CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,169 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-1646 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow rem… | Patch early | 4.3 medium | 1.3% | 2013-09-05 |
| CVE-2006-5556 EXP | Buffer overflow in the localtime_r function, and certain other functions, in libc in HP-UX B.11.11 and possibly other versions allows local users to e… | Patch early | 4.6 medium | 1.3% | 2006-10-27 |
| CVE-2015-6493 EXP | Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenti… | Patch early | 6.8 medium | 1.3% | 2015-10-28 |
| CVE-2006-4855 EXP | The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, Ant… | Patch early | 4.9 medium | 1.3% | 2006-09-19 |
| CVE-2012-5367 EXP | Multiple SQL injection vulnerabilities in OrangeHRM 2.7.1 RC 1 allow remote authenticated administrators to execute arbitrary SQL commands via the sor… | Patch early | 6.0 medium | 1.3% | 2012-12-03 |
| CVE-2012-2571 EXP | Multiple cross-site scripting (XSS) vulnerabilities in WinWebMail Server 3.8.1.6 allow remote attackers to inject arbitrary web script or HTML via an… | Patch early | 4.3 medium | 1.3% | 2012-08-12 |
| CVE-2012-2575 EXP | Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 6.0a4 allows remote attackers to inject arbitrary web script or HTML via the SRC attribut… | Patch early | 4.3 medium | 1.3% | 2012-09-17 |
| CVE-2012-2587 EXP | Multiple cross-site scripting (XSS) vulnerabilities in AfterLogic MailSuite Pro 6.3 allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.3% | 2012-08-12 |
| CVE-2012-2590 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ESCON SupportPortal Professional Edition 3.0 allow remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 1.3% | 2012-08-12 |
| CVE-2012-4932 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SimpleInvoices before stable-2012-1-CIS3000 allow remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 1.3% | 2012-12-28 |
| CVE-2012-6585 EXP | Cross-site scripting (XSS) vulnerability in search.php in MYRE Realty Manager allows remote attackers to inject arbitrary web script or HTML via the c… | Patch early | 4.3 medium | 1.3% | 2013-08-25 |
| CVE-2012-6589 EXP | Cross-site scripting (XSS) vulnerability in search.php in MYRE Business Directory allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.3% | 2013-08-25 |
| CVE-2024-28623 EXP | RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section. | Patch early | 6.1 medium | 1.3% | 2024-03-13 |
| CVE-2009-4157 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for Joomla! allow… | Patch early | 4.3 medium | 1.3% | 2009-12-02 |
| CVE-2010-2509 EXP | Multiple cross-site scripting (XSS) vulnerabilities in 2daybiz Web Template Software allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.3% | 2010-06-28 |
| CVE-2008-1228 EXP | Cross-site scripting (XSS) vulnerability in admin.php in MG2 (formerly Minigal) allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.3% | 2008-03-10 |
| CVE-2005-0886 EXP | Cross-site scripting (XSS) vulnerability in Invision Power Board 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.3% | 2005-05-02 |
| CVE-2008-6975 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijack the authentication of admini… | Patch early | 6.8 medium | 1.3% | 2009-08-14 |
| CVE-2024-27743 EXP | Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the A… | Patch early | 6.1 medium | 1.3% | 2024-03-01 |
| CVE-2005-3914 EXP | Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCa… | Patch early | 6.4 medium | 1.3% | 2005-11-30 |
| CVE-2012-1506 EXP | SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to e… | Patch early | 6.5 medium | 1.3% | 2014-09-17 |
| CVE-2025-47226 EXP | Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information. | Patch early | 5.0 medium | 1.3% | 2025-05-02 |
| CVE-2012-6518 EXP | Cross-site request forgery (CSRF) vulnerability in mod.php in DiY-CMS 1.0 allows remote attackers to hijack the authentication of administrators for r… | Patch early | 6.8 medium | 1.3% | 2013-01-24 |
| CVE-2008-6478 EXP | Cross-site request forgery (CSRF) vulnerability in the file manager in the VZPP web interface for Parallels Virtuozzo 365.6.swsoft (build 4.0.0-365.6.… | Patch early | 6.8 medium | 1.3% | 2009-03-16 |
| CVE-2012-3232 EXP | Cross-site scripting (XSS) vulnerability in search.php in web@all 2.0, as downloaded before May 30, 2012, allows remote attackers to inject arbitrary… | Patch early | 4.3 medium | 1.3% | 2012-06-29 |
| CVE-2011-1100 EXP | Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute arbitrary SQL commands via th… | Patch early | 6.5 medium | 1.3% | 2011-02-25 |
| CVE-2012-4902 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Template CMS 2.1.1 and earlier allow remote attackers to hijack the authentication of ad… | Patch early | 6.8 medium | 1.3% | 2015-05-20 |
| CVE-2009-3057 EXP | Multiple cross-site scripting (XSS) vulnerabilities in AOM Software Beex 3 allow remote attackers to inject arbitrary web script or HTML via the navac… | Patch early | 4.3 medium | 1.3% | 2009-09-03 |
| CVE-2009-3066 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PropertyWatchScript.com Property Watch 2.0 allow remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 1.3% | 2009-09-03 |
| CVE-2009-4717 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Gonafish WebStatCaffe allow remote attackers to inject arbitrary web script or HTML via the (1)… | Patch early | 4.3 medium | 1.3% | 2010-03-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt