CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,905 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
208,021 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-0559 EXP | Multiple directory traversal vulnerabilities in Nilson's Blogger 0.11 allow remote attackers to include and execute arbitrary local files via a .. (do… | Patch early | 5.0 medium | 2.7% | 2008-02-04 |
| CVE-2010-4858 EXP | Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the… | Patch early | 5.0 medium | 2.7% | 2011-10-05 |
| CVE-2006-2747 EXP | Directory traversal vulnerability in index.php in PhpMyDesktop|arcade 1.0 FINAL allows remote attackers to read arbitrary files or execute PHP code vi… | Patch early | 5.1 medium | 2.7% | 2006-06-01 |
| CVE-2008-6586 EXP | Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attackers to (1) hijack the authenti… | Patch early | 6.8 medium | 2.7% | 2009-04-03 |
| CVE-2009-1750 EXP | Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by uploading a file with an executab… | Patch early | 6.0 medium | 2.7% | 2009-05-22 |
| CVE-2004-2287 EXP | Directory traversal vulnerability in explorer.php in DSM Light Web File Browser 2.0 allows remote attackers to read arbitrary files via .. (dot dot) i… | Patch early | 5.0 medium | 2.7% | 2004-12-31 |
| CVE-2005-2140 EXP | Directory traversal vulnerability in default.asp for FSboard 2.0 allows remote attackers to read arbitrary files via ".." sequences in the filename pa… | Patch early | 5.0 medium | 2.7% | 2005-07-05 |
| CVE-2015-1517 EXP | SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to execute arbitrary SQL command… | Patch early | 6.0 medium | 2.7% | 2015-02-20 |
| CVE-2010-0967 EXP | Multiple directory traversal vulnerabilities in Geekhelps ADMP 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute… | Patch early | 5.1 medium | 2.7% | 2010-03-16 |
| CVE-2010-2850 EXP | Directory traversal vulnerability in productionnu2/fileuploader.php in nuBuilder 10.04.20, and possibly other versions before 10.07.12, allows remote… | Patch early | 6.8 medium | 2.7% | 2010-07-25 |
| CVE-2012-1110 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Etano 1.22 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1… | Patch early | 4.3 medium | 2.7% | 2012-09-06 |
| CVE-2005-1672 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Help Center Live allow remote attackers to inject arbitrary web script or HTML via the (1) find… | Patch early | 4.3 medium | 2.7% | 2005-05-19 |
| CVE-1999-1235 EXP | Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information… | Patch early | 4.6 medium | 2.7% | 1999-08-25 |
| CVE-2018-6130 EXP | Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds… | Patch early | 6.5 medium | 2.7% | 2019-06-27 |
| CVE-2012-0902 EXP | AirTies Air 4450 1.1.2.18 allows remote attackers to cause a denial of service (reboot) via a direct request to cgi-bin/loader. | Patch early | 5.0 medium | 2.7% | 2012-01-20 |
| CVE-2009-2151 EXP | Directory traversal vulnerability in index.php in AdaptWeb 0.9.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the newlang par… | Patch early | 5.0 medium | 2.7% | 2009-06-22 |
| CVE-2020-35416 EXP | Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with differen… | Patch early | 6.1 medium | 2.7% | 2020-12-15 |
| CVE-2005-3547 EXP | Cross-site scripting (XSS) vulnerability in Invision Power Board 2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) adsess… | Patch early | 4.3 medium | 2.7% | 2005-11-16 |
| CVE-2007-5221 EXP | PHP remote file inclusion vulnerability in mail/childwindow.inc.php in Poppawid 2.7 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 6.8 medium | 2.7% | 2007-10-05 |
| CVE-2014-3138 EXP | SQL injection vulnerability in Xerox DocuShare before 6.53 Patch 6 Hotfix 2, 6.6.1 Update 1 before Hotfix 24, and 6.6.1 Update 2 before Hotfix 3 allow… | Patch early | 6.5 medium | 2.7% | 2014-05-02 |
| CVE-2013-4727 EXP | DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive in… | Patch early | 5.0 medium | 2.7% | 2014-06-06 |
| CVE-2004-1788 EXP | ASP-Nuke 1.3 and earlier places user credentials under the web document root with insufficient access control, which allows remote attackers to obtain… | Patch early | 5.0 medium | 2.7% | 2004-12-31 |
| CVE-2011-5184 EXP | Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i 9.10 allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 2.7% | 2012-09-20 |
| CVE-2018-6582 EXP | SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHo… | Patch early | 9.8 critical | 2.7% | 2018-02-05 |
| CVE-2018-7180 EXP | SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2012-6038 EXP | admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which allows remo… | Patch early | 6.5 medium | 2.7% | 2012-11-26 |
| CVE-2015-7252 EXP | Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to… | Patch early | 6.1 medium | 2.7% | 2015-12-30 |
| CVE-2007-0353 EXP | Cross-site scripting (XSS) vulnerability in (1) index.php and (2) login.php in myBloggie 2.1.5 allows remote attackers to inject arbitrary web script… | Patch early | 6.8 medium | 2.7% | 2007-01-19 |
| CVE-2018-6129 EXP | Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory acce… | Patch early | 6.5 medium | 2.7% | 2019-06-27 |
| CVE-2009-2159 EXP | backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and download… | Patch early | 6.4 medium | 2.7% | 2009-06-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt