CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,075 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-2582 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.13, 3.0.x before 3.0.15, and 3.1.x… | Patch early | 4.3 medium | 4.2% | 2012-08-23 |
| CVE-2005-3966 EXP | Cross-site scripting (XSS) vulnerability in search.jsp in Java Search Engine (JSE) 0.9.34 allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 4.2% | 2005-12-03 |
| CVE-2009-3457 EXP | Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP reque… | Patch early | 5.0 medium | 4.2% | 2009-09-29 |
| CVE-2008-0838 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface in Sophos ES1000 and ES4000 Email Security Appliance 2.1.0.0 a… | Patch early | 4.3 medium | 4.2% | 2008-02-20 |
| CVE-2013-3241 EXP | export.php (aka the export script) in phpMyAdmin 4.x before 4.0.0-rc3 overwrites global variables on the basis of the contents of the POST superglobal… | Patch early | 4.0 medium | 4.2% | 2013-04-26 |
| CVE-2014-4873 EXP | SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL commands… | Patch early | 6.5 medium | 4.2% | 2014-10-10 |
| CVE-2009-2177 EXP | code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to conduct directory traversal attac… | Patch early | 6.8 medium | 4.2% | 2009-06-23 |
| CVE-2006-3793 EXP | PHP remote file inclusion vulnerability in constants.php in SiteDepth CMS 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a… | Patch early | 5.1 medium | 4.2% | 2006-07-24 |
| CVE-2015-2218 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the WonderPlugin Audio Player plugin… | Patch early | 4.3 medium | 4.2% | 2015-03-05 |
| CVE-2002-0908 EXP | Directory traversal vulnerability in the web server for Cisco IDS Device Manager before 3.1.2 allows remote attackers to read arbitrary files via a ..… | Patch early | 5.0 medium | 4.2% | 2002-10-04 |
| CVE-2015-4465 EXP | Cross-site scripting (XSS) vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to inject arbitrary… | Patch early | 4.3 medium | 4.2% | 2015-06-10 |
| CVE-2014-4312 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allow remote attackers to inject arbitrary… | Patch early | 4.3 medium | 4.2% | 2014-10-10 |
| CVE-2013-3535 EXP | Multiple cross-site scripting (XSS) vulnerabilities in CMSLogik 1.2.0 and 1.2.1 allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 4.2% | 2013-05-13 |
| CVE-2004-2072 EXP | Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute scr… | Patch early | 6.8 medium | 4.2% | 2004-12-31 |
| CVE-2008-6926 EXP | Directory traversal vulnerability in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allows remote attackers to inclu… | Patch early | 6.8 medium | 4.2% | 2009-08-10 |
| CVE-2009-2787 EXP | Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB, when regi… | Patch early | 6.8 medium | 4.2% | 2009-08-17 |
| CVE-2017-12952 EXP | The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application cra… | Patch early | 6.5 medium | 4.2% | 2017-08-28 |
| CVE-2007-6309 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in webSPELL 4.1.2 allow remote attackers to inject arbitrary web script or HTML via (… | Patch early | 4.3 medium | 4.2% | 2007-12-11 |
| CVE-2007-4143 EXP | user.php in the Billing Control Panel in phpCoupon allows remote authenticated users to obtain Premium Member status, and possibly acquire free coupon… | Patch early | 4.0 medium | 4.2% | 2007-08-03 |
| CVE-2012-6667 EXP | Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbi… | Patch early | 6.1 medium | 4.2% | 2018-01-11 |
| CVE-2012-0984 EXP | Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) to… | Patch early | 4.3 medium | 4.2% | 2014-09-11 |
| CVE-2010-1948 EXP | Directory traversal vulnerability in scr/soustab.php in openMairie Openfoncier 2.00, when register_globals is enabled, allows remote attackers to incl… | Patch early | 6.8 medium | 4.2% | 2010-05-19 |
| CVE-2017-12953 EXP | The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory wri… | Patch early | 6.5 medium | 4.2% | 2017-08-28 |
| CVE-2017-12954 EXP | The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory read a… | Patch early | 6.5 medium | 4.2% | 2017-08-28 |
| CVE-2011-3979 EXP | Cross-site scripting (XSS) vulnerability in ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme module in Zikula Application Framework… | Patch early | 4.3 medium | 4.2% | 2011-10-04 |
| CVE-2007-2716 EXP | Multiple cross-site scripting (XSS) vulnerabilities in EQdkp 1.3.2c and earlier allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 6.8 medium | 4.2% | 2007-05-16 |
| CVE-2006-1679 EXP | Cross-site scripting (XSS) vulnerability in modules/online.php in Jupiter CMS 1.1.5 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 4.2% | 2006-04-11 |
| CVE-2014-6242 EXP | Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow remote authenticated users to… | Patch early | 6.5 medium | 4.2% | 2014-10-02 |
| CVE-2015-8727 EXP | The dissect_rsvp_common function in epan/dissectors/packet-rsvp.c in the RSVP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does… | Patch early | 5.5 medium | 4.2% | 2016-01-04 |
| CVE-2014-6312 EXP | Cross-site request forgery (CSRF) vulnerability in the Login Widget With Shortcode (login-sidebar-widget) plugin before 3.2.1 for WordPress allows rem… | Patch early | 4.3 medium | 4.2% | 2014-10-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt