CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,208 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-0555 EXP | Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote attackers to execute arbitrar… | Patch early | 6.8 medium | 6.4% | 2015-02-24 |
| CVE-2009-0961 EXP | The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the call approval dialog when another… | Patch early | 5.0 medium | 6.4% | 2009-06-19 |
| CVE-2010-1217 EXP | Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attack… | Patch early | 4.3 medium | 6.4% | 2010-03-30 |
| CVE-2015-3300 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plug… | Patch early | 4.3 medium | 6.4% | 2015-05-14 |
| CVE-2002-0375 EXP | Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript via a URL with the script in t… | Patch early | 5.0 medium | 6.4% | 2002-05-29 |
| CVE-2012-0025 EXP | Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for Irfan… | Patch early | 6.8 medium | 6.4% | 2012-11-02 |
| CVE-2020-15718 EXP | RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could… | Patch early | 6.1 medium | 6.4% | 2020-07-15 |
| CVE-2009-4091 EXP | comments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers to edit or delete comments via… | Patch early | 5.0 medium | 6.4% | 2009-11-29 |
| CVE-2001-1490 EXP | Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images. | Patch early | 5.0 medium | 6.4% | 2001-12-31 |
| CVE-2006-2516 EXP | mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite variables such as $xoopsOption['noc… | Patch early | 5.1 medium | 6.4% | 2006-05-22 |
| CVE-2009-3643 EXP | Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote attackers to cause a denial of service via a long argument to the (1) LIST and (2) NLST comman… | Patch early | 5.0 medium | 6.4% | 2009-10-09 |
| CVE-2013-1463 EXP | Cross-site scripting (XSS) vulnerability in js/tabletools/zeroclipboard.swf in the WP-Table Reloaded module before 1.9.4 for Wordpress allows remote a… | Patch early | 4.3 medium | 6.4% | 2013-02-07 |
| CVE-2019-8927 EXP | An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfi… | Patch early | 6.1 medium | 6.3% | 2019-05-17 |
| CVE-2013-2682 EXP | Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information. | Patch early | 4.3 medium | 6.3% | 2020-02-05 |
| CVE-2006-6847 EXP | An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) b… | Patch early | 5.0 medium | 6.3% | 2006-12-31 |
| CVE-2007-6537 EXP | Stack-based buffer overflow in the zfile_gunzip function in zfile.c in WinUAE 1.4.4 and earlier allows user-assisted remote attackers to execute arbit… | Patch early | 6.8 medium | 6.3% | 2007-12-27 |
| CVE-2009-0572 EXP | PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enab… | Patch early | 5.1 medium | 6.3% | 2009-02-13 |
| CVE-2000-0146 EXP | The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service via a long URL to the servlet… | Patch early | 5.0 medium | 6.3% | 2000-02-07 |
| CVE-2017-2479 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affect… | Patch early | 6.5 medium | 6.3% | 2017-04-02 |
| CVE-2014-3146 EXP | Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) at… | Patch early | 6.1 medium | 6.3% | 2014-05-14 |
| CVE-2013-1402 EXP | DigiLIBE 3.4 and possibly other versions sends a redirect but does not exit, which allows remote attackers to obtain sensitive configuration informati… | Patch early | 5.0 medium | 6.3% | 2013-02-14 |
| CVE-2011-4810 EXP | Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read arbitrary files via the templat… | Patch early | 5.0 medium | 6.3% | 2011-12-14 |
| CVE-2013-1937 EXP | Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inje… | Patch early | 6.1 medium | 6.3% | 2013-04-16 |
| CVE-2008-5919 EXP | Directory traversal vulnerability in rss.php in WebSVN 2.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to overwrite arbitr… | Patch early | 6.8 medium | 6.3% | 2009-01-21 |
| CVE-2022-39195 EXP | A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c p… | Patch early | 6.1 medium | 6.3% | 2023-01-17 |
| CVE-2013-1636 EXP | Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin be… | Patch early | 4.3 medium | 6.3% | 2014-03-12 |
| CVE-2019-8926 EXP | An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp fi… | Patch early | 6.1 medium | 6.3% | 2019-05-17 |
| CVE-2019-8928 EXP | An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp via these GET… | Patch early | 6.1 medium | 6.3% | 2019-05-17 |
| CVE-2014-9598 EXP | The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial… | Patch early | 6.8 medium | 6.3% | 2015-01-21 |
| CVE-2018-1185 EXP | An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint versi… | Patch early | 6.7 medium | 6.3% | 2018-02-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt