CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,098 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
169,951 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-4402 EXP | Buffer overflow in MailEnable Professional 1.71 and earlier, and Enterprise 1.1 and earlier, allows remote authenticated users to execute arbitrary co… | Patch early | 6.5 medium | 4.3% | 2005-12-20 |
| CVE-2008-4795 EXP | The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which allows remote attackers to inje… | Patch early | 4.3 medium | 4.3% | 2008-10-30 |
| CVE-2007-5111 EXP | A certain ActiveX control in EBCRYPT.DLL 2.0 in EB Design ebCrypt allows remote attackers to cause a denial of service (crash) via a string argument t… | Patch early | 4.3 medium | 4.3% | 2007-09-26 |
| CVE-2015-8724 EXP | The AirPDcapDecryptWPABroadcastKey function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1… | Patch early | 5.5 medium | 4.3% | 2016-01-04 |
| CVE-2015-8731 EXP | The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 doe… | Patch early | 5.5 medium | 4.3% | 2016-01-04 |
| CVE-2006-7026 EXP | PHP remote file inclusion vulnerability in sources/join.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows remot… | Patch early | 6.8 medium | 4.3% | 2007-02-23 |
| CVE-2017-16884 EXP | Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web script or HTML via vectors related… | Patch early | 6.1 medium | 4.3% | 2017-12-07 |
| CVE-2016-5348 EXP | The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows man-in-… | Patch early | 5.9 medium | 4.3% | 2016-10-10 |
| CVE-2001-1097 EXP | Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets. | Patch early | 5.0 medium | 4.3% | 2001-07-24 |
| CVE-2012-6290 EXP | SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL commands via the q parameter to… | Patch early | 6.5 medium | 4.3% | 2014-03-11 |
| CVE-2013-1408 EXP | Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execut… | Patch early | 6.5 medium | 4.3% | 2014-03-24 |
| CVE-2017-2480 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affect… | Patch early | 6.5 medium | 4.3% | 2017-04-02 |
| CVE-2019-2861 EXP | Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported version that is affected is 11.1.2.… | Patch early | 4.2 medium | 4.3% | 2019-07-23 |
| CVE-2002-1434 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML script as ot… | Patch early | 6.8 medium | 4.3% | 2003-04-11 |
| CVE-2006-2955 EXP | Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice 7.5 and earlier allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 4.3% | 2006-06-12 |
| CVE-2007-0827 EXP | The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that invokes the R… | Patch early | 6.8 medium | 4.3% | 2007-02-07 |
| CVE-2004-0725 EXP | Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 6.8 medium | 4.3% | 2004-07-27 |
| CVE-2010-2544 EXP | Cross-site scripting (XSS) vulnerability in utilities.php in Cacti before 0.8.7g, as used in Red Hat High Performance Computing (HPC) Solution and oth… | Patch early | 4.3 medium | 4.3% | 2010-08-23 |
| CVE-2013-2637 EXP | A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorde… | Patch early | 6.1 medium | 4.3% | 2020-02-12 |
| CVE-2009-1938 EXP | Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecifie… | Patch early | 4.3 medium | 4.3% | 2009-06-05 |
| CVE-2006-6719 EXP | The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause a denial of service (applicati… | Patch early | 5.0 medium | 4.3% | 2006-12-23 |
| CVE-2006-2122 EXP | PHP remote file inclusion vulnerability in index.php in CoolMenus allows remote attackers to execute arbitrary code via a URL in the page parameter.… | Patch early | 6.8 medium | 4.3% | 2006-05-01 |
| CVE-2018-11522 EXP | Yosoro 1.0.4 has stored XSS. | Patch early | 6.1 medium | 4.3% | 2018-06-02 |
| CVE-2012-4231 EXP | Cross-site scripting (XSS) vulnerability in admin/index.php in jCore before 1.0pre2 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 4.3% | 2012-10-22 |
| CVE-2007-3182 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Calendarix 0.7.20070307, when register_globals is enabled, allow remote attackers to inject arb… | Patch early | 4.3 medium | 4.3% | 2007-06-26 |
| CVE-2008-6978 EXP | Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary code by uploading a file with a… | Patch early | 6.8 medium | 4.3% | 2009-08-19 |
| CVE-2000-0984 EXP | The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string. | Patch early | 5.0 medium | 4.3% | 2000-12-19 |
| CVE-2006-3259 EXP | Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) ep paramet… | Patch early | 4.3 medium | 4.3% | 2006-06-27 |
| CVE-2012-5876 EXP | Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to cause a denial of service (cras… | Patch early | 5.0 medium | 4.3% | 2014-05-30 |
| CVE-2011-4958 EXP | Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x before 2.4.6 allows remote at… | Patch early | 4.3 medium | 4.3% | 2014-04-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt