CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,169 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-0455 EXP | gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature fi… | Patch early | 4.6 medium | 1.4% | 2006-02-15 |
| CVE-2013-6922 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attac… | Patch early | 6.8 medium | 1.4% | 2014-01-21 |
| CVE-2008-3937 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web sc… | Patch early | 6.1 medium | 1.4% | 2008-09-05 |
| CVE-2008-0787 EXP | SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via t… | Patch early | 6.5 medium | 1.4% | 2008-02-15 |
| CVE-2004-2102 EXP | Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.4% | 2004-12-31 |
| CVE-2005-0889 EXP | Cross-site scripting (XSS) vulnerability in index.php for Dream4 Koobi CMS 4.2.3 allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 1.4% | 2005-03-24 |
| CVE-2011-4806 EXP | Multiple cross-site scripting (XSS) vulnerabilities in main.php in phpAlbum 0.4.1.16 and earlier allow remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.4% | 2011-12-14 |
| CVE-2011-5185 EXP | Cross-site scripting (XSS) vulnerability in video_comments.php in Online Subtitles Workshop before 2.0 rev 131 allows remote attackers to inject arbit… | Patch early | 4.3 medium | 1.4% | 2012-09-20 |
| CVE-2012-2585 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ServiceDesk Plus 8.1 allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.4% | 2012-08-12 |
| CVE-2012-6587 EXP | Cross-site scripting (XSS) vulnerability in vacation/1_mobile/alert_members.php in MYRE Vacation Rental Software allows remote attackers to inject arb… | Patch early | 4.3 medium | 1.4% | 2013-08-25 |
| CVE-2018-10828 EXP | An issue was discovered in Alps Pointing-device Driver 10.1.101.207. ApMsgFwd.exe allows the current user to map and write to the "ApMsgFwd File Mappi… | Patch early | 5.5 medium | 1.3% | 2018-05-09 |
| CVE-2002-0793 EXP | Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the… | Patch early | 5.5 medium | 1.3% | 2002-08-12 |
| CVE-2012-2573 EXP | Multiple cross-site scripting (XSS) vulnerabilities in T-dah WebMail 3.2.0-2.3 allow remote attackers to inject arbitrary web script or HTML via an e-… | Patch early | 4.3 medium | 1.3% | 2012-08-12 |
| CVE-2018-13441 EXP | qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-o… | Patch early | 5.5 medium | 1.3% | 2018-07-12 |
| CVE-2006-0972 EXP | SQL injection vulnerability in news.php in Tony Baird Fantastic News 2.1.1 allows remote attackers to execute arbitrary SQL commands via the page para… | Patch early | 5.0 medium | 1.3% | 2006-03-03 |
| CVE-2006-3011 EXP | The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restricti… | Patch early | 4.6 medium | 1.3% | 2006-06-26 |
| CVE-2008-0540 EXP | Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote attackers to inject arbitrary web script or HTML via the query str… | Patch early | 4.3 medium | 1.3% | 2008-02-01 |
| CVE-2003-1308 EXP | CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary comma… | Patch early | 4.6 medium | 1.3% | 2003-12-31 |
| CVE-2010-0695 EXP | Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web script or HTML via the nav_id… | Patch early | 4.3 medium | 1.3% | 2010-02-23 |
| CVE-2013-4665 EXP | SPBAS Business Automation Software 2012 has CSRF. | Patch early | 6.5 medium | 1.3% | 2019-12-27 |
| CVE-2024-27744 EXP | Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the i… | Patch early | 6.1 medium | 1.3% | 2024-03-01 |
| CVE-2010-5285 EXP | Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the authentication of administrator… | Patch early | 6.8 medium | 1.3% | 2012-11-26 |
| CVE-2011-5196 EXP | Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Systems 2.3.6 and earlier allows… | Patch early | 6.8 medium | 1.3% | 2012-09-23 |
| CVE-2011-5160 EXP | Cross-site scripting (XSS) vulnerability in setup.php in OpenEMR 4 allows remote attackers to inject arbitrary web script or HTML via the site paramet… | Patch early | 4.3 medium | 1.3% | 2012-09-09 |
| CVE-2008-2189 EXP | SQL injection vulnerability in viewfaqs.php in AnServ Auction XL allows remote attackers to execute arbitrary SQL commands via the cat parameter. | Patch early | 6.8 medium | 1.3% | 2008-05-14 |
| CVE-2014-3246 EXP | SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via the folder parameter in a filevi… | Patch early | 6.5 medium | 1.3% | 2014-05-13 |
| CVE-2011-5186 EXP | Cross-site scripting (XSS) vulnerability in jbshop.php in the jbShop plugin for e107 7 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.3% | 2012-09-20 |
| CVE-2018-8815 EXP | Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to inject arbitrary web script or H… | Patch early | 4.6 medium | 1.3% | 2018-03-20 |
| CVE-2006-4250 EXP | Buffer overflow in man and mandb (man-db) 2.4.3 and earlier allows local users to execute arbitrary code via crafted arguments to the -H flag. | Patch early | 4.6 medium | 1.3% | 2007-04-10 |
| CVE-2013-6794 EXP | Cross-site scripting (XSS) vulnerability in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.3% | 2013-11-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt