CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,116 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-4882 EXP | Multiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (ePO) extension for McAfee Agent… | Patch early | 6.5 medium | 3.9% | 2013-07-22 |
| CVE-2019-1642 EXP | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attac… | Patch early | 6.1 medium | 3.9% | 2019-01-23 |
| CVE-2018-20503 EXP | Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter. | Patch early | 6.1 medium | 3.9% | 2019-05-07 |
| CVE-2023-24657 EXP | phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php. | Patch early | 6.1 medium | 3.9% | 2023-03-08 |
| CVE-2006-5241 EXP | Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Gallery 1.4 and earlier, when register_globals is enabled, allow remote attackers… | Patch early | 5.1 medium | 3.9% | 2006-10-12 |
| CVE-2005-0843 EXP | CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body parameter… | Patch early | 5.0 medium | 3.9% | 2005-05-02 |
| CVE-2006-2040 EXP | Multiple SQL injection vulnerabilities in photokorn 1.53 and 1.542 allow remote attackers to execute arbitrary SQL commands via the (1) cat, (2) pic a… | Patch early | 6.4 medium | 3.9% | 2006-04-26 |
| CVE-2017-8479 EXP | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… | Patch early | 5.0 medium | 3.9% | 2017-06-15 |
| CVE-2017-8481 EXP | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… | Patch early | 5.0 medium | 3.9% | 2017-06-15 |
| CVE-2017-8489 EXP | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… | Patch early | 5.0 medium | 3.9% | 2017-06-15 |
| CVE-2017-8491 EXP | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… | Patch early | 5.0 medium | 3.9% | 2017-06-15 |
| CVE-2007-4140 EXP | Buffer overflow in Live for Speed (LFS) S2 ALPHA PATCH 0.5x allows user-assisted remote attackers to execute arbitrary code via a .mpr file (replay fi… | Patch early | 6.8 medium | 3.9% | 2007-08-03 |
| CVE-2010-3077 EXP | Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows remote attackers to inject ar… | Patch early | 4.3 medium | 3.9% | 2010-11-09 |
| CVE-2006-2027 EXP | Buffer overflow in Unicode processing in the logging functionality in Pablo Software Solutions Quick 'n Easy FTP Server Professional and Lite, probabl… | Patch early | 6.5 medium | 3.9% | 2006-04-26 |
| CVE-2011-5228 EXP | Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 3.9% | 2012-10-25 |
| CVE-2013-4950 EXP | Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the element_2 pa… | Patch early | 4.3 medium | 3.9% | 2013-07-29 |
| CVE-2008-5185 EXP | The highlighting functionality in geshi.php in GeSHi before 1.0.8 allows remote attackers to cause a denial of service (infinite loop) via an XML sequ… | Patch early | 5.0 medium | 3.9% | 2008-11-21 |
| CVE-2007-4803 EXP | Buffer overflow in AtomixMP3 2.3 allows user-assisted remote attackers to execute arbitrary code via long strings in file and title fields in a .pls f… | Patch early | 6.8 medium | 3.9% | 2007-09-11 |
| CVE-2019-10349 EXP | A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jen… | Patch early | 5.4 medium | 3.9% | 2019-07-11 |
| CVE-2003-1157 EXP | Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3.9% | 2003-12-31 |
| CVE-2006-2986 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Baby Katie Media (a) very Simple Car Lister (vSCAL) 1.0 and (b) very simple Realty Lister (vsRE… | Patch early | 4.3 medium | 3.9% | 2006-06-13 |
| CVE-2006-3006 EXP | Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly other versions before 0.50, allows remote attackers to inject arbitrary HTML or w… | Patch early | 4.3 medium | 3.9% | 2006-06-13 |
| CVE-2015-2511 EXP | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012… | Patch early | 6.9 medium | 3.9% | 2015-09-09 |
| CVE-2015-2518 EXP | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012… | Patch early | 6.9 medium | 3.9% | 2015-09-09 |
| CVE-2018-6219 EXP | An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain typ… | Patch early | 6.5 medium | 3.9% | 2018-03-15 |
| CVE-2023-1258 EXP | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allo… | Patch early | 5.3 medium | 3.9% | 2023-03-31 |
| CVE-2002-2338 EXP | The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no n… | Patch early | 5.0 medium | 3.9% | 2002-12-31 |
| CVE-2004-2528 EXP | Cross-site scripting (XSS) vulnerability in sresult.exe in Webcam Watchdog 4.0.1a allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 3.9% | 2004-12-31 |
| CVE-2006-1486 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in realestateZONE 4.2 allow remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 3.9% | 2006-03-29 |
| CVE-2007-5064 EXP | Buffer overflow in a certain ActiveX control in Xunlei Web Thunder 5.6.9.344, possibly the DapPlayer ActiveX control in DapPlayer_Now.dll, allows remo… | Patch early | 6.8 medium | 3.9% | 2007-09-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt