CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,893 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
170,612 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-9979 EXP | On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the invali… | Patch early | 6.1 medium | 2.6% | 2017-08-28 |
| CVE-2002-1878 EXP | PHP remote file inclusion vulnerability in w-Agora 4.1.3 allows remote attackers to execute arbitrary PHP code via the inc_dir parameter. | Patch early | 5.0 medium | 2.6% | 2002-12-31 |
| CVE-2009-5103 EXP | Cross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP allows remote attackers to inject arbitrary web script or HTML via the email var… | Patch early | 4.3 medium | 2.6% | 2011-10-21 |
| CVE-2017-11823 EXP | The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass by the way it… | Patch early | 6.7 medium | 2.6% | 2017-10-13 |
| CVE-2023-3187 EXP | A vulnerability, which was classified as critical, has been found in PHPGurukul Teachers Record Management System 1.0. Affected by this issue is some… | Patch early | 6.3 medium | 2.6% | 2023-06-09 |
| CVE-2013-7247 EXP | cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows remote attackers to discover… | Patch early | 5.0 medium | 2.6% | 2014-01-26 |
| CVE-2017-6478 EXP | paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter). | Patch early | 6.1 medium | 2.6% | 2017-03-05 |
| CVE-2008-0843 EXP | StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a direct request to admin.asp. | Patch early | 6.4 medium | 2.6% | 2008-02-20 |
| CVE-2016-3652 EXP | Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow rem… | Patch early | 5.4 medium | 2.6% | 2016-06-30 |
| CVE-2003-1325 EXP | The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows remote authenticated users to c… | Patch early | 5.2 medium | 2.6% | 2003-12-31 |
| CVE-2008-3194 EXP | Multiple directory traversal vulnerabilities in data/inc/themes/predefined_variables.php in pluck 4.5.1 allow remote attackers to include and execute… | Patch early | 6.8 medium | 2.6% | 2008-07-16 |
| CVE-2012-6608 EXP | Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 2.6% | 2013-11-25 |
| CVE-2005-4502 EXP | Cross-site scripting (XSS) vulnerability in httprint v202, and possibly other versions before v301, allows remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 2.6% | 2005-12-22 |
| CVE-2015-6512 EXP | SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows remote attackers to execute ar… | Patch early | 5.0 medium | 2.5% | 2015-08-18 |
| CVE-2002-2336 EXP | Norton Personal Firewall 2002 4.0, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of… | Patch early | 4.3 medium | 2.5% | 2002-12-31 |
| CVE-2007-5017 EXP | Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.1.0.421 allows remote attacker… | Patch early | 5.0 medium | 2.5% | 2007-09-20 |
| CVE-2006-7114 EXP | P-News 2.0 stores db/user.txt under the web document root with insufficient access control, which allows remote attackers to obtain sensitive informat… | Patch early | 5.0 medium | 2.5% | 2007-03-06 |
| CVE-2005-0344 EXP | Directory traversal vulnerability in 602LAN SUITE 2004.0.04.1221 allows remote authenticated users to upload and execute arbitrary files via a .. (dot… | Patch early | 5.0 medium | 2.5% | 2005-05-02 |
| CVE-2004-0740 EXP | The HTTP server in Lexmark T522 and possibly other models allows remote attackers to cause a denial of service (server crash, reload, or hang) via an… | Patch early | 5.0 medium | 2.5% | 2004-07-27 |
| CVE-2004-0820 EXP | Winamp before 5.0.4 allows remote attackers to execute arbitrary script in the Local computer zone via script in HTML files that are referenced from X… | Patch early | 4.6 medium | 2.5% | 2004-08-28 |
| CVE-2008-2116 EXP | Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to read arbitrary local files via… | Patch early | 4.4 medium | 2.5% | 2008-05-08 |
| CVE-2008-7154 EXP | Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/class.conf_fw.php, (2) class.modu… | Patch early | 5.0 medium | 2.5% | 2009-09-02 |
| CVE-2000-0734 EXP | eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections. | Patch early | 5.0 medium | 2.5% | 2000-10-20 |
| CVE-2004-2038 EXP | Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a… | Patch early | 4.3 medium | 2.5% | 2004-05-29 |
| CVE-2006-1127 EXP | Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-F… | Patch early | 4.3 medium | 2.5% | 2006-03-09 |
| CVE-2012-5242 EXP | Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary… | Patch early | 6.8 medium | 2.5% | 2014-10-21 |
| CVE-2023-25440 EXP | Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/s… | Patch early | 5.4 medium | 2.5% | 2023-05-23 |
| CVE-2007-1898 EXP | formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and… | Patch early | 5.8 medium | 2.5% | 2007-05-16 |
| CVE-2011-1665 EXP | PHPBoost 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain backup SQL file… | Patch early | 5.0 medium | 2.5% | 2011-04-10 |
| CVE-2021-25791 EXP | Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated… | Patch early | 5.4 medium | 2.5% | 2021-07-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt