CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,908 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
207,499 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2001-0122 EXP | Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote atta… | Patch early | 5.0 medium | 3.3% | 2001-03-13 |
| CVE-2001-0386 EXP | AnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory. | Patch early | 5.0 medium | 3.3% | 2001-07-02 |
| CVE-2002-0894 EXP | NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to cause a denial of service (crash) via (1) a request for a long .jsp file, or (2) a long UR… | Patch early | 5.0 medium | 3.3% | 2002-10-04 |
| CVE-2002-1071 EXP | ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the… | Patch early | 5.0 medium | 3.3% | 2002-10-04 |
| CVE-2026-24897 EXP | Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files… | Patch early | 10.0 critical | 3.3% | 2026-01-28 |
| CVE-2008-4087 EXP | Stack-based buffer overflow in Acoustica Beatcraft 1.02 Build 19 allows user-assisted attackers to cause a denial of service or execute arbitrary code… | Patch early | 6.8 medium | 3.3% | 2008-09-15 |
| CVE-2018-19749 EXP | DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field. | Patch early | 4.8 medium | 3.3% | 2018-11-29 |
| CVE-2018-19751 EXP | DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields. | Patch early | 4.8 medium | 3.3% | 2018-11-29 |
| CVE-2018-19752 EXP | DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar. | Patch early | 4.8 medium | 3.3% | 2018-11-29 |
| CVE-2018-19914 EXP | DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field. | Patch early | 4.8 medium | 3.3% | 2018-12-06 |
| CVE-2003-1219 EXP | Cross-site scripting (XSS) vulnerability in the tep_href_link function in html_output.php for osCommerce before 2.2-MS3 allows remote attackers to inj… | Patch early | 4.3 medium | 3.3% | 2003-12-31 |
| CVE-2006-3363 EXP | PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via a… | Patch early | 5.1 medium | 3.3% | 2006-07-06 |
| CVE-2005-4723 EXP | D-Link DI-524 Wireless Router, DI-624 Wireless Router, and DI-784 allow remote attackers to cause a denial of service (device reboot) via a series of… | Patch early | 5.0 medium | 3.3% | 2005-12-31 |
| CVE-2012-5967 EXP | SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote authenticated users to execut… | Patch early | 6.5 medium | 3.3% | 2012-12-19 |
| CVE-2007-4911 EXP | JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a long .mp3 URI to TCP port 8000.… | Patch early | 5.0 medium | 3.3% | 2007-09-17 |
| CVE-2009-3856 EXP | Cross-site scripting (XSS) vulnerability in the default URI in news/ in Twilight CMS before 4.1 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 3.3% | 2009-11-04 |
| CVE-2015-4665 EXP | Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 3.3% | 2015-08-13 |
| CVE-2012-3845 EXP | Buffer overflow in LAN Messenger 1.2.28 and earlier allows remote attackers to cause a denial of service (crash) via a long string in an initiation re… | Patch early | 5.0 medium | 3.3% | 2012-07-03 |
| CVE-2000-0569 EXP | Sybergen Sygate allows remote attackers to cause a denial of service by sending a malformed DNS UDP packet to its internal interface. | Patch early | 5.0 medium | 3.3% | 2000-06-30 |
| CVE-2000-1193 EXP | Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhausti… | Patch early | 5.0 medium | 3.3% | 2001-08-31 |
| CVE-2014-4014 EXP | The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows… | Patch early | 6.2 medium | 3.3% | 2014-06-23 |
| CVE-2020-9371 EXP | Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input… | Patch early | 4.8 medium | 3.3% | 2020-03-04 |
| CVE-2004-1953 EXP | phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error… | Patch early | 5.0 medium | 3.3% | 2004-12-31 |
| CVE-2005-1552 EXP | GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0, when set to create JPEG images, does not properly protect an image even when a password… | Patch early | 5.0 medium | 3.3% | 2005-05-14 |
| CVE-2007-1118 EXP | Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 6.8 medium | 3.3% | 2007-02-27 |
| CVE-2003-0523 EXP | Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the… | Patch early | 6.8 medium | 3.3% | 2003-08-18 |
| CVE-2007-3161 EXP | Buffer overflow in Ace-FTP Client 1.24a allows user-assisted, remote FTP servers to execute arbitrary code via a long response. | Patch early | 6.8 medium | 3.3% | 2007-06-11 |
| CVE-2008-6659 EXP | Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated users… | Patch early | 5.5 medium | 3.3% | 2009-04-07 |
| CVE-2014-4033 EXP | Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to inject arb… | Patch early | 4.3 medium | 3.3% | 2014-06-11 |
| CVE-2009-0290 EXP | Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files via a ..… | Patch early | 6.8 medium | 3.3% | 2009-01-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt