CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,123 CVEs
1,733 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-5749 EXP | Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --rendere… | Patch early | 6.8 medium | 3.7% | 2008-12-29 |
| CVE-2014-9610 EXP | Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP addresses from the… | Patch early | 5.3 medium | 3.7% | 2017-09-19 |
| CVE-2014-3738 EXP | Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the title of a device. | Patch early | 4.3 medium | 3.7% | 2014-05-20 |
| CVE-2009-4932 EXP | Stack-based buffer overflow in 1by1 1.67 (aka 1.6.7.0) allows remote attackers to cause a denial of service (application crash) or possibly execute ar… | Patch early | 6.8 medium | 3.7% | 2010-07-12 |
| CVE-2011-5180 EXP | Cross-site scripting (XSS) vulnerability in wp-1pluginjquery.php in the ZooEffect plugin 1.01 for WordPress allows remote attackers to inject arbitrar… | Patch early | 4.3 medium | 3.7% | 2012-09-20 |
| CVE-2012-2579 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the WP SimpleMail plugin 1.0.6 for WordPress allow remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 3.7% | 2014-06-20 |
| CVE-2012-2580 EXP | Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly before 1.5.15, for WordPress allows remote attackers to inject arbit… | Patch early | 4.3 medium | 3.7% | 2014-06-20 |
| CVE-2012-2583 EXP | Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 3.7% | 2014-09-17 |
| CVE-2012-5229 EXP | Cross-site scripting (XSS) vulnerability in css/gallery-css.php in the Slideshow Gallery2 plugin for WordPress allows remote attackers to inject arbit… | Patch early | 4.3 medium | 3.7% | 2012-10-01 |
| CVE-2012-5346 EXP | Cross-site scripting (XSS) vulnerability in wp-live.php in the WP Live.php module 1.2.1 for WordPress allows remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 3.7% | 2012-10-09 |
| CVE-2007-1678 EXP | Cross-site scripting (XSS) vulnerability in the Fizzle 0.5 extension for Firefox allows remote attackers to inject arbitrary web script or HTML via RS… | Patch early | 4.3 medium | 3.7% | 2007-03-26 |
| CVE-2020-15364 EXP | The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS. | Patch early | 6.1 medium | 3.7% | 2020-06-28 |
| CVE-2009-3861 EXP | Stack-based buffer overflow in SafeNet SoftRemote 10.8.5 (Build 2) and 10.3.5 (Build 6), and possibly other versions before 10.8.9, allows local users… | Patch early | 6.9 medium | 3.7% | 2009-11-04 |
| CVE-2004-0276 EXP | The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an HTT… | Patch early | 5.0 medium | 3.7% | 2004-11-23 |
| CVE-2004-1744 EXP | Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to cause a denial of service (CPU consumption or crash) via many large HTTP requests. | Patch early | 5.0 medium | 3.7% | 2004-08-24 |
| CVE-2003-0769 EXP | Cross-site scripting (XSS) vulnerability in the ICQ Web Front guestbook (guestbook.html) allows remote attackers to insert arbitrary web script and HT… | Patch early | 4.3 medium | 3.7% | 2003-09-22 |
| CVE-2008-0547 EXP | Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably earlier 4.x and 3.x versions, all… | Patch early | 4.3 medium | 3.7% | 2008-02-01 |
| CVE-2009-2275 EXP | Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrary files via a .. (dot dot) in… | Patch early | 5.0 medium | 3.7% | 2009-07-01 |
| CVE-2007-2532 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Minh Nguyen Duong Obie Website Mini Web Shop 2 allow remote attackers to inject arbitrary web s… | Patch early | 4.3 medium | 3.7% | 2007-05-09 |
| CVE-2016-2384 EXP | Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows physically proximate attackers… | Patch early | 4.6 medium | 3.7% | 2016-04-27 |
| CVE-2008-6495 EXP | Cross-site scripting (XSS) vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 allows remote att… | Patch early | 4.3 medium | 3.7% | 2009-03-20 |
| CVE-2007-6516 EXP | Buffer overflow in RavWare Software MAS Flic ActiveX Control (masflc.ocx) 1.0.0.1 allows remote attackers to execute arbitrary code via a long FileNam… | Patch early | 6.8 medium | 3.7% | 2007-12-21 |
| CVE-2014-8948 EXP | Cross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote attackers to hijack the a… | Patch early | 6.8 medium | 3.7% | 2014-11-16 |
| CVE-2015-4018 EXP | SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for WordPress allows remote authent… | Patch early | 6.5 medium | 3.7% | 2015-05-21 |
| CVE-2009-1064 EXP | Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allows remote attackers to overwrit… | Patch early | 5.8 medium | 3.7% | 2009-03-26 |
| CVE-2006-1941 EXP | Neon Responder 5.4 for LANsurveyor allows remote attackers to cause a denial of service (application outage) via a crafted Clock Synchronisation packe… | Patch early | 5.0 medium | 3.7% | 2006-04-20 |
| CVE-2004-2592 EXP | Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a modified cli… | Patch early | 5.0 medium | 3.7% | 2004-12-31 |
| CVE-2017-8469 EXP | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… | Patch early | 5.5 medium | 3.7% | 2017-06-15 |
| CVE-2005-0870 EXP | Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary we… | Patch early | 4.3 medium | 3.7% | 2005-05-02 |
| CVE-2012-4668 EXP | Cross-site scripting (XSS) vulnerability in Roundcube Webmail 0.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 3.7% | 2012-08-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt