CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,899 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
207,498 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-3546 EXP | Patrice Freydiere ImgSvr (aka ADA Image Server) allows remote attackers to cause a denial of service (daemon crash) via a long HTTP POST request. NOT… | Patch early | 5.0 medium | 3.4% | 2006-07-13 |
| CVE-2007-0986 EXP | PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remote attackers to execute arbitra… | Patch early | 5.1 medium | 3.4% | 2007-02-16 |
| CVE-2010-2856 EXP | Cross-site scripting (XSS) vulnerability in admin/currencies.php in osCSS 1.2.2, and probably earlier versions, allows remote attackers to inject arbi… | Patch early | 4.3 medium | 3.4% | 2010-07-25 |
| CVE-2005-1718 EXP | Buffer overflow in LS Games War Times 1.03 and earlier allows remote attackers to cause a denial of service (server crash) via a long nickname. | Patch early | 5.0 medium | 3.4% | 2005-05-24 |
| CVE-2018-7543 EXP | Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attac… | Patch early | 6.1 medium | 3.3% | 2018-03-26 |
| CVE-2017-2504 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. Th… | Patch early | 6.1 medium | 3.3% | 2017-05-22 |
| CVE-2021-43701 EXP | CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS[] and ord… | Patch early | 6.5 medium | 3.3% | 2022-03-29 |
| CVE-2006-5711 EXP | ECI Telecom B-FOCuS Wireless 802.11b/g ADSL2+ Router allows remote attackers to read arbitrary files via a certain HTTP request, as demonstrated by a… | Patch early | 5.0 medium | 3.3% | 2006-11-04 |
| CVE-2017-17999 EXP | SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter to… | Patch early | 9.8 critical | 3.3% | 2018-01-23 |
| CVE-2011-0167 EXP | The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Policy, and force the upload of arb… | Patch early | 4.3 medium | 3.3% | 2011-03-11 |
| CVE-2007-1843 EXP | PHP remote file inclusion vulnerability in gmapfactory/params.php in MapLab 2.2.1, when register_globals is enabled, allows remote attackers to execut… | Patch early | 6.8 medium | 3.3% | 2007-04-03 |
| CVE-2019-8391 EXP | qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter. | Patch early | 6.1 medium | 3.3% | 2019-05-14 |
| CVE-2004-2371 EXP | Multiple Red Storm web-based games, including Ghost Recon 1.4 and earlier, Desert Siege, and The Sum of all Fears 1.1.1.0 and earlier, do not properly… | Patch early | 5.0 medium | 3.3% | 2004-12-31 |
| CVE-2005-1667 EXP | DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request. | Patch early | 5.0 medium | 3.3% | 2005-05-18 |
| CVE-2006-6028 EXP | Directory traversal vulnerability in textview.php in Anton Vlasov DoSePa 1.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) sequ… | Patch early | 5.0 medium | 3.3% | 2006-11-21 |
| CVE-2007-2195 EXP | aMSN (aka Alvaro's Messenger) 0.96 and earlier allows remote attackers to cause a denial of service (application crash) by sending invalid data to TCP… | Patch early | 5.0 medium | 3.3% | 2007-04-24 |
| CVE-2007-6000 EXP | KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a denial of service (crash) via large HTTP cookie parameters. | Patch early | 5.0 medium | 3.3% | 2007-11-15 |
| CVE-2009-4451 EXP | Unrestricted file upload vulnerability in upper.php in kandalf upper 0.1 allows remote attackers to execute arbitrary code by uploading a file with an… | Patch early | 6.8 medium | 3.3% | 2009-12-29 |
| CVE-2009-4819 EXP | Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitrary code by uploading a file w… | Patch early | 6.8 medium | 3.3% | 2010-04-27 |
| CVE-2010-0390 EXP | Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mim… | Patch early | 6.8 medium | 3.3% | 2010-01-26 |
| CVE-2008-6528 EXP | NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to the URL, which accesses the alt… | Patch early | 5.0 medium | 3.3% | 2009-03-26 |
| CVE-2010-4863 EXP | Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3.3% | 2011-10-05 |
| CVE-2006-4458 EXP | Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers to include… | Patch early | 6.4 medium | 3.3% | 2006-08-31 |
| CVE-2008-6900 EXP | Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allows remote authenticated users… | Patch early | 6.5 medium | 3.3% | 2009-08-06 |
| CVE-2001-1347 EXP | Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using globa… | Patch early | 4.6 medium | 3.3% | 2001-05-24 |
| CVE-2015-1674 EXP | The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly validate an unspecified… | Patch early | 4.6 medium | 3.3% | 2015-05-13 |
| CVE-2010-3314 EXP | Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1… | Patch early | 4.3 medium | 3.3% | 2010-09-22 |
| CVE-2017-11831 EXP | Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,… | Patch early | 4.7 medium | 3.3% | 2017-11-15 |
| CVE-2009-4612 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inje… | Patch early | 4.3 medium | 3.3% | 2010-01-13 |
| CVE-2012-1464 EXP | Dashboard Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the installation path via a request with a trailing "?" c… | Patch early | 5.0 medium | 3.3% | 2012-03-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt