary web script or HTML via the for… | Patch early | 4.3 medium | 2.7% | 2005-11-06 |
| CVE-2006-0894 EXP | Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the html… | Patch early | 4.3 medium | 2.7% | 2006-02-25 |
| CVE-2003-1412 EXP | PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code… | Patch early | 6.8 medium | 2.7% | 2003-12-31 |
| CVE-2023-26692 EXP | ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Management System (ZBBS) 4.14k is vuln… | Patch early | 6.1 medium | 2.7% | 2023-03-30 |
| CVE-2020-28092 EXP | PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&m=Task&a=m… | Patch early | 6.1 medium | 2.7% | 2020-11-17 |
| CVE-2004-2246 EXP | Cross-site scripting (XSS) vulnerability in Goollery before 0.04b allows remote attackers to inject arbitrary HTML or web script via the conversation_… | Patch early | 4.3 medium | 2.7% | 2004-12-31 |
| CVE-2007-2647 EXP | Static code injection vulnerability in admin/admin_configuration.php in Monalbum 0.8.7 allows remote authenticated users to inject arbitrary PHP code… | Patch early | 6.5 medium | 2.7% | 2007-05-14 |
| CVE-2014-3991 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1… | Patch early | 4.3 medium | 2.7% | 2014-07-11 |
| CVE-2008-2215 EXP | Multiple directory traversal vulnerabilities in Project-Based Calendaring System (PBCS) 0.7.1-1 allow remote attackers to read arbitrary files via a .… | Patch early | 5.0 medium | 2.7% | 2008-05-14 |
| CVE-2008-2350 EXP | Directory traversal vulnerability in highlight.php in bcoos 1.0.9 through 1.0.13 allows remote attackers to read arbitrary files via (1) .. (dot dot)… | Patch early | 5.0 medium | 2.7% | 2008-05-20 |
| CVE-2010-0799 EXP | Directory traversal vulnerability in misc/tell_a_friend/tell.php in phpunity.newsmanager allows remote attackers to read arbitrary files via a .. (dot… | Patch early | 5.0 medium | 2.7% | 2010-03-02 |
| CVE-2008-5861 EXP | Directory traversal vulnerability in source.php in FreeLyrics 1.0 allows remote attackers to read arbitrary files via directory traversal sequences in… | Patch early | 5.0 medium | 2.7% | 2009-01-06 |
| CVE-2018-9137 EXP | Open-AudIT before 2.2 has CSV Injection. | Patch early | 6.8 medium | 2.7% | 2018-04-19 |
| CVE-2010-2677 EXP | PHP remote file inclusion vulnerability in mw_plugin.php in Open Web Analytics (OWA) 1.2.3, when magic_quotes_gpc is disabled and register_globals is… | Patch early | 5.1 medium | 2.7% | 2010-07-08 |
| CVE-2006-4115 EXP | PHP remote file inclusion vulnerability in common.inc.php in PgMarket 2.2.3, when register_globals is enabled, allows remote attackers to execute arbi… | Patch early | 5.1 medium | 2.7% | 2006-08-14 |
| CVE-2008-4913 EXP | Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to delete arbitrary files via a .. (dot dot) in th… | Patch early | 5.0 medium | 2.7% | 2008-11-04 |
| CVE-2008-1856 EXP | plugins/maps/db_handler.php in LinPHA 1.3.3 and earlier does not require authentication for a settings action that modifies the configuration file, wh… | Patch early | 5.1 medium | 2.7% | 2008-04-16 |
| CVE-2008-3776 EXP | Directory traversal vulnerability in Fujitsu Web-Based Admin View 2.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | Patch early | 5.0 medium | 2.7% | 2008-08-25 |
| CVE-2010-2505 EXP | Soft SaschArt SasCAM Webcam Server 2.6.5, 2.7, and earlier allows remote attackers to cause a denial of service (crash) via a large number of requests… | Patch early | 5.0 medium | 2.7% | 2010-06-28 |
| CVE-2009-3366 EXP | Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) i… | Patch early | 5.0 medium | 2.7% | 2009-09-24 |
| CVE-2000-0904 EXP | Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, whic… | Patch early | 5.0 medium | 2.7% | 2000-12-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt