CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,169 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
208,192 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-6547 EXP | RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords… | Patch early | 6.8 medium | 2.4% | 2007-12-28 |
| CVE-2011-4595 EXP | Pretty-Link WordPress plugin 1.5.2 has XSS | Patch early | 6.1 medium | 2.4% | 2020-01-10 |
| CVE-2002-1533 EXP | Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to… | Patch early | 5.8 medium | 2.4% | 2003-03-31 |
| CVE-2007-6501 EXP | Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type" via a re… | Patch early | 5.5 medium | 2.4% | 2007-12-20 |
| CVE-2009-4048 EXP | Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (daemon outage) via an APPE command to one so… | Patch early | 4.0 medium | 2.4% | 2009-11-23 |
| CVE-2008-6643 EXP | LokiCMS 0.3.4 and possibly earlier versions does not properly restrict access to administrative functions, which allows remote attackers to bypass int… | Patch early | 5.0 medium | 2.4% | 2009-04-07 |
| CVE-2013-1742 EXP | Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7;… | Patch early | 4.3 medium | 2.4% | 2013-10-24 |
| CVE-2005-0776 EXP | adm-photo.php in PhotoPost PHP 5.0 RC3 does not properly verify administrative privileges before manipulating photos, which could allow remote attacke… | Patch early | 5.0 medium | 2.4% | 2005-05-02 |
| CVE-2007-4089 EXP | Vikingboard 0.1.2 allows remote attackers to obtain sensitive information via the debug parameter to (1) forum.php, (2) cp.php, and possibly other uns… | Patch early | 4.3 medium | 2.4% | 2007-07-30 |
| CVE-2007-1580 EXP | FTPDMIN 0.96 allows remote attackers to cause a denial of service (daemon crash) via a LIST command for a Windows drive letter, as demonstrated using… | Patch early | 6.3 medium | 2.4% | 2007-03-21 |
| CVE-2014-2017 EXP | CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x befor… | Patch early | 6.1 medium | 2.4% | 2018-01-18 |
| CVE-2008-0724 EXP | The Everything Development Engine in The Everything Development System Pre-1.0 and earlier stores passwords in cleartext in a database, which makes it… | Patch early | 5.0 medium | 2.4% | 2008-02-12 |
| CVE-2019-18859 EXP | Digi AnywhereUSB 14 allows XSS via a link for the Digi Page. | Patch early | 6.1 medium | 2.4% | 2020-01-09 |
| CVE-2006-1323 EXP | Directory traversal vulnerability in WinHKI 1.6 and earlier allows user-assisted attackers to overwrite arbitrary files via a (1) RAR, (2) TAR, (3) ZI… | Patch early | 5.1 medium | 2.4% | 2006-03-20 |
| CVE-2006-6363 EXP | Cross-site scripting (XSS) vulnerability in admin.pl in BlueSocket Secure Controller (BSC) before 5.2, or without 5.1.1-BluePatch, allows remote attac… | Patch early | 6.8 medium | 2.4% | 2006-12-07 |
| CVE-2006-6451 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 6.8 medium | 2.4% | 2006-12-10 |
| CVE-2001-1259 EXP | Avaya Argent Office allows remote attackers to cause a denial of service by sending UDP packets to port 53 with no payload. | Patch early | 5.0 medium | 2.4% | 2001-08-07 |
| CVE-2005-4080 EXP | Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting… | Patch early | 4.3 medium | 2.4% | 2005-12-08 |
| CVE-2009-0374 EXP | Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to… | Patch early | 4.3 medium | 2.4% | 2009-01-30 |
| CVE-2010-0966 EXP | PHP remote file inclusion vulnerability in inc/config.php in deV!L`z Clanportal (DZCP) 1.5.2, when register_globals is enabled, allows remote attacker… | Patch early | 6.8 medium | 2.4% | 2010-03-16 |
| CVE-2005-0895 EXP | Netcomm 1300NB DSL Modem allows remote attackers to cause a denial of service (device hang) via a large number of ping packets. | Patch early | 5.0 medium | 2.4% | 2005-05-02 |
| CVE-2005-3002 EXP | Multi-Computer Control System (MCCS) 1.0 allows remote attackers to cause a denial of service via a malformed UDP packet. | Patch early | 5.0 medium | 2.4% | 2005-09-20 |
| CVE-2012-1912 EXP | Cross-site scripting (XSS) vulnerability in preferences.php in PHP Address Book 7.0 and earlier allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 2.4% | 2012-09-09 |
| CVE-2010-3437 EXP | Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users t… | Patch early | 6.6 medium | 2.4% | 2010-10-04 |
| CVE-2007-3523 EXP | Multiple directory traversal vulnerabilities in Module/Galerie.php in XCMS 1.1 allow remote attackers to include and execute arbitrary local files via… | Patch early | 6.4 medium | 2.4% | 2007-07-03 |
| CVE-2007-3772 EXP | Directory traversal vulnerability in news/show.php in PsNews 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot do… | Patch early | 6.4 medium | 2.4% | 2007-07-15 |
| CVE-2017-6982 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. The issue involves the "Notifications" component. It allows attacker… | Patch early | 5.5 medium | 2.4% | 2017-05-22 |
| CVE-2006-5838 EXP | PHP remote file inclusion vulnerability in lib/class.Database.php in NewP News Publication System 1.0.0, when register_globals is enabled, allows remo… | Patch early | 5.1 medium | 2.4% | 2006-11-10 |
| CVE-2010-0983 EXP | PHP remote file inclusion vulnerability in include/mail.inc.php in Rezervi 3.0.2 and earlier, when register_globals is enabled, allows remote attacker… | Patch early | 6.8 medium | 2.4% | 2010-03-16 |
| CVE-2008-5938 EXP | PHP remote file inclusion vulnerability in assets/snippets/reflect/snippet.reflect.php in MODx CMS 0.9.6.2 and earlier, when magic_quotes_gpc is disab… | Patch early | 6.8 medium | 2.4% | 2009-01-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt