CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,905 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
208,021 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-25679 EXP | The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. These issues impact at minimum… | Patch early | 5.4 medium | 2.7% | 2021-04-20 |
| CVE-2005-1402 EXP | Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows re… | Patch early | 5.0 medium | 2.7% | 2005-05-03 |
| CVE-2008-0297 EXP | PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its out… | Patch early | 5.0 medium | 2.7% | 2008-01-16 |
| CVE-2008-5105 EXP | KarjaSoft Sami FTP Server 2.0.x allows remote attackers to cause a denial of service (daemon crash or hang) via certain (1) APPE, (2) CWD, (3) DELE, (… | Patch early | 5.0 medium | 2.7% | 2008-11-17 |
| CVE-2008-6185 EXP | NoticeWare Email Server NG 5.1.2.2 allows remote attackers to cause a denial of service (crash) via multiple POP3 requests with a long PASS command. | Patch early | 5.0 medium | 2.7% | 2009-02-19 |
| CVE-2014-0984 EXP | The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation of a Route Permission Table en… | Patch early | 4.3 medium | 2.7% | 2014-04-17 |
| CVE-2007-6546 EXP | RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id. | Patch early | 6.4 medium | 2.7% | 2007-12-28 |
| CVE-2018-10309 EXP | The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS. | Patch early | 5.4 medium | 2.7% | 2018-04-24 |
| CVE-2000-0397 EXP | The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's ema… | Patch early | 5.0 medium | 2.7% | 2000-05-15 |
| CVE-2005-2021 EXP | Cross-site scripting (XSS) vulnerability in cPanel 9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the user paramet… | Patch early | 4.3 medium | 2.7% | 2005-06-20 |
| CVE-2005-2326 EXP | Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the yr paramet… | Patch early | 4.3 medium | 2.7% | 2005-07-19 |
| CVE-2002-1943 EXP | SafeTP 1.46, when network address translation (NAT) is being used, leaks the internal IP address of the FTP server in a response to a passive mode (PA… | Patch early | 5.0 medium | 2.7% | 2002-12-31 |
| CVE-2005-1620 EXP | Cross-site scripting (XSS) vulnerability in Skull-Splitter Guestbook 1.0, 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 2.7% | 2005-05-16 |
| CVE-2006-6340 EXP | keystone.exe in nVIDIA nView allows attackers to cause a denial of service via a long command line argument. NOTE: it is not clear whether this issue… | Patch early | 5.0 medium | 2.7% | 2006-12-07 |
| CVE-2007-1106 EXP | PHP remote file inclusion vulnerability in includes/functions_nomoketos_rules.php in the NoMoKeTos Rules 0.0.1 module for phpBB allows remote attacker… | Patch early | 6.8 medium | 2.7% | 2007-02-26 |
| CVE-2006-3361 EXP | PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary… | Patch early | 5.1 medium | 2.7% | 2006-07-06 |
| CVE-2009-1975 EXP | Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality, integrity, and… | Patch early | 6.8 medium | 2.7% | 2009-07-14 |
| CVE-2008-1557 EXP | BolinOS 4.6.1 allows remote attackers to obtain sensitive information via a direct request to system/actionspages/_b/contentFiles/gBphpInfo.php, which… | Patch early | 5.0 medium | 2.7% | 2008-03-31 |
| CVE-2008-5218 EXP | ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext p… | Patch early | 5.0 medium | 2.7% | 2008-11-25 |
| CVE-2008-5560 EXP | PostEcards stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database fi… | Patch early | 5.0 medium | 2.7% | 2008-12-15 |
| CVE-2007-3714 EXP | Directory traversal vulnerability in Ada Image Server (ImgSvr) 0.6.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the templat… | Patch early | 5.0 medium | 2.7% | 2007-07-11 |
| CVE-1999-0975 EXP | The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and m… | Patch early | 4.6 medium | 2.7% | 1999-12-10 |
| CVE-2006-1367 EXP | The Motorola PEBL U6 08.83.76R, the Motorola V600, and possibly the Motorola E398 and other Motorola P2K-based phones does not require pairing for a c… | Patch early | 6.8 medium | 2.7% | 2006-03-23 |
| CVE-2014-9099 EXP | Cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to hijack the authentication… | Patch early | 6.8 medium | 2.7% | 2014-11-26 |
| CVE-2007-4092 EXP | Directory traversal vulnerability in index.php in iFoto 1.0.1 and earlier allows remote attackers to list arbitrary directories, and possibly download… | Patch early | 5.0 medium | 2.7% | 2007-07-30 |
| CVE-2005-3514 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Forum script allow remote attackers to inject arbitrary web script or HTML via the for… | Patch early | 4.3 medium | 2.7% | 2005-11-06 |
| CVE-2006-0894 EXP | Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the html… | Patch early | 4.3 medium | 2.7% | 2006-02-25 |
| CVE-2003-1412 EXP | PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code… | Patch early | 6.8 medium | 2.7% | 2003-12-31 |
| CVE-2020-28092 EXP | PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&m=Task&a=m… | Patch early | 6.1 medium | 2.7% | 2020-11-17 |
| CVE-2023-26692 EXP | ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Management System (ZBBS) 4.14k is vuln… | Patch early | 6.1 medium | 2.7% | 2023-03-30 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt