CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,620 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
206,930 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-3185 EXP | Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6… | Patch early | 4.9 medium | 4.2% | 2012-10-17 |
| CVE-2012-3186 EXP | Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6… | Patch early | 4.9 medium | 4.2% | 2012-10-17 |
| CVE-2011-1524 EXP | Cross-site scripting (XSS) vulnerability in the management login GUI page in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attacker… | Patch early | 4.3 medium | 4.2% | 2011-03-28 |
| CVE-2006-6015 EXP | Buffer overflow in the JavaScript implementation in Safari on Apple Mac OS X 10.4 allows remote attackers to cause a denial of service (application cr… | Patch early | 5.0 medium | 4.2% | 2006-11-21 |
| CVE-2009-4818 EXP | Unrestricted file upload vulnerability in upload.php in PHPSimplicity Simplicity oF Upload 1.3.2 allows remote attackers to execute arbitrary PHP code… | Patch early | 6.8 medium | 4.2% | 2010-04-27 |
| CVE-2014-5194 EXP | Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into settings/c… | Patch early | 6.5 medium | 4.2% | 2014-08-07 |
| CVE-2008-4340 EXP | Google Chrome 0.2.149.29 and 0.2.149.30 allows remote attackers to cause a denial of service (memory consumption) via an HTML document containing a ca… | Patch early | 4.3 medium | 4.2% | 2008-09-30 |
| CVE-2010-3977 EXP | Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers t… | Patch early | 4.3 medium | 4.2% | 2010-11-03 |
| CVE-2004-2444 EXP | Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script or HTML via the action parame… | Patch early | 4.3 medium | 4.2% | 2004-12-31 |
| CVE-2003-0864 EXP | Buffer overflow in m_join in channel.c for IRCnet IRCD 2.10.x to 2.10.3p3 allows remote attackers to cause a denial of service. | Patch early | 5.0 medium | 4.2% | 2003-11-17 |
| CVE-2015-8730 EXP | epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the number of items, wh… | Patch early | 5.5 medium | 4.2% | 2016-01-04 |
| CVE-2005-4576 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the UpdateEngine program in Fatwire UpdateEngine 6.2 and earlier allow remote attackers to inje… | Patch early | 4.3 medium | 4.2% | 2005-12-29 |
| CVE-2012-3508 EXP | Cross-site scripting (XSS) vulnerability in program/lib/washtml.php in Roundcube Webmail 0.8.0 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 4.2% | 2012-08-25 |
| CVE-2006-4450 EXP | usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to t… | Patch early | 5.1 medium | 4.2% | 2006-08-30 |
| CVE-2015-8735 EXP | The get_value function in epan/dissectors/packet-btatt.c in the Bluetooth Attribute (aka BT ATT) dissector in Wireshark 2.0.x before 2.0.1 uses an inc… | Patch early | 5.5 medium | 4.2% | 2016-01-04 |
| CVE-2015-8739 EXP | The ipmi_fmt_udpport function in epan/dissectors/packet-ipmi.c in the IPMI dissector in Wireshark 2.0.x before 2.0.1 improperly attempts to access a p… | Patch early | 5.5 medium | 4.2% | 2016-01-04 |
| CVE-2024-0737 EXP | A vulnerability classified as problematic was found in Xlightftpd Xlight FTP Server 1.1. This vulnerability affects unknown code of the component Logi… | Patch early | 5.3 medium | 4.2% | 2024-01-19 |
| CVE-2005-3966 EXP | Cross-site scripting (XSS) vulnerability in search.jsp in Java Search Engine (JSE) 0.9.34 allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 4.2% | 2005-12-03 |
| CVE-2012-2582 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.13, 3.0.x before 3.0.15, and 3.1.x… | Patch early | 4.3 medium | 4.2% | 2012-08-23 |
| CVE-2009-3457 EXP | Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP reque… | Patch early | 5.0 medium | 4.2% | 2009-09-29 |
| CVE-2008-0838 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface in Sophos ES1000 and ES4000 Email Security Appliance 2.1.0.0 a… | Patch early | 4.3 medium | 4.2% | 2008-02-20 |
| CVE-2024-53584 EXP | OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter. | Patch early | 9.8 critical | 4.2% | 2025-01-31 |
| CVE-2013-3241 EXP | export.php (aka the export script) in phpMyAdmin 4.x before 4.0.0-rc3 overwrites global variables on the basis of the contents of the POST superglobal… | Patch early | 4.0 medium | 4.2% | 2013-04-26 |
| CVE-2014-4873 EXP | SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL commands… | Patch early | 6.5 medium | 4.2% | 2014-10-10 |
| CVE-2009-2177 EXP | code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to conduct directory traversal attac… | Patch early | 6.8 medium | 4.2% | 2009-06-23 |
| CVE-2006-3793 EXP | PHP remote file inclusion vulnerability in constants.php in SiteDepth CMS 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a… | Patch early | 5.1 medium | 4.2% | 2006-07-24 |
| CVE-2015-2218 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the WonderPlugin Audio Player plugin… | Patch early | 4.3 medium | 4.2% | 2015-03-05 |
| CVE-2018-18619 EXP | internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently… | Patch early | 9.8 critical | 4.2% | 2018-11-29 |
| CVE-2002-0908 EXP | Directory traversal vulnerability in the web server for Cisco IDS Device Manager before 3.1.2 allows remote attackers to read arbitrary files via a ..… | Patch early | 5.0 medium | 4.2% | 2002-10-04 |
| CVE-2015-4465 EXP | Cross-site scripting (XSS) vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to inject arbitrary… | Patch early | 4.3 medium | 4.2% | 2015-06-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt