CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,370 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
322,112 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-6668 EXP | admin/uploadgames.php in MySpace Content Zone (MCZ) 3.x does not require administrative privileges, which allows remote attackers to perform unrestric… | Patch early | 7.5 high | 6.4% | 2008-01-08 |
| CVE-2009-4091 EXP | comments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers to edit or delete comments via… | Patch early | 5.0 medium | 6.4% | 2009-11-29 |
| CVE-2001-1490 EXP | Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images. | Patch early | 5.0 medium | 6.4% | 2001-12-31 |
| CVE-2006-2516 EXP | mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite variables such as $xoopsOption['noc… | Patch early | 5.1 medium | 6.4% | 2006-05-22 |
| CVE-2009-3643 EXP | Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote attackers to cause a denial of service via a long argument to the (1) LIST and (2) NLST comman… | Patch early | 5.0 medium | 6.4% | 2009-10-09 |
| CVE-2008-6752 EXP | adminlogin/password.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging does not verify the original password before changing passwords,… | Patch early | 7.5 high | 6.3% | 2009-04-24 |
| CVE-2019-8927 EXP | An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfi… | Patch early | 6.1 medium | 6.3% | 2019-05-17 |
| CVE-2013-2682 EXP | Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information. | Patch early | 4.3 medium | 6.3% | 2020-02-05 |
| CVE-2010-5194 EXP | Stack-based buffer overflow in the Image2PDF function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageViewer2.ocx) in Viscom Image Viewer CP Pro… | Patch early | 9.3 high | 6.3% | 2012-08-31 |
| CVE-2015-8612 EXP | The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users to gain privileges via the dh… | Patch early | 8.4 high | 6.3% | 2016-01-08 |
| CVE-2008-7240 EXP | Directory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows remote attackers to include and e… | Patch early | 7.5 high | 6.3% | 2009-09-17 |
| CVE-2007-6537 EXP | Stack-based buffer overflow in the zfile_gunzip function in zfile.c in WinUAE 1.4.4 and earlier allows user-assisted remote attackers to execute arbit… | Patch early | 6.8 medium | 6.3% | 2007-12-27 |
| CVE-2005-3010 EXP | Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers… | Patch early | 7.5 high | 6.3% | 2005-09-21 |
| CVE-2009-0572 EXP | PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enab… | Patch early | 5.1 medium | 6.3% | 2009-02-13 |
| CVE-2000-0146 EXP | The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service via a long URL to the servlet… | Patch early | 5.0 medium | 6.3% | 2000-02-07 |
| CVE-2002-1910 EXP | Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtai… | Patch early | 7.5 high | 6.3% | 2002-12-31 |
| CVE-2017-2479 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affect… | Patch early | 6.5 medium | 6.3% | 2017-04-02 |
| CVE-2014-3146 EXP | Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) at… | Patch early | 6.1 medium | 6.3% | 2014-05-14 |
| CVE-2007-1933 EXP | Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a… | Patch early | 7.5 high | 6.3% | 2007-04-10 |
| CVE-2007-3932 EXP | uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to… | Patch early | 7.5 high | 6.3% | 2007-07-21 |
| CVE-2008-6535 EXP | admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the administrative password via a direc… | Patch early | 7.5 high | 6.3% | 2009-03-26 |
| CVE-2004-1535 EXP | PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by m… | Patch early | 7.5 high | 6.3% | 2004-12-31 |
| CVE-2005-0513 EXP | PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions includi… | Patch early | 7.5 high | 6.3% | 2005-02-19 |
| CVE-2007-6041 EXP | Buffer overflow in the Sequencer::queueMessage function in sequencer.cpp in the server in Rigs of Rods (RoR) before 0.33d SP1 allows remote attackers… | Patch early | 7.5 high | 6.3% | 2007-11-20 |
| CVE-2006-6690 EXP | rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote auth… | Patch early | 7.5 high | 6.3% | 2006-12-21 |
| CVE-2013-1402 EXP | DigiLIBE 3.4 and possibly other versions sends a redirect but does not exit, which allows remote attackers to obtain sensitive configuration informati… | Patch early | 5.0 medium | 6.3% | 2013-02-14 |
| CVE-2011-4810 EXP | Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read arbitrary files via the templat… | Patch early | 5.0 medium | 6.3% | 2011-12-14 |
| CVE-2007-2777 EXP | Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execut… | Patch early | 7.5 high | 6.3% | 2007-05-21 |
| CVE-2013-1937 EXP | Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inje… | Patch early | 6.1 medium | 6.3% | 2013-04-16 |
| CVE-2008-6761 EXP | Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject arbitrary PHP code into const.in… | Patch early | 10.0 high | 6.3% | 2009-04-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt