CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,899 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-4798 EXP | Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbitrary local files via directory… | Patch early | 6.8 medium | 2.3% | 2011-04-27 |
| CVE-2009-2330 EXP | Cross-site scripting (XSS) vulnerability in admin/admin_menu.php in CMS Chainuk 1.2 and earlier allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 2.3% | 2009-07-05 |
| CVE-2007-3630 EXP | changePW.php in AV Tutorial Script (avtutorial) 1.0 does not require authentication or knowledge of an old password for password changes, which allows… | Patch early | 6.4 medium | 2.3% | 2007-07-10 |
| CVE-2009-1665 EXP | myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid parameter wit… | Patch early | 6.4 medium | 2.3% | 2009-05-18 |
| CVE-2008-6354 EXP | The Net Guys ASPired2poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download… | Patch early | 5.0 medium | 2.3% | 2009-03-02 |
| CVE-2008-6355 EXP | The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo… | Patch early | 5.0 medium | 2.3% | 2009-03-02 |
| CVE-2009-0571 EXP | admin.php in Ninja Designs Mailist 3.0 stores backup copies of maillist.php under the web root with insufficient access control, which allows remote a… | Patch early | 5.0 medium | 2.3% | 2009-02-13 |
| CVE-2009-0767 EXP | Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file contain… | Patch early | 5.0 medium | 2.3% | 2009-03-06 |
| CVE-2009-1495 EXP | Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a da… | Patch early | 5.0 medium | 2.3% | 2009-05-01 |
| CVE-2015-5534 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall before 1.8 allow remote attackers to hijack the authentication of administrators… | Patch early | 6.8 medium | 2.3% | 2015-11-02 |
| CVE-2018-13134 EXP | TP-Link Archer C1200 1.13 Build 2018/01/24 rel.52299 EU devices have XSS via the PATH_INFO to the /webpages/data URI. | Patch early | 6.1 medium | 2.3% | 2018-07-04 |
| CVE-2018-7203 EXP | Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the fr… | Patch early | 6.1 medium | 2.3% | 2018-03-30 |
| CVE-2012-3819 EXP | Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and other products, allows remote… | Patch early | 5.0 medium | 2.3% | 2012-10-04 |
| CVE-2011-2743 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Chyrp 2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the act… | Patch early | 4.3 medium | 2.3% | 2011-07-19 |
| CVE-2017-10033 EXP | Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Support Tools). Supported versions that are affected… | Patch early | 4.0 medium | 2.3% | 2017-10-19 |
| CVE-2006-6732 EXP | PHP remote file inclusion vulnerability in archive.php in cwmVote 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the abs param… | Patch early | 6.8 medium | 2.3% | 2006-12-26 |
| CVE-2008-6849 EXP | Unrestricted file upload vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to execute arbitrary PHP code by uploading a file wit… | Patch early | 6.8 medium | 2.3% | 2009-07-07 |
| CVE-2008-0351 EXP | admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter an… | Patch early | 5.0 medium | 2.3% | 2008-01-18 |
| CVE-2014-3216 EXP | GOM Media Player 2.2.57.5189 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg file. | Patch early | 4.3 medium | 2.3% | 2014-06-10 |
| CVE-2005-4238 EXP | Cross-site scripting (XSS) vulnerability in view_filters_page.php in Mantis 1.0.0rc3 and earlier allows remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 2.3% | 2005-12-14 |
| CVE-2012-1027 EXP | Cross-site scripting (XSS) vulnerability in account-closed.tcl in ]project-open[ (aka ]po[) 3.4.x, 3.5.0.1-2, and possibly other versions allows remot… | Patch early | 4.3 medium | 2.3% | 2012-02-08 |
| CVE-2014-4699 EXP | The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a… | Patch early | 6.9 medium | 2.3% | 2014-07-09 |
| CVE-2018-17310 EXP | On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNam… | Patch early | 6.1 medium | 2.3% | 2018-09-26 |
| CVE-2018-17313 EXP | On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn p… | Patch early | 6.1 medium | 2.3% | 2018-09-26 |
| CVE-2007-1895 EXP | PHP remote file inclusion vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier, when used with PHP 5, allows remote attackers to execut… | Patch early | 6.8 medium | 2.3% | 2007-04-09 |
| CVE-2007-2049 EXP | Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (com_calendar) 1.5.5 for Mambo allow remote attackers to execute arbitrary P… | Patch early | 6.8 medium | 2.3% | 2007-04-16 |
| CVE-2006-0936 EXP | Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a form… | Patch early | 6.5 medium | 2.3% | 2006-02-28 |
| CVE-2007-6513 EXP | HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via… | Patch early | 4.3 medium | 2.3% | 2007-12-21 |
| CVE-2018-17587 EXP | AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. | Patch early | 6.1 medium | 2.3% | 2018-10-02 |
| CVE-2018-17588 EXP | AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. | Patch early | 6.1 medium | 2.3% | 2018-10-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt