CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,593 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
207,238 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-44916 EXP | Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routin… | Patch early | 6.1 medium | 3.7% | 2021-12-20 |
| CVE-2019-9554 EXP | In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new U… | Patch early | 6.1 medium | 3.7% | 2019-12-31 |
| CVE-2007-6752 EXP | Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for… | Patch early | 6.8 medium | 3.7% | 2012-03-28 |
| CVE-2007-0298 EXP | PHP remote file inclusion vulnerability in show.php in LunarPoll, when register_globals is enabled, allows remote attackers to execute arbitrary PHP c… | Patch early | 6.8 medium | 3.7% | 2007-01-17 |
| CVE-2013-2684 EXP | Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecifie… | Patch early | 6.1 medium | 3.7% | 2020-02-06 |
| CVE-2007-1149 EXP | Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the step paramete… | Patch early | 5.0 medium | 3.7% | 2007-03-02 |
| CVE-2006-2410 EXP | raydium_network_netcall_exec function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to cause a denial of service (appli… | Patch early | 5.0 medium | 3.7% | 2006-05-16 |
| CVE-2006-2412 EXP | The raydium_network_read function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to cause a denial of service (applicati… | Patch early | 5.0 medium | 3.7% | 2006-05-16 |
| CVE-2018-20418 EXP | index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab. | Patch early | 4.8 medium | 3.7% | 2018-12-24 |
| CVE-2005-1480 EXP | Directory traversal vulnerability in RaidenFTPD before 2.4.2241 allows remote attackers to read arbitrary files via a "..\\" (dot dot backslash) in th… | Patch early | 5.0 medium | 3.7% | 2005-05-11 |
| CVE-2015-7346 EXP | SQL injection vulnerability in ZCMS 1.1. | Patch early | 9.8 critical | 3.7% | 2017-06-07 |
| CVE-2014-9558 EXP | Multiple SQL injection vulnerabilities in SmartCMS v.2. | Patch early | 9.8 critical | 3.7% | 2017-08-28 |
| CVE-2017-15974 EXP | tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php. | Patch early | 9.8 critical | 3.7% | 2017-10-29 |
| CVE-2019-6209 EXP | An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixe… | Patch early | 5.5 medium | 3.7% | 2019-03-05 |
| CVE-2005-2479 EXP | Quick 'n Easy FTP Server 3.0 allows remote attackers to cause a denial of service (application crash or CPU consumption) via a long USER command. | Patch early | 5.0 medium | 3.7% | 2005-08-05 |
| CVE-2009-1067 EXP | Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web script or HTML via the x para… | Patch early | 4.3 medium | 3.7% | 2009-03-26 |
| CVE-2011-2841 EXP | Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, which allows remote attackers t… | Patch early | 6.8 medium | 3.7% | 2011-09-19 |
| CVE-2007-6553 EXP | Multiple PHP remote file inclusion vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 6.8 medium | 3.7% | 2007-12-28 |
| CVE-2015-2275 EXP | Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 3.7% | 2015-03-12 |
| CVE-2003-0749 EXP | Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbi… | Patch early | 6.8 medium | 3.7% | 2003-10-20 |
| CVE-2012-2917 EXP | Cross-site scripting (XSS) vulnerability in the Share and Follow plugin 1.80.3 for WordPress allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 3.7% | 2012-05-21 |
| CVE-2005-3236 EXP | Multiple SQL injection vulnerabilities in Cyphor 0.19 allow remote attackers to execute arbitrary SQL and obtain administrative access via (1) the fid… | Patch early | 6.8 medium | 3.7% | 2005-10-14 |
| CVE-2007-0347 EXP | The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users… | Patch early | 4.3 medium | 3.7% | 2007-01-29 |
| CVE-2003-1369 EXP | Buffer overflow in ByteCatcher FTP client 1.04b allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a… | Patch early | 6.8 medium | 3.7% | 2003-12-31 |
| CVE-2011-4045 EXP | Buffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote atta… | Patch early | 4.3 medium | 3.7% | 2012-04-03 |
| CVE-2023-31069 EXP | An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page. | Patch early | 9.8 critical | 3.7% | 2023-09-11 |
| CVE-2002-2192 EXP | Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web script via (1) a Host: header… | Patch early | 4.3 medium | 3.7% | 2002-12-31 |
| CVE-2023-23156 EXP | Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product p… | Patch early | 9.8 critical | 3.7% | 2023-02-27 |
| CVE-2020-14943 EXP | The Firstname and Lastname parameters in Global RADAR BSA Radar 1.6.7234.24750 and earlier are vulnerable to stored cross-site scripting (XSS) via Upd… | Patch early | 5.4 medium | 3.7% | 2020-06-22 |
| CVE-2007-3227 EXP | Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attacker… | Patch early | 4.3 medium | 3.7% | 2007-06-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt