CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,999 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
207,510 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-0786 EXP | iCon administrative web server for Critical Path inJoin Directory Server 4.0 allows authenticated inJoin administrators to read arbitrary files by spe… | Patch early | 5.0 medium | 3.2% | 2002-08-12 |
| CVE-2015-2789 EXP | Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.1 through 7.0.6.1126 allows lo… | Patch early | 4.4 medium | 3.2% | 2015-03-30 |
| CVE-2020-18724 EXP | Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to exe… | Patch early | 5.4 medium | 3.2% | 2021-02-03 |
| CVE-2005-1440 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (… | Patch early | 6.8 medium | 3.2% | 2005-05-03 |
| CVE-2006-5546 EXP | PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.3.0 through 1.4.1 allows remote… | Patch early | 5.1 medium | 3.2% | 2006-10-26 |
| CVE-2020-25270 EXP | PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City. | Patch early | 5.4 medium | 3.2% | 2020-10-08 |
| CVE-2009-1912 EXP | Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary loc… | Patch early | 6.8 medium | 3.2% | 2009-06-04 |
| CVE-2006-4782 EXP | src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication and gain sensitive i… | Patch early | 5.4 medium | 3.2% | 2006-09-14 |
| CVE-2003-0310 EXP | Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script. | Patch early | 6.8 medium | 3.2% | 2003-06-16 |
| CVE-2007-3310 EXP | Cross-site scripting (XSS) vulnerability in arama.asp in TDizin allows remote attackers to inject arbitrary web script or HTML via the ara parameter.… | Patch early | 4.3 medium | 3.2% | 2007-06-21 |
| CVE-2006-3987 EXP | Multiple PHP remote file inclusion vulnerabilities in index.php in Knusperleicht FileManager 1.2 and earlier allow remote attackers to execute arbitra… | Patch early | 5.1 medium | 3.2% | 2006-08-05 |
| CVE-2006-3988 EXP | PHP remote file inclusion vulnerability in index.php in Knusperleicht newsReporter 1.1 and earlier allows remote attackers to execute arbitrary PHP co… | Patch early | 5.1 medium | 3.2% | 2006-08-05 |
| CVE-2006-4012 EXP | Multiple PHP remote file inclusion vulnerabilities in circeOS SaveWeb Portal 3.4 allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 5.1 medium | 3.2% | 2006-08-07 |
| CVE-2006-4488 EXP | PHP remote file inclusion vulnerability in modules/userstop/userstop.php in ExBB Italia 0.2 and earlier, when register_globals is enabled, allows remo… | Patch early | 5.1 medium | 3.2% | 2006-08-31 |
| CVE-2012-0407 EXP | Integer overflow in the DPA_Utilities library in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of se… | Patch early | 5.0 medium | 3.2% | 2012-04-20 |
| CVE-2007-5840 EXP | PHP remote file inclusion vulnerability in starnet/themes/c-sky/main.inc.php in Fred Stuurman SyndeoCMS 2.5.01 allows remote attackers to execute arbi… | Patch early | 6.8 medium | 3.2% | 2007-11-06 |
| CVE-2001-0097 EXP | The Web interface for Infinite Interchange 3.6.1 allows remote attackers to cause a denial of service (application crash) via a large POST request. | Patch early | 5.0 medium | 3.2% | 2001-02-12 |
| CVE-2001-0952 EXP | THQ Volition Red Faction Game allows remote attackers to cause a denial of service (hang) of a client or server via packets to UDP port 7755. | Patch early | 5.0 medium | 3.2% | 2001-12-07 |
| CVE-2002-0135 EXP | Netopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of connections to one of the ports (1… | Patch early | 5.0 medium | 3.2% | 2002-03-25 |
| CVE-2006-2866 EXP | PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 5.1 medium | 3.2% | 2006-06-06 |
| CVE-2012-1024 EXP | Directory traversal vulnerability in file in Enigma2 Webinterface 1.5rc1 and 1.5beta4 allows remote attackers to read arbitrary files via a .. (dot do… | Patch early | 5.0 medium | 3.2% | 2012-02-08 |
| CVE-2010-2334 EXP | Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote attacker… | Patch early | 5.0 medium | 3.2% | 2010-06-18 |
| CVE-2012-6644 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat pa… | Patch early | 4.3 medium | 3.2% | 2014-04-08 |
| CVE-2013-1775 EXP | sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions a… | Patch early | 6.9 medium | 3.2% | 2013-03-05 |
| CVE-2017-3898 EXP | A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allow… | Patch early | 5.9 medium | 3.2% | 2017-09-01 |
| CVE-2007-1240 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS 3.0.3 through 3.0.5 allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 3.2% | 2007-03-03 |
| CVE-2016-6283 EXP | Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 6.1 medium | 3.2% | 2017-01-18 |
| CVE-2002-0812 EXP | Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default SN… | Patch early | 6.4 medium | 3.2% | 2002-08-12 |
| CVE-2011-1099 EXP | Multiple directory traversal vulnerabilities in FocalMedia.Net Quick Polls before 1.0.2 allow remote attackers to (1) read arbitrary files via a .. (d… | Patch early | 5.8 medium | 3.2% | 2011-03-09 |
| CVE-2020-8777 EXP | Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT el… | Patch early | 5.4 medium | 3.2% | 2020-03-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt