CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,674 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
207,309 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-1669 EXP | Directory traversal vulnerability in index.php in phpMoneyBooks before 1.0.3 allows remote attackers to include and execute arbitrary local files via… | Patch early | 4.3 medium | 3.5% | 2014-11-17 |
| CVE-2013-4759 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Magnolia Form module 1.x before 1.4.7 and 2.x before 2.0.2 for Magnolia CMS allow remote at… | Patch early | 4.3 medium | 3.5% | 2013-08-09 |
| CVE-2010-0714 EXP | Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Con… | Patch early | 4.3 medium | 3.5% | 2010-02-26 |
| CVE-2004-1912 EXP | The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke… | Patch early | 5.0 medium | 3.5% | 2004-12-31 |
| CVE-2007-2268 EXP | Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a… | Patch early | 5.0 medium | 3.5% | 2007-04-25 |
| CVE-2007-2747 EXP | Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in t… | Patch early | 5.0 medium | 3.5% | 2007-05-17 |
| CVE-2006-7086 EXP | The (1) dlback.php and (2) dlback.cgi scripts in Hot Links allow remote attackers to obtain sensitive information and download the database via a dire… | Patch early | 4.3 medium | 3.5% | 2007-03-02 |
| CVE-2002-2055 EXP | Cross-site scripting (XSS) vulnerability in userlog.php in TeeKai Tracking Online 1.0 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 3.5% | 2002-12-31 |
| CVE-2004-2028 EXP | Cross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or HTML via the referer parameter… | Patch early | 4.3 medium | 3.5% | 2004-05-21 |
| CVE-2005-0881 EXP | Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 3.5% | 2005-03-23 |
| CVE-2006-2280 EXP | Directory traversal vulnerability in website.php in openEngine 1.8 Beta 2 and earlier allows remote attackers to list arbitrary directories and read a… | Patch early | 5.0 medium | 3.5% | 2006-05-10 |
| CVE-2007-3139 EXP | config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to access the application via a l… | Patch early | 6.8 medium | 3.5% | 2007-06-08 |
| CVE-2009-1447 EXP | Unrestricted file upload vulnerability in admin/editor/image.php in e-cart.biz Free Shopping Cart allows remote attackers to execute arbitrary code by… | Patch early | 6.8 medium | 3.5% | 2009-04-27 |
| CVE-2004-2170 EXP | Directory traversal vulnerability in sample_showcode.html in Caravan 2.00/03d and earlier allows remote attackers to read arbitrary files via the fnam… | Patch early | 5.0 medium | 3.5% | 2004-12-31 |
| CVE-2004-2464 EXP | Directory traversal vulnerability in ADA Image Server (ImgSvr) 0.4 allows remote attackers to read arbitrary files or list directories via hex-encoded… | Patch early | 5.0 medium | 3.5% | 2004-12-31 |
| CVE-1999-1084 EXP | The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which… | Patch early | 4.6 medium | 3.5% | 1999-12-31 |
| CVE-2010-4747 EXP | Cross-site scripting (XSS) vulnerability in wordpress-processing-embed/data/popup.php in the Processing Embed plugin 0.5 for WordPress allows remote a… | Patch early | 4.3 medium | 3.5% | 2011-03-01 |
| CVE-2006-6779 EXP | Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file that uses… | Patch early | 6.8 medium | 3.5% | 2006-12-28 |
| CVE-2011-3860 EXP | Cross-site scripting (XSS) vulnerability in the Cover WP theme before 1.6.6 for WordPress allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 3.5% | 2011-09-28 |
| CVE-2008-6750 EXP | Unrestricted file upload vulnerability in add.php in FlexPHPDirectory 0.0.1 allows remote attackers to execute arbitrary code by uploading a file with… | Patch early | 6.8 medium | 3.5% | 2009-04-24 |
| CVE-2009-2238 EXP | Unrestricted file upload vulnerability in includes/shared_scripts/wysiwyg_editor/assetmanager/assetmanager.asp in DMXReady Registration Manager 1.1 al… | Patch early | 6.8 medium | 3.5% | 2009-06-27 |
| CVE-2006-1151 EXP | Cross-site scripting vulnerability in index.php in M-Phorum 0.2 allows remote attackers to inject arbitrary web script or HTML via the go parameter. | Patch early | 5.0 medium | 3.5% | 2006-03-10 |
| CVE-2022-1163 EXP | Cross-site Scripting (XSS) - Stored in GitHub repository mineweb/minewebcms prior to next. | Patch early | 4.8 medium | 3.5% | 2022-03-30 |
| CVE-2005-3492 EXP | FlatFrag 0.3 and earlier allows remote attackers to cause a denial of service (crash) by sending an NT_CONN_OK command from a client that is not conne… | Patch early | 5.0 medium | 3.5% | 2005-11-04 |
| CVE-2005-1164 EXP | Yager 5.24 and earlier allows remote attackers to cause a denial of service (application hang) via a packet with a game header that provides less data… | Patch early | 5.0 medium | 3.5% | 2005-05-02 |
| CVE-2005-1741 EXP | Gearbox Software Halo: Combat Evolved 1.6 allows remote attackers to cause a denial of service (infinite loop) via malformed data. | Patch early | 5.0 medium | 3.5% | 2005-05-24 |
| CVE-2017-11356 EXP | The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to ob… | Patch early | 6.5 medium | 3.5% | 2017-08-02 |
| CVE-2013-7054 EXP | D-Link DIR-100 4.03B07: cli.cgi XSS | Patch early | 6.1 medium | 3.5% | 2020-02-04 |
| CVE-2005-2176 EXP | Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers… | Patch early | 6.4 medium | 3.5% | 2005-07-09 |
| CVE-2009-5087 EXP | Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote attackers to read arbitrary files… | Patch early | 5.0 medium | 3.5% | 2011-09-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt