CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,984 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-3199 EXP | Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download… | Patch early | 5.0 medium | 2.2% | 2009-09-15 |
| CVE-2009-4545 EXP | Logoshows BBS 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a databa… | Patch early | 5.0 medium | 2.2% | 2010-01-04 |
| CVE-2007-0302 EXP | Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Sess… | Patch early | 6.8 medium | 2.2% | 2007-01-18 |
| CVE-2009-1595 EXP | The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passw… | Patch early | 4.0 medium | 2.2% | 2009-05-11 |
| CVE-2010-1999 EXP | Directory traversal vulnerability in scr/soustab.php in OpenMairie Opencatalogue 1.024, when register_globals is enabled, allows remote attackers to i… | Patch early | 6.8 medium | 2.2% | 2010-05-20 |
| CVE-2009-0611 EXP | Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterprise Server 1.x allow remote a… | Patch early | 4.3 medium | 2.2% | 2009-02-17 |
| CVE-2012-3835 EXP | Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow remote attackers to in… | Patch early | 4.3 medium | 2.2% | 2012-07-03 |
| CVE-2012-1261 EXP | Cross-site scripting (XSS) vulnerability in cgi-bin/scrut_fa_exclusions.cgi in Plixer International Scrutinizer NetFlow and sFlow Analyzer 8.6.2.16204… | Patch early | 6.1 medium | 2.2% | 2020-01-09 |
| CVE-2006-0787 EXP | wimpy_trackplays.php in Plaino Wimpy MP3 Player, possibly 5.2 and earlier, allows remote attackers to insert arbitrary strings into trackme.txt via th… | Patch early | 4.0 medium | 2.2% | 2006-02-19 |
| CVE-2007-6202 EXP | SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers to execute arbitrary SQL comm… | Patch early | 6.8 medium | 2.2% | 2007-12-01 |
| CVE-2013-4200 EXP | The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs start… | Patch early | 5.8 medium | 2.2% | 2014-01-21 |
| CVE-2007-0121 EXP | Cross-site scripting (XSS) vulnerability in search.asp in RI Blog 1.3 allows remote attackers to inject arbitrary web script or HTML via the q paramet… | Patch early | 6.8 medium | 2.2% | 2007-01-09 |
| CVE-1999-0908 EXP | Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_ent… | Patch early | 5.0 medium | 2.2% | 1999-09-23 |
| CVE-2001-0407 EXP | Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whos… | Patch early | 4.6 medium | 2.2% | 2001-06-27 |
| CVE-2008-0751 EXP | Cross-site scripting (XSS) vulnerability in the Freetag before 2.96 plugin for S9Y Serendipity, when using Internet Explorer 6 or 7, allows remote att… | Patch early | 4.3 medium | 2.2% | 2008-02-13 |
| CVE-2004-2563 EXP | Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and conduct cro… | Patch early | 5.8 medium | 2.2% | 2004-12-31 |
| CVE-2007-6135 EXP | Cross-site scripting (XSS) vulnerability in phpslideshow.php in PHPSlideShow 0.9.9.2, and possibly earlier, allows remote attackers to inject arbitrar… | Patch early | 4.3 medium | 2.2% | 2007-11-27 |
| CVE-2013-4664 EXP | SPBAS Business Automation Software 2012 has XSS. | Patch early | 6.1 medium | 2.2% | 2019-12-27 |
| CVE-2014-8995 EXP | SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the UserId cookie. | Patch early | 5.0 medium | 2.2% | 2014-11-20 |
| CVE-2009-2329 EXP | KerviNet Forum 1.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) admin/head.php, or (2) voting_diagr… | Patch early | 5.0 medium | 2.2% | 2009-07-05 |
| CVE-2009-4961 EXP | Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls the phpinfo function. | Patch early | 5.0 medium | 2.2% | 2010-07-28 |
| CVE-2007-1873 EXP | Cross-site scripting (XSS) vulnerability in Mephisto 0.7.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter to the s… | Patch early | 4.3 medium | 2.2% | 2007-04-13 |
| CVE-2001-0114 EXP | statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter. | Patch early | 5.0 medium | 2.2% | 2001-03-12 |
| CVE-2005-3329 EXP | Cross-site scripting (XSS) vulnerability in RSA Authentication Agent for Web 5.3 and earlier allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 2.2% | 2005-10-27 |
| CVE-2008-5569 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PHPepperShop 1.4 allow remote attackers to inject arbitrary web script or HTML via the PATH_INF… | Patch early | 4.3 medium | 2.2% | 2008-12-15 |
| CVE-2006-6487 EXP | Cross-site scripting (XSS) vulnerability in index.php in DT Guestbook (dt_guestbook) 1.0f, when register_globals is enabled, allows remote attackers t… | Patch early | 5.1 medium | 2.2% | 2007-01-16 |
| CVE-2009-2588 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Hotscripts Type PHP Clone Script allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 2.2% | 2009-07-24 |
| CVE-2009-2684 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers,… | Patch early | 4.3 medium | 2.2% | 2009-10-13 |
| CVE-2009-3565 EXP | Multiple cross-site scripting (XSS) vulnerabilities in intruvert/jsp/module/Login.jsp in McAfee IntruShield Network Security Manager (NSM) before 5.1.… | Patch early | 4.3 medium | 2.2% | 2009-11-13 |
| CVE-2007-6374 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 2.2% | 2007-12-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt