CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,169 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
208,192 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-4640 EXP | Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload and execute arbitrary PHP files… | Patch early | 6.4 medium | 2.4% | 2007-08-31 |
| CVE-2012-1308 EXP | Cross-site request forgery (CSRF) vulnerability in redpass.cgi in D-Link DSL-2640B Firmware EU_4.00 allows remote attackers to hijack the authenticati… | Patch early | 6.8 medium | 2.4% | 2012-10-08 |
| CVE-2004-0615 EXP | Cross-site scripting (XSS) vulnerability in D-Link DI-614+ SOHO router running firmware 2.30, and DI-704 SOHO router running firmware 2.60B2, and DI-6… | Patch early | 5.1 medium | 2.4% | 2004-12-06 |
| CVE-2003-1512 EXP | Buffer overflow in mIRC 6.1 and 6.11 allows remote attackers to cause a denial of service (crash) via a long DCC SEND request. | Patch early | 5.0 medium | 2.4% | 2003-12-31 |
| CVE-2007-2574 EXP | Directory traversal vulnerability in index.php in Archangel Weblog 0.90.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the i… | Patch early | 5.0 medium | 2.4% | 2007-05-09 |
| CVE-2008-6765 EXP | ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a modified cart_name parameter. | Patch early | 5.0 medium | 2.4% | 2009-04-28 |
| CVE-2009-2332 EXP | CMS Chainuk 1.2 and earlier allows remote attackers to obtain sensitive information via (1) a crafted id parameter to index.php or (2) a nonexistent f… | Patch early | 5.0 medium | 2.4% | 2009-07-05 |
| CVE-2009-4466 EXP | DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a crafted page parameter to misc.php, which reveals the installation path in… | Patch early | 5.0 medium | 2.4% | 2009-12-30 |
| CVE-2015-6944 EXP | Cross-site request forgery (CSRF) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to hijack the authentication of users for req… | Patch early | 6.8 medium | 2.4% | 2015-09-15 |
| CVE-2018-10366 EXP | An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the name field. | Patch early | 6.1 medium | 2.4% | 2018-04-25 |
| CVE-2016-1596 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary… | Patch early | 5.4 medium | 2.4% | 2016-04-22 |
| CVE-2009-2161 EXP | Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remot… | Patch early | 5.1 medium | 2.4% | 2009-06-22 |
| CVE-1999-0393 EXP | Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers. | Patch early | 5.0 medium | 2.4% | 1999-01-01 |
| CVE-1999-0925 EXP | UnityMail allows remote attackers to conduct a denial of service via a large number of MIME headers. | Patch early | 5.0 medium | 2.4% | 1999-09-03 |
| CVE-2014-9101 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall 1.7.0 (build 7907 and 7906) and SkaDate Lite 2.0 (build 7651) allow remote attack… | Patch early | 6.8 medium | 2.4% | 2014-11-26 |
| CVE-2009-0769 EXP | QIP 2005 build 8082 allows remote attackers to cause a denial of service (CPU consumption and application hang) via a crafted Rich Text Format (RTF) I… | Patch early | 4.3 medium | 2.4% | 2009-03-06 |
| CVE-2009-1825 EXP | modules/admuser.php in myColex 1.4.2 does not require administrative authentication, which allows remote authenticated users to list user accounts via… | Patch early | 4.0 medium | 2.4% | 2009-05-29 |
| CVE-2008-7032 EXP | Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote attackers to hij… | Patch early | 6.8 medium | 2.4% | 2009-08-24 |
| CVE-2007-0499 EXP | PHP remote file inclusion vulnerability in config.php in Sangwan Kim phpIndexPage 1.0.1 and earlier allows remote attackers to execute arbitrary PHP c… | Patch early | 6.8 medium | 2.4% | 2007-01-25 |
| CVE-2017-16807 EXP | A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exists when displaying a specially… | Patch early | 5.4 medium | 2.4% | 2017-11-13 |
| CVE-2008-2943 EXP | Double free vulnerability in IBM Tivoli Directory Server (TDS) 6.1.0.0 through 6.1.0.15 allows remote authenticated administrators to cause a denial o… | Patch early | 6.0 medium | 2.4% | 2008-06-30 |
| CVE-2006-0786 EXP | Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attackers to cond… | Patch early | 5.1 medium | 2.4% | 2006-02-19 |
| CVE-2006-4065 EXP | Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko SAPID Gallery 1.0 and earlier allow remote attackers to execute arbitrary PHP code… | Patch early | 5.1 medium | 2.4% | 2006-08-10 |
| CVE-2013-5118 EXP | Cross-site scripting (XSS) vulnerability in the Good for Enterprise app before 2.2.4.1659 for iOS allows remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 2.4% | 2013-09-25 |
| CVE-2007-1514 EXP | PHP remote file inclusion vulnerability in index.php in ViperWeb Portal alpha 0.1 allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 6.8 medium | 2.4% | 2007-03-20 |
| CVE-2005-1655 EXP | AOL Instant Messenger 5.5.x and earlier allows remote attackers to cause a denial of service (client crash) via an invalid smiley icon location in the… | Patch early | 5.0 medium | 2.4% | 2005-05-18 |
| CVE-2006-2577 EXP | Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute ar… | Patch early | 5.1 medium | 2.4% | 2006-05-24 |
| CVE-2004-1828 EXP | Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and d… | Patch early | 5.0 medium | 2.4% | 2004-12-31 |
| CVE-2007-0501 EXP | PHP remote file inclusion vulnerability in index.php in Mafia Scum Tools 2.0.0 in Matthew Wardrop Advanced Random Generators (adv-random-gen) allows r… | Patch early | 6.8 medium | 2.4% | 2007-01-25 |
| CVE-2017-15081 EXP | In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php. | Patch early | 9.8 critical | 2.4% | 2017-10-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt