CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,237 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-10019 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem allow remot… | Patch early | 6.8 medium | 1.3% | 2015-01-13 |
| CVE-2017-9150 EXP | The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value available for restricting the… | Patch early | 5.5 medium | 1.3% | 2017-05-22 |
| CVE-2002-1602 EXP | Buffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows local users to execute arbitrary code. | Patch early | 4.6 medium | 1.3% | 2002-04-23 |
| CVE-2009-1283 EXP | glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privileg… | Patch early | 6.8 medium | 1.3% | 2009-04-09 |
| CVE-2009-3248 EXP | Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin us… | Patch early | 6.8 medium | 1.3% | 2009-09-18 |
| CVE-2014-0794 EXP | SQL injection vulnerability in the JV Comment (com_jvcomment) component before 3.0.3 for Joomla! allows remote authenticated users to execute arbitrar… | Patch early | 4.3 medium | 1.3% | 2014-01-26 |
| CVE-2009-0672 EXP | SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated administrators to execute arbi… | Patch early | 6.5 medium | 1.3% | 2009-02-22 |
| CVE-2001-0641 EXP | Buffer overflow in man program in various distributions of Linux allows local user to execute arbitrary code as group man via a long -S option. | Patch early | 4.6 medium | 1.3% | 2001-09-20 |
| CVE-2009-1337 EXP | The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, w… | Patch early | 4.4 medium | 1.3% | 2009-04-22 |
| CVE-2009-1451 EXP | Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB 0.3.12 allows remote attackers to inject arbitrary web script or HTML via the PATH… | Patch early | 4.3 medium | 1.3% | 2009-04-28 |
| CVE-2009-2153 EXP | Cross-site scripting (XSS) vulnerability in index.php in Impleo Music Collection 2.0 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.3% | 2009-06-22 |
| CVE-2007-1289 EXP | SQL injection vulnerability in ViewBugs.php in Tyger Bug Tracking System (TygerBT) 1.1.3 allows remote attackers to execute arbitrary SQL commands via… | Patch early | 6.4 medium | 1.3% | 2007-03-07 |
| CVE-2001-0595 EXP | Buffer overflow in the kcsSUNWIOsolf.so library in Solaris 7 and 8 allows local attackers to execute arbitrary commands via the KCMS_PROFILES environm… | Patch early | 4.6 medium | 1.3% | 2001-08-02 |
| CVE-2009-3256 EXP | Cross-site scripting (XSS) vulnerability in include/ajax/blogInfo.php in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.3% | 2009-09-18 |
| CVE-2013-7376 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.10, possibly before revision 82710, allow remote attackers to hijack the authe… | Patch early | 6.8 medium | 1.3% | 2014-05-14 |
| CVE-2015-4119 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication of (1) ad… | Patch early | 6.8 medium | 1.3% | 2015-06-15 |
| CVE-2007-1159 EXP | Cross-site scripting (XSS) vulnerability in modules/out.php in Pyrophobia 2.1.3.1 allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.2% | 2007-03-02 |
| CVE-2002-0932 EXP | SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activit… | Patch early | 6.4 medium | 1.2% | 2002-10-04 |
| CVE-2012-4240 EXP | SQL injection vulnerability in modules/calendar/json.php in Group-Office community before 4.0.90 allows remote authenticated users to execute arbitrar… | Patch early | 6.5 medium | 1.2% | 2014-09-11 |
| CVE-2006-1419 EXP | SQL injection vulnerability in the Calendar module in nuked-klan 1.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the m… | Patch early | 5.0 medium | 1.2% | 2006-03-28 |
| CVE-2006-1572 EXP | SQL injection vulnerability in post.php in Oxygen 1.1.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a newthread… | Patch early | 5.0 medium | 1.2% | 2006-04-01 |
| CVE-2009-3348 EXP | Cross-site scripting (XSS) vulnerability in Datavore Gyro 5.0 allows remote attackers to inject arbitrary web script or HTML via the cid parameter in… | Patch early | 4.3 medium | 1.2% | 2009-09-24 |
| CVE-2009-3755 EXP | Multiple cross-site scripting (XSS) vulnerabilities in phpBMS 0.96 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to… | Patch early | 4.3 medium | 1.2% | 2009-10-22 |
| CVE-2009-2178 EXP | Cross-site scripting (XSS) vulnerability in website.php in phpDatingClub 3.7 allows remote attackers to inject arbitrary web script or HTML via the pa… | Patch early | 4.3 medium | 1.2% | 2009-06-23 |
| CVE-2009-4864 EXP | Multiple cross-site scripting (XSS) vulnerabilities in escorts_search.php in I-Escorts Directory Script and Agency Script allow remote attackers to in… | Patch early | 4.3 medium | 1.2% | 2010-05-11 |
| CVE-2006-5086 EXP | Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with mo… | Patch early | 6.4 medium | 1.2% | 2006-09-29 |
| CVE-2009-2424 EXP | Cross-site scripting (XSS) vulnerability in search.php in Ebay Clone 2009 allows remote attackers to inject arbitrary web script or HTML via the mode… | Patch early | 4.3 medium | 1.2% | 2009-07-10 |
| CVE-2014-4865 EXP | Cross-site request forgery (CSRF) vulnerability in gui/password-wadmin.apl in CacheGuard OS 5.7.7 allows remote attackers to hijack the authentication… | Patch early | 6.8 medium | 1.2% | 2014-09-10 |
| CVE-2024-11605 EXP | The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, which could allow high privilege u… | Patch early | 4.8 medium | 1.2% | 2024-12-27 |
| CVE-2012-1901 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in FlexCMS 3.2.1 and earlier allow remote attackers to (1) hijack the authentication of use… | Patch early | 6.8 medium | 1.2% | 2012-09-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt