CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,011 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
170,625 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2000-0014 EXP | Denial of service in Savant web server via a null character in the requested URL. | Patch early | 5.0 medium | 2.3% | 1999-12-28 |
| CVE-2009-4750 EXP | PHP remote file inclusion vulnerability in home.php in Top Paidmailer allows remote attackers to execute arbitrary PHP code via a URL in the page para… | Patch early | 6.8 medium | 2.3% | 2010-03-26 |
| CVE-2006-0157 EXP | settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specif… | Patch early | 5.0 medium | 2.3% | 2006-01-10 |
| CVE-2014-4716 EXP | Cross-site request forgery (CSRF) vulnerability in Thomson TWG87OUIR allows remote attackers to hijack the authentication of unspecified victims for r… | Patch early | 6.8 medium | 2.3% | 2014-07-03 |
| CVE-2013-2754 EXP | Cross-site request forgery (CSRF) vulnerability in Umisoft UMI.CMS before 2.9 build 21905 allows remote attackers to hijack the authentication of admi… | Patch early | 6.8 medium | 2.3% | 2014-03-11 |
| CVE-2006-1768 EXP | Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary… | Patch early | 5.1 medium | 2.3% | 2006-04-13 |
| CVE-2017-14841 EXP | Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling. | Patch early | 6.5 medium | 2.3% | 2017-09-28 |
| CVE-2003-1139 EXP | Musicqueue 1.2.0 allows local users to overwrite arbitrary files by triggering a segmentation fault and using a symlink attack on the resulting musicq… | Patch early | 5.0 medium | 2.3% | 2003-10-27 |
| CVE-2005-2162 EXP | PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang param… | Patch early | 5.0 medium | 2.3% | 2005-07-06 |
| CVE-2007-6214 EXP | Directory traversal vulnerability in include/file_download.php in LearnLoop 2.0 beta7 allows remote attackers to read arbitrary files via a .. (dot do… | Patch early | 4.3 medium | 2.3% | 2007-12-04 |
| CVE-2007-1509 EXP | Directory traversal vulnerability in enkrypt.php in Sascha Schroeder krypt (aka Holtstraeter Rot 13) allows remote attackers to read arbitrary files v… | Patch early | 4.3 medium | 2.3% | 2007-03-20 |
| CVE-2007-3158 EXP | download_script.asp in ASP Folder Gallery allows remote attackers to read arbitrary files via a filename in the file parameter. | Patch early | 5.0 medium | 2.3% | 2007-06-11 |
| CVE-2008-0332 EXP | Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute arbitrary local files via dir… | Patch early | 5.0 medium | 2.3% | 2008-01-17 |
| CVE-2009-2130 EXP | Elvin 1.2.0 allows remote attackers to read the PHP source code of (1) login.ei, (2) jump_bug.ei, or (3) create_account.ei in inc/ via a direct reques… | Patch early | 5.0 medium | 2.3% | 2009-06-19 |
| CVE-2009-0498 EXP | Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to down… | Patch early | 5.0 medium | 2.3% | 2009-02-10 |
| CVE-2008-6012 EXP | Directory traversal vulnerability in index.php in Pritlog 0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrar… | Patch early | 4.3 medium | 2.3% | 2009-01-30 |
| CVE-2009-1354 EXP | Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | Patch early | 4.0 medium | 2.3% | 2009-04-21 |
| CVE-2018-8738 EXP | Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS. | Patch early | 6.1 medium | 2.3% | 2018-07-05 |
| CVE-2018-13849 EXP | edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequate XSS protection mechanism b… | Patch early | 6.1 medium | 2.3% | 2018-07-10 |
| CVE-2018-17832 EXP | XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter. | Patch early | 6.1 medium | 2.3% | 2018-10-01 |
| CVE-2018-18437 EXP | In AXIOS ITALIA Axioscloud Sissiweb Registro Elettronico 1.7.0, secret/relogoff.aspx has XSS via the Error_Desc parameter. | Patch early | 6.1 medium | 2.3% | 2018-10-23 |
| CVE-2018-19828 EXP | Artica Integria IMS 5.0.83 has XSS via the search_string parameter. | Patch early | 6.1 medium | 2.3% | 2018-12-17 |
| CVE-2006-6771 EXP | Multiple PHP remote file inclusion vulnerabilities in Irokez CMS 0.7.1 and earlier, when register_globals is enabled, allow remote attackers to execut… | Patch early | 6.8 medium | 2.3% | 2006-12-27 |
| CVE-2006-2363 EXP | SQL injection vulnerability in the weblinks option (weblinks.html.php) in Limbo CMS allows remote attackers to execute arbitrary SQL commands via the… | Patch early | 5.1 medium | 2.3% | 2006-05-15 |
| CVE-2008-2279 EXP | Freelance Auction Script 1.0 stores user passwords in plaintext in the tbl_users table, which allows attackers to gain privileges by reading the table… | Patch early | 5.0 medium | 2.3% | 2008-05-16 |
| CVE-2003-1468 EXP | The Web_Links module in PHP-Nuke 6.0 through 6.5 final allows remote attackers to obtain the full web server path via an invalid cid parameter that is… | Patch early | 4.3 medium | 2.3% | 2003-12-31 |
| CVE-2014-1459 EXP | SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administrators to execute arbitrary SQL… | Patch early | 6.5 medium | 2.3% | 2014-02-11 |
| CVE-2013-5316 EXP | Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for requests t… | Patch early | 6.8 medium | 2.3% | 2013-08-20 |
| CVE-2014-4155 EXP | Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the au… | Patch early | 6.8 medium | 2.3% | 2014-06-19 |
| CVE-2014-6409 EXP | Cross-site request forgery (CSRF) vulnerability in M/Monit 3.3.2 and earlier allows remote attackers to hijack the authentication of administrators fo… | Patch early | 6.8 medium | 2.3% | 2014-10-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt