CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,166 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
208,189 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-5114 EXP | Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject arb… | Patch early | 6.8 medium | 2.5% | 2006-10-03 |
| CVE-2007-3171 EXP | Uebimiau Webmail allows remote attackers to obtain sensitive information via a request to demo/pop3/error.php with an invalid value of the (1) smarty… | Patch early | 5.0 medium | 2.5% | 2007-06-11 |
| CVE-2010-2656 EXP | The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, stores sensitive… | Patch early | 5.0 medium | 2.5% | 2010-07-08 |
| CVE-2009-4820 EXP | Angelo-Emlak 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a databas… | Patch early | 5.0 medium | 2.5% | 2010-04-27 |
| CVE-2009-4825 EXP | 8pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a databa… | Patch early | 5.0 medium | 2.5% | 2010-04-27 |
| CVE-2006-4796 EXP | Cross-site scripting (XSS) vulnerability in forum.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 2.5% | 2006-09-14 |
| CVE-2008-6538 EXP | DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser. | Patch early | 5.0 medium | 2.5% | 2009-03-30 |
| CVE-2024-48852 EXP | Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access.… | Patch early | 9.4 critical | 2.5% | 2025-01-29 |
| CVE-2012-2940 EXP | MediaChance Real-DRAW PRO 5.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted (1) PNG, (2) WMF, (3) PSD, (4)… | Patch early | 4.3 medium | 2.5% | 2012-05-27 |
| CVE-2008-0135 EXP | Snitz Forums 2000 3.4.06 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers t… | Patch early | 5.0 medium | 2.5% | 2008-01-08 |
| CVE-2008-1181 EXP | Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a direct request for remediate.cg… | Patch early | 5.0 medium | 2.5% | 2008-03-06 |
| CVE-2007-5011 EXP | webbatch.exe in WebBatch allows remote attackers to obtain sensitive information via the dumpinputdata parameter. | Patch early | 5.0 medium | 2.5% | 2007-09-20 |
| CVE-2002-2174 EXP | The Telnet proxy of 602Pro LAN SUITE 2002 does not restrict the number of outstanding connections to the local host, which allows remote attackers to… | Patch early | 5.0 medium | 2.5% | 2002-12-31 |
| CVE-2005-1931 EXP | GoodTech SMTP Server 5.14 allows remote attackers to cause a denial of service (application crash) via a RCPT TO command with an invalid argument, as… | Patch early | 5.0 medium | 2.5% | 2005-07-05 |
| CVE-2016-2784 EXP | CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, mod… | Patch early | 4.7 medium | 2.5% | 2016-05-26 |
| CVE-2013-4692 EXP | Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS | Patch early | 6.1 medium | 2.5% | 2019-12-27 |
| CVE-2005-0978 EXP | Directory traversal vulnerability in the Object Push service in IVT BlueSoleil 1.4 allows remote attackers to upload arbitrary files via a .. (dot dot… | Patch early | 5.0 medium | 2.4% | 2005-05-02 |
| CVE-2007-3396 EXP | Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 2.4% | 2007-06-26 |
| CVE-2011-0505 EXP | Directory traversal vulnerability in system/system.php in Zwii 2.1.1, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote… | Patch early | 5.1 medium | 2.4% | 2011-01-20 |
| CVE-2007-6398 EXP | Flat PHP Board 1.2 and earlier allows remote attackers to bypass authentication and obtain limited access to an arbitrary user account via the fpb_use… | Patch early | 5.0 medium | 2.4% | 2007-12-17 |
| CVE-2008-5981 EXP | PacPoll 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via… | Patch early | 5.0 medium | 2.4% | 2009-01-27 |
| CVE-2009-1369 EXP | moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) page[] and (3) cat[] parameter… | Patch early | 5.0 medium | 2.4% | 2009-04-22 |
| CVE-2008-5936 EXP | front-end/edit.php in mini-pub 0.3 and earlier allows remote attackers to read files and obtain PHP source code via a filename in the sFileName parame… | Patch early | 5.0 medium | 2.4% | 2009-01-22 |
| CVE-2008-7118 EXP | WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain S… | Patch early | 5.0 medium | 2.4% | 2009-08-28 |
| CVE-2012-6048 EXP | Guitar Pro 6.1.1 r10791 allows remote attackers to cause a denial of service (crash) via a long string in a gpx file. | Patch early | 5.0 medium | 2.4% | 2012-11-27 |
| CVE-2010-0765 EXP | fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database v… | Patch early | 5.0 medium | 2.4% | 2010-03-02 |
| CVE-2010-0939 EXP | Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a d… | Patch early | 5.0 medium | 2.4% | 2010-03-08 |
| CVE-2008-1506 EXP | PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpin… | Patch early | 5.0 medium | 2.4% | 2008-03-25 |
| CVE-2008-1782 EXP | phpdemo/viewsource.php in Advanced Software Engineering ChartDirector 4.1 allows remote attackers to read sensitive files via the file parameter. | Patch early | 5.0 medium | 2.4% | 2008-04-15 |
| CVE-2010-0674 EXP | StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database… | Patch early | 5.0 medium | 2.4% | 2010-02-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt