CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,247 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-0761 EXP | Cross-site scripting (XSS) vulnerability in online.asp in Team Board 1.x allows remote attackers to inject arbitrary web script or HTML via the lookna… | Patch early | 4.3 medium | 1.2% | 2009-03-06 |
| CVE-2020-8425 EXP | Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php. | Patch early | 6.5 medium | 1.2% | 2020-01-28 |
| CVE-2003-1445 EXP | Stack-based buffer overflow in Far Manager 1.70beta1 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrar… | Patch early | 4.6 medium | 1.2% | 2003-12-31 |
| CVE-2005-3566 EXP | Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18… | Patch early | 4.3 medium | 1.2% | 2005-11-16 |
| CVE-2011-5259 EXP | SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM before 2.6.11.2 allows remote attackers to execute arbitrary SQL com… | Patch early | 6.8 medium | 1.2% | 2013-02-12 |
| CVE-2019-10227 EXP | openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component. | Patch early | 6.1 medium | 1.2% | 2019-12-31 |
| CVE-2010-0709 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Limny 2.0 allow remote attackers to (1) hijack the authentication of users or administra… | Patch early | 6.8 medium | 1.2% | 2010-02-25 |
| CVE-2020-12707 EXP | An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS i… | Patch early | 6.1 medium | 1.2% | 2020-05-07 |
| CVE-2014-5335 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in innovaphone PBX 10.00 sr11 and earlier allow remote attackers to hijack the authenticati… | Patch early | 6.8 medium | 1.2% | 2014-08-25 |
| CVE-2005-1843 EXP | VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with Version Cue Workspace, allows l… | Patch early | 4.6 medium | 1.2% | 2005-08-24 |
| CVE-2005-2466 EXP | Multiple SQL injection vulnerabilities in the auth_user function in admin.php in OpenBook 1.2.2 allow remote attackers to execute arbitrary SQL comman… | Patch early | 6.4 medium | 1.2% | 2005-12-31 |
| CVE-2006-2209 EXP | Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands via (1) the… | Patch early | 6.4 medium | 1.2% | 2006-05-05 |
| CVE-2007-3693 EXP | Cross-site scripting (XSS) vulnerability in Gobi as of 20070711, built on Helma, allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 1.2% | 2007-07-11 |
| CVE-2008-6585 EXP | Cross-site request forgery (CSRF) vulnerability in html/admin.php in TorrentFlux 2.3 allows remote attackers to hijack the authentication of administr… | Patch early | 6.8 medium | 1.2% | 2009-04-03 |
| CVE-2006-1676 EXP | SQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other versions befo… | Patch early | 6.4 medium | 1.2% | 2006-04-11 |
| CVE-2012-1224 EXP | Cross-site scripting (XSS) vulnerability in system/classes/login.php in ContentLion Alpha 1.3 allows remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 1.2% | 2012-02-21 |
| CVE-2006-2032 EXP | Multiple SQL injection vulnerabilities in Core CoreNews 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) icon_id… | Patch early | 6.4 medium | 1.2% | 2006-04-26 |
| CVE-2008-3186 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blog (Blogger) allow remote attackers to inject arbitrary web script or HTML via the m… | Patch early | 4.3 medium | 1.2% | 2008-07-15 |
| CVE-2003-0358 EXP | Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileg… | Patch early | 4.6 medium | 1.2% | 2003-06-09 |
| CVE-2006-0801 EXP | SQL injection vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is off, allows remote attackers to execut… | Patch early | 5.1 medium | 1.2% | 2006-02-20 |
| CVE-2024-50857 EXP | The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and enables CSRF attacks. The vulner… | Patch early | 4.8 medium | 1.2% | 2025-01-14 |
| CVE-2008-0676 EXP | Cross-site scripting (XSS) vulnerability in search.php in A-Blog 2 allows remote attackers to inject arbitrary web script or HTML via the words parame… | Patch early | 4.3 medium | 1.2% | 2008-02-12 |
| CVE-2008-2980 EXP | Multiple cross-site scripting (XSS) vulnerabilities in HomePH Design 2.10 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1… | Patch early | 4.3 medium | 1.2% | 2008-07-02 |
| CVE-2008-5889 EXP | Cross-site scripting (XSS) vulnerability in user.asp in Click&Rank allows remote attackers to inject arbitrary web script or HTML via the action param… | Patch early | 4.3 medium | 1.2% | 2009-01-12 |
| CVE-2008-6004 EXP | Cross-site scripting (XSS) vulnerability in search.php in AJ Auction Pro Platinum 2 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.2% | 2009-01-28 |
| CVE-2009-2127 EXP | Cross-site scripting (XSS) vulnerability in show_activity.php in Elvin 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the id… | Patch early | 4.3 medium | 1.2% | 2009-06-19 |
| CVE-2009-2219 EXP | Multiple cross-site scripting (XSS) vulnerabilities in phpCollegeExchange 0.1.5c allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.2% | 2009-06-25 |
| CVE-2007-4075 EXP | Cross-site scripting (XSS) vulnerability in index.asp in Alisveris Sitesi Scripti allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.2% | 2007-07-30 |
| CVE-2009-2920 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Elvin 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) component… | Patch early | 4.3 medium | 1.2% | 2009-08-21 |
| CVE-2009-2928 EXP | Cross-site scripting (XSS) vulnerability in login.php in TGS Content Management 0.x allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.2% | 2009-08-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt