CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,660 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
207,266 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-33570 EXP | Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files… | Patch early | 5.4 medium | 3.6% | 2021-05-25 |
| CVE-2007-2964 EXP | The fsmsh.dll host module in F-Secure Policy Manager Server 7.00 and earlier allows remote attackers to cause a denial of service (application crash)… | Patch early | 5.0 medium | 3.6% | 2007-05-31 |
| CVE-2006-5319 EXP | Directory traversal vulnerability in redir.php in Foafgen 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the foaf parameter… | Patch early | 5.0 medium | 3.6% | 2006-10-17 |
| CVE-2003-1032 EXP | Pi3Web web server 2.0.2 Beta 1, when the Directory Index is configured to use the "Name" column and sort using the column title as a hyperlink, allows… | Patch early | 5.0 medium | 3.6% | 2004-02-17 |
| CVE-2008-6420 EXP | Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.php, (2) webadmin/download.php… | Patch early | 5.0 medium | 3.6% | 2009-03-06 |
| CVE-2012-1001 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Chyrp before 2.1.2 and before 2.5 Beta 2 allow remote attackers to inject arbitrary web script… | Patch early | 6.1 medium | 3.6% | 2019-11-21 |
| CVE-2006-6827 EXP | Flash8b.ocx in Macromedia Flash 8 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the Flash8b.Al… | Patch early | 5.0 medium | 3.6% | 2006-12-31 |
| CVE-2008-0631 EXP | Multiple ActiveX controls in MailBee.dll in MailBee Objects 5.5 allow remote attackers to (1) overwrite arbitrary files via the SaveToDisk method, or… | Patch early | 4.3 medium | 3.6% | 2008-02-06 |
| CVE-2012-4267 EXP | Cross-site scripting (XSS) vulnerability in user/register in Sockso 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 3.6% | 2012-08-13 |
| CVE-2013-2760 EXP | Buffer overflow in Groovy Media Player 3.2.0 allows remote attackers to execute arbitrary code via a long string in a .m3u file. | Patch early | 6.8 medium | 3.6% | 2013-04-16 |
| CVE-2006-5034 EXP | Directory traversal vulnerability in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to read arbitrary files via a ..… | Patch early | 5.0 medium | 3.6% | 2006-09-27 |
| CVE-2024-33559 EXP | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue af… | Patch early | 9.3 critical | 3.6% | 2024-04-29 |
| CVE-2014-4944 EXP | Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress allow remote authenticated users… | Patch early | 6.5 medium | 3.6% | 2014-07-14 |
| CVE-2007-2423 EXP | Cross-site scripting (XSS) vulnerability in index.php in MoinMoin 1.5.7 allows remote attackers to inject arbitrary web script or HTML via the do para… | Patch early | 5.8 medium | 3.6% | 2007-05-02 |
| CVE-2007-1110 EXP | Directory traversal vulnerability in data/showcode.php in ActiveCalendar 1.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in t… | Patch early | 5.0 medium | 3.6% | 2007-02-26 |
| CVE-2002-1033 EXP | Directory traversal vulnerability in none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via a "..:" sequence (dot-dot v… | Patch early | 5.0 medium | 3.6% | 2002-10-04 |
| CVE-2003-1450 EXP | BitchX 75p3 and 1.0c16 through 1.0c20cvs allows remote attackers to cause a denial of service (segmentation fault) via a malformed RPL_NAMREPLY numeri… | Patch early | 5.0 medium | 3.6% | 2003-12-31 |
| CVE-2001-0462 EXP | Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | Patch early | 5.0 medium | 3.6% | 2001-06-27 |
| CVE-2015-8261 EXP | The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows rem… | Patch early | 9.8 critical | 3.6% | 2016-01-08 |
| CVE-2018-0968 EXP | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel… | Patch early | 5.5 medium | 3.6% | 2018-04-12 |
| CVE-2008-4874 EXP | The web component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 has a back door "service" account with "service" as it… | Patch early | 5.0 medium | 3.5% | 2008-11-01 |
| CVE-2005-0369 EXP | Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a… | Patch early | 5.3 medium | 3.5% | 2005-05-02 |
| CVE-2006-4633 EXP | index.php in SoftBB 0.1, and possibly earlier, allows remote attackers to obtain the installation path via a null or invalid page[] parameter. | Patch early | 5.0 medium | 3.5% | 2006-09-08 |
| CVE-2012-0782 EXP | Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow re… | Patch early | 4.3 medium | 3.5% | 2012-01-30 |
| CVE-2009-4053 EXP | Multiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) create arbitrary directories via di… | Patch early | 6.5 medium | 3.5% | 2009-11-23 |
| CVE-2012-6276 EXP | Directory traversal vulnerability in the web-based management interface on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n a… | Patch early | 4.3 medium | 3.5% | 2013-01-26 |
| CVE-2007-6581 EXP | Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrary local files via a .. (dot do… | Patch early | 6.4 medium | 3.5% | 2007-12-28 |
| CVE-2002-1494 EXP | Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script by inserting the script after… | Patch early | 4.3 medium | 3.5% | 2003-04-02 |
| CVE-2002-1806 EXP | Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. | Patch early | 4.3 medium | 3.5% | 2002-12-31 |
| CVE-2002-1995 EXP | Cross-site scripting (XSS) vulnerability in phptonuke.php for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the filnavn… | Patch early | 4.3 medium | 3.5% | 2002-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt