CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,893 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
207,498 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-20204 EXP | The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginning and a crafted SVG element. | Patch early | 5.4 medium | 3.4% | 2020-01-02 |
| CVE-2004-1539 EXP | Halo: Combat Evolved 1.05 and earlier allows remote game servers to cause a denial of service (client crash) via a long value in a game server reply,… | Patch early | 5.0 medium | 3.4% | 2004-12-31 |
| CVE-2008-6612 EXP | Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary code by uploading a fil… | Patch early | 6.8 medium | 3.4% | 2009-04-06 |
| CVE-2009-4817 EXP | Unrestricted file upload vulnerability in Element-IT Ultimate Uploader 1.3 allows remote attackers to execute arbitrary code by uploading a file with… | Patch early | 6.8 medium | 3.4% | 2010-04-27 |
| CVE-2010-0279 EXP | Unrestricted file upload vulnerability in upload.php in BTS-GI Read excel 1.1 allows remote attackers to execute arbitrary code by uploading a file wi… | Patch early | 6.8 medium | 3.4% | 2010-01-13 |
| CVE-2010-2144 EXP | Cross-site scripting (XSS) vulnerability in signinform.php in Zeeways eBay Clone Auction Script allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 3.4% | 2010-06-03 |
| CVE-2006-6855 EXP | AIDeX Mini-WebServer 1.1 early release 3 allows remote attackers to cause a denial of service (daemon crash) via a flood of HTTP GET requests, possibl… | Patch early | 5.0 medium | 3.4% | 2006-12-31 |
| CVE-2018-10110 EXP | D-Link DIR-615 T1 devices allow XSS via the Add User feature. | Patch early | 4.8 medium | 3.4% | 2018-04-18 |
| CVE-2015-3986 EXP | Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin f… | Patch early | 4.3 medium | 3.4% | 2015-05-14 |
| CVE-2008-6590 EXP | Multiple directory traversal vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allow remote att… | Patch early | 5.0 medium | 3.4% | 2009-04-03 |
| CVE-2009-4699 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SkaDate Dating allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO… | Patch early | 4.3 medium | 3.4% | 2010-03-15 |
| CVE-2006-2405 EXP | Directory traversal vulnerability in unb_lib/abbc.conf.php in Unclassified NewsBoard (UNB) 1.6.1 patch 1 and earlier, when register_globals is enabled… | Patch early | 6.8 medium | 3.4% | 2006-05-16 |
| CVE-2005-4194 EXP | Buffer overflow in MediaServerList.exe in Sights 'n Sounds Streaming Media Server 2.0.3.a allows remote attackers to cause a denial of service (applic… | Patch early | 5.0 medium | 3.4% | 2005-12-13 |
| CVE-2003-1456 EXP | Album.pl 6.1 allows remote attackers to execute arbitrary commands, when an alternative configuration file is used, via unknown attack vectors. | Patch early | 5.0 medium | 3.4% | 2003-12-31 |
| CVE-1999-0470 EXP | A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted. | Patch early | 5.0 medium | 3.4% | 1999-04-09 |
| CVE-2006-6751 EXP | Format string vulnerability in XM Easy Personal FTP Server 5.2.1 allows remote attackers to cause a denial of service (application crash) via format s… | Patch early | 5.0 medium | 3.4% | 2006-12-27 |
| CVE-2009-1561 EXP | Cross-site request forgery (CSRF) vulnerability in administration.cgi on the Cisco Linksys WRT54GC router with firmware 1.05.7 allows remote attackers… | Patch early | 6.8 medium | 3.4% | 2009-05-06 |
| CVE-2001-0593 EXP | Anaconda Partners Clipper 3.3 and earlier allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the template parameter. | Patch early | 5.0 medium | 3.4% | 2001-08-22 |
| CVE-2002-1852 EXP | Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) a param… | Patch early | 4.3 medium | 3.4% | 2002-12-31 |
| CVE-2005-1201 EXP | Multiple directory traversal vulnerabilities in AZ Bulletin board (AZbb) before 1.0.08 allow (1) remote authenticated users with administrative privil… | Patch early | 6.4 medium | 3.4% | 2005-05-02 |
| CVE-2004-2360 EXP | Targem Battle Mages 1.0 allows remote attackers to cause a denial of service (infinite loop) via a UDP packet with incomplete data, which causes the s… | Patch early | 5.0 medium | 3.4% | 2004-12-31 |
| CVE-2025-8730 EXP | A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functionali… | Patch early | 9.8 critical | 3.4% | 2025-08-08 |
| CVE-2007-4366 EXP | WengoPhone 2.1 allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Content-Type header. | Patch early | 5.0 medium | 3.4% | 2007-08-15 |
| CVE-2014-5023 EXP | Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in… | Patch early | 6.8 medium | 3.4% | 2014-07-22 |
| CVE-2006-5636 EXP | PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote attackers to execute arbitrary P… | Patch early | 5.1 medium | 3.4% | 2006-11-01 |
| CVE-2006-5727 EXP | PHP remote file inclusion vulnerability in admin/controls/cart.php in sazcart 1.5 allows remote attackers to execute arbitrary PHP code via the (1) _s… | Patch early | 5.1 medium | 3.4% | 2006-11-06 |
| CVE-2004-2675 EXP | ArGoSoft FTP Server before 1.4.1.6 allows remote authenticated users to cause a denial of service (crash) via a SITE PASS command with a long password… | Patch early | 6.8 medium | 3.4% | 2004-12-31 |
| CVE-2008-5566 EXP | Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote attackers to inject arbitrary w… | Patch early | 4.3 medium | 3.4% | 2008-12-15 |
| CVE-2010-2032 EXP | Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possib… | Patch early | 4.3 medium | 3.4% | 2010-05-24 |
| CVE-2010-2130 EXP | Cross-site scripting (XSS) vulnerability in wflogin.jsp in Aris Global ARISg 5.0 allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 3.4% | 2010-06-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt