CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,146 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
208,173 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2000-0426 EXP | UltraBoard 1.6 and other versions allow remote attackers to cause a denial of service by referencing UltraBoard in the Session parameter, which causes… | Patch early | 5.0 medium | 2.5% | 2000-05-05 |
| CVE-2000-0463 EXP | BeOS 5.0 allows remote attackers to cause a denial of service via fragmented TCP packets. | Patch early | 5.0 medium | 2.5% | 2000-05-18 |
| CVE-2005-0666 EXP | Unknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC and VMA mirroring, allows local… | Patch early | 4.6 medium | 2.5% | 2005-05-02 |
| CVE-2005-2539 EXP | Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 2.5% | 2005-08-10 |
| CVE-2006-5894 EXP | Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and e… | Patch early | 6.8 medium | 2.5% | 2006-11-14 |
| CVE-2006-2828 EXP | Global variable overwrite vulnerability in PHP-Nuke allows remote attackers to conduct remote PHP file inclusion attacks via a modified phpbb_root_pat… | Patch early | 6.4 medium | 2.5% | 2006-06-05 |
| CVE-2004-2649 EXP | Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of characters (e.g. spaces coded as "… | Patch early | 5.8 medium | 2.5% | 2004-12-31 |
| CVE-2000-0476 EXP | xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force the window to be resized. | Patch early | 5.0 medium | 2.5% | 2000-06-01 |
| CVE-2009-1911 EXP | Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG)… | Patch early | 6.8 medium | 2.5% | 2009-06-04 |
| CVE-2021-42053 EXP | The Unicorn framework through 0.35.3 for Django allows XSS via component.name. | Patch early | 5.4 medium | 2.5% | 2021-10-07 |
| CVE-2014-0864 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Executer in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.… | Patch early | 6.8 medium | 2.5% | 2014-07-07 |
| CVE-2006-5294 EXP | Cross-site scripting (XSS) vulnerability in index.php in phplist before 2.10.3 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 2.5% | 2006-10-16 |
| CVE-2008-2864 EXP | eLineStudio Site Composer (ESC) 2.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) trigger.asp or (2)… | Patch early | 5.0 medium | 2.5% | 2008-06-25 |
| CVE-2010-2358 EXP | PHP remote file inclusion vulnerability in modules/catalog/upload_photo.php in Nakid CMS 0.5.2, when magic_quotes_gpc is disabled and register_globals… | Patch early | 5.1 medium | 2.5% | 2010-06-21 |
| CVE-2006-2675 EXP | PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 5.1 medium | 2.5% | 2006-05-30 |
| CVE-2004-1822 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 2.5% | 2004-03-15 |
| CVE-2012-5337 EXP | Multiple cross-site scripting (XSS) vulnerabilities in jforum.page in JForum 2.1.9 allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 2.5% | 2013-02-24 |
| CVE-2014-9146 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web script or HTML via the (1) view… | Patch early | 4.3 medium | 2.5% | 2015-04-14 |
| CVE-2019-6965 EXP | An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter. | Patch early | 6.1 medium | 2.5% | 2019-06-18 |
| CVE-2007-5816 EXP | dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to obtain sensitive author credentials by making a request with an editautho… | Patch early | 5.0 medium | 2.5% | 2007-11-05 |
| CVE-2011-0772 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow remote attackers to inject arbitr… | Patch early | 4.3 medium | 2.5% | 2011-02-04 |
| CVE-2009-2081 EXP | Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read ar… | Patch early | 4.3 medium | 2.5% | 2009-06-16 |
| CVE-2000-0669 EXP | Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data. | Patch early | 5.0 medium | 2.5% | 2000-07-11 |
| CVE-2003-1344 EXP | Trend Micro Virus Control System (TVCS) Log Collector allows remote attackers to obtain usernames, encrypted passwords, and other sensitive informatio… | Patch early | 5.0 medium | 2.5% | 2003-12-31 |
| CVE-2006-1196 EXP | Multiple cross-site scripting (XSS) vulnerabilities in QwikiWiki 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) from an… | Patch early | 4.3 medium | 2.5% | 2006-03-13 |
| CVE-2006-1233 EXP | Multiple cross-site scripting (XSS) vulnerabilities in WMNews allow remote attackers to inject arbitrary web script or HTML via the (1) ArtCat paramet… | Patch early | 4.3 medium | 2.5% | 2006-03-14 |
| CVE-2006-1430 EXP | Multiple cross-site scripting (XSS) vulnerabilities in CONTROLzx HMS (formerly DRZES) 3.3.4 and earlier allow remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 2.5% | 2006-03-28 |
| CVE-2008-0403 EXP | The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, which allows remote attackers to r… | Patch early | 5.5 medium | 2.5% | 2008-01-23 |
| CVE-2001-0270 EXP | Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet w… | Patch early | 5.0 medium | 2.5% | 2001-05-03 |
| CVE-2001-1525 EXP | Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.dat and poss… | Patch early | 5.0 medium | 2.5% | 2001-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt