CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,999 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
170,624 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-5796 EXP | Cross-site scripting (XSS) vulnerability in the management console in Blue Coat ProxySG before 4.2.6.1, and 5.x before 5.2.2.5, allows remote attacker… | Patch early | 4.3 medium | 2.3% | 2007-11-03 |
| CVE-2009-4426 EXP | Multiple directory traversal vulnerabilities in Ignition 1.2, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitra… | Patch early | 6.8 medium | 2.3% | 2009-12-28 |
| CVE-2005-1951 EXP | Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web… | Patch early | 5.0 medium | 2.3% | 2005-06-16 |
| CVE-2014-9344 EXP | Cross-site request forgery (CSRF) vulnerability in Snowfox CMS before 1.0.10 allows remote attackers to hijack the authentication of administrators fo… | Patch early | 6.8 medium | 2.3% | 2014-12-08 |
| CVE-2009-0392 EXP | Directory traversal vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to read arbitrary files via a .. (d… | Patch early | 6.8 medium | 2.3% | 2009-02-03 |
| CVE-2009-4553 EXP | Stack-based buffer overflow in iRehearse allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other i… | Patch early | 5.0 medium | 2.3% | 2010-01-04 |
| CVE-2018-0832 EXP | The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Serv… | Patch early | 4.7 medium | 2.3% | 2018-02-15 |
| CVE-2018-0894 EXP | The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold… | Patch early | 4.7 medium | 2.3% | 2018-03-14 |
| CVE-2018-0897 EXP | The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold… | Patch early | 4.7 medium | 2.3% | 2018-03-14 |
| CVE-2008-1564 EXP | Directory traversal vulnerability in Dan Costin File Transfer before 1.2f allows remote attackers to read arbitrary files via a "..\" (dot dot backsla… | Patch early | 4.3 medium | 2.3% | 2008-03-31 |
| CVE-2013-3961 EXP | SQL injection vulnerability in edit_event.php in Simple PHP Agenda before 2.2.9 allows remote authenticated users to execute arbitrary SQL commands vi… | Patch early | 6.5 medium | 2.3% | 2014-03-11 |
| CVE-2011-3393 EXP | Multiple cross-site scripting (XSS) vulnerabilities in findagent.php in MYRE Real Estate Software allow remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 2.3% | 2011-09-15 |
| CVE-2019-10261 EXP | CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fields via a "DNS Functions" "Edit… | Patch early | 4.8 medium | 2.3% | 2019-04-03 |
| CVE-2007-2086 EXP | Multiple PHP remote file inclusion vulnerabilities in CNStats 2.9 allow remote attackers to execute arbitrary PHP code via a URL in the bj parameter t… | Patch early | 6.8 medium | 2.3% | 2007-04-18 |
| CVE-2010-4835 EXP | Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via d… | Patch early | 4.0 medium | 2.3% | 2011-09-14 |
| CVE-2007-5321 EXP | Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers to include arbitrary files via… | Patch early | 6.8 medium | 2.3% | 2007-10-09 |
| CVE-2002-1704 EXP | Zeroboard 4.1, when the "allow_url_fopen" and "register_globals" variables are enabled, allows remote attackers to execute arbitrary PHP code by modif… | Patch early | 5.0 medium | 2.3% | 2002-12-31 |
| CVE-2004-0528 EXP | Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to th… | Patch early | 5.0 medium | 2.3% | 2004-08-06 |
| CVE-2007-6270 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Absolute News Manager.NET 5.1 allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 2.3% | 2007-12-07 |
| CVE-2007-0371 EXP | A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a… | Patch early | 4.3 medium | 2.3% | 2007-01-19 |
| CVE-2006-6563 EXP | Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1.3.1rc1 allows local users to… | Patch early | 6.6 medium | 2.3% | 2006-12-15 |
| CVE-2006-5838 EXP | PHP remote file inclusion vulnerability in lib/class.Database.php in NewP News Publication System 1.0.0, when register_globals is enabled, allows remo… | Patch early | 5.1 medium | 2.3% | 2006-11-10 |
| CVE-2010-4798 EXP | Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbitrary local files via directory… | Patch early | 6.8 medium | 2.3% | 2011-04-27 |
| CVE-2009-2330 EXP | Cross-site scripting (XSS) vulnerability in admin/admin_menu.php in CMS Chainuk 1.2 and earlier allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 2.3% | 2009-07-05 |
| CVE-2007-3630 EXP | changePW.php in AV Tutorial Script (avtutorial) 1.0 does not require authentication or knowledge of an old password for password changes, which allows… | Patch early | 6.4 medium | 2.3% | 2007-07-10 |
| CVE-2009-1665 EXP | myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid parameter wit… | Patch early | 6.4 medium | 2.3% | 2009-05-18 |
| CVE-2008-6354 EXP | The Net Guys ASPired2poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download… | Patch early | 5.0 medium | 2.3% | 2009-03-02 |
| CVE-2008-6355 EXP | The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo… | Patch early | 5.0 medium | 2.3% | 2009-03-02 |
| CVE-2009-0571 EXP | admin.php in Ninja Designs Mailist 3.0 stores backup copies of maillist.php under the web root with insufficient access control, which allows remote a… | Patch early | 5.0 medium | 2.3% | 2009-02-13 |
| CVE-2009-0767 EXP | Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file contain… | Patch early | 5.0 medium | 2.3% | 2009-03-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt