CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,585 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
207,237 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-3607 EXP | Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) v… | Patch early | 5.0 medium | 3.8% | 2007-07-06 |
| CVE-2014-8800 EXP | Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before 1.5.1 for WordPress allows rem… | Patch early | 4.3 medium | 3.8% | 2014-12-05 |
| CVE-2012-3830 EXP | Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.3 allows remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 3.8% | 2012-07-03 |
| CVE-2012-6624 EXP | Cross-site scripting (XSS) vulnerability in the SoundCloud Is Gold plugin 2.1 for WordPress allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 3.8% | 2014-01-16 |
| CVE-2009-3469 EXP | Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows remote attackers to inject arbitrary w… | Patch early | 4.3 medium | 3.7% | 2009-09-29 |
| CVE-2017-11494 EXP | SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user p… | Patch early | 9.8 critical | 3.7% | 2017-08-02 |
| CVE-2008-0919 EXP | Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 and earlier allows remo… | Patch early | 4.3 medium | 3.7% | 2008-02-22 |
| CVE-2014-4963 EXP | Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.customerId parameter to shop/pro… | Patch early | 6.8 medium | 3.7% | 2014-07-15 |
| CVE-2018-10310 EXP | A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Consent plugin before 2.3.10 for Wo… | Patch early | 5.4 medium | 3.7% | 2018-04-25 |
| CVE-2004-1838 EXP | Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the URL. | Patch early | 5.0 medium | 3.7% | 2004-03-22 |
| CVE-2007-2250 EXP | admin.php in Phorum before 5.1.22 allows remote attackers to obtain the full path via the module[] parameter. | Patch early | 5.0 medium | 3.7% | 2007-04-25 |
| CVE-2006-1278 EXP | SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) function… | Patch early | 6.8 medium | 3.7% | 2006-03-19 |
| CVE-2006-2242 EXP | acFTP 1.4 allows remote attackers to cause a denial of service (application crash) via a long string with "{" (brace) characters to the USER command. | Patch early | 5.0 medium | 3.7% | 2006-05-09 |
| CVE-2007-6651 EXP | Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive information (script source code) vi… | Patch early | 5.0 medium | 3.7% | 2008-01-04 |
| CVE-2007-2643 EXP | Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to read arbitrary files via a ..… | Patch early | 5.0 medium | 3.7% | 2007-05-13 |
| CVE-2005-0325 EXP | Xpand Rally 1.0.0.0 allows remote attackers or remote malicious game servers to cause a denial of service (application crash) via a packet with large… | Patch early | 5.0 medium | 3.7% | 2005-05-02 |
| CVE-2008-5749 EXP | Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --rendere… | Patch early | 6.8 medium | 3.7% | 2008-12-29 |
| CVE-2014-9610 EXP | Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP addresses from the… | Patch early | 5.3 medium | 3.7% | 2017-09-19 |
| CVE-2014-3738 EXP | Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the title of a device. | Patch early | 4.3 medium | 3.7% | 2014-05-20 |
| CVE-2015-5066 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 3.7% | 2015-06-24 |
| CVE-2009-4932 EXP | Stack-based buffer overflow in 1by1 1.67 (aka 1.6.7.0) allows remote attackers to cause a denial of service (application crash) or possibly execute ar… | Patch early | 6.8 medium | 3.7% | 2010-07-12 |
| CVE-2012-2579 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the WP SimpleMail plugin 1.0.6 for WordPress allow remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 3.7% | 2014-06-20 |
| CVE-2012-2580 EXP | Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly before 1.5.15, for WordPress allows remote attackers to inject arbit… | Patch early | 4.3 medium | 3.7% | 2014-06-20 |
| CVE-2012-2583 EXP | Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 3.7% | 2014-09-17 |
| CVE-2012-5229 EXP | Cross-site scripting (XSS) vulnerability in css/gallery-css.php in the Slideshow Gallery2 plugin for WordPress allows remote attackers to inject arbit… | Patch early | 4.3 medium | 3.7% | 2012-10-01 |
| CVE-2012-5346 EXP | Cross-site scripting (XSS) vulnerability in wp-live.php in the WP Live.php module 1.2.1 for WordPress allows remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 3.7% | 2012-10-09 |
| CVE-2011-5180 EXP | Cross-site scripting (XSS) vulnerability in wp-1pluginjquery.php in the ZooEffect plugin 1.01 for WordPress allows remote attackers to inject arbitrar… | Patch early | 4.3 medium | 3.7% | 2012-09-20 |
| CVE-2016-3694 EXP | Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-module is not installed, allow remo… | Patch early | 9.8 critical | 3.7% | 2017-02-15 |
| CVE-2007-1678 EXP | Cross-site scripting (XSS) vulnerability in the Fizzle 0.5 extension for Firefox allows remote attackers to inject arbitrary web script or HTML via RS… | Patch early | 4.3 medium | 3.7% | 2007-03-26 |
| CVE-2020-15364 EXP | The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS. | Patch early | 6.1 medium | 3.7% | 2020-06-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt