CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,984 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
170,623 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-0080 EXP | The ThreadPool class in Windows Vista Gold and SP1, and Server 2008, does not properly implement isolation among a set of distinct processes that (1)… | Patch early | 6.9 medium | 2.4% | 2009-04-15 |
| CVE-2008-3127 EXP | PHP remote file inclusion vulnerability in hioxBannerRotate.php in HIOX Banner Rotator (HBR) 1.3, when register_globals is enabled, allows remote atta… | Patch early | 6.8 medium | 2.4% | 2008-07-10 |
| CVE-2021-24664 EXP | The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them… | Patch early | 4.8 medium | 2.4% | 2021-11-08 |
| CVE-2008-0798 EXP | Multiple directory traversal vulnerabilities in artmedic webdesign weblog 1.0, when magic_quotes_gpc is disabled, allow remote attackers to read arbit… | Patch early | 4.3 medium | 2.4% | 2008-02-15 |
| CVE-2008-3589 EXP | Directory traversal vulnerability in download.php in moziloCMS 1.10.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary fi… | Patch early | 4.3 medium | 2.4% | 2008-08-11 |
| CVE-2007-5120 EXP | Multiple cross-site scripting (XSS) vulnerabilities in JSPWiki 2.4.103 and 2.5.139-beta allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 2.4% | 2007-09-27 |
| CVE-2007-6054 EXP | Cross-site scripting (XSS) vulnerability in the login page in the management interface in the Aruba 800 Mobility Controller 2.5.4.18 and earlier, and… | Patch early | 4.3 medium | 2.4% | 2007-11-20 |
| CVE-2018-11532 EXP | An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field. | Patch early | 6.1 medium | 2.4% | 2018-05-29 |
| CVE-2008-7246 EXP | Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a… | Patch early | 5.0 medium | 2.4% | 2009-09-18 |
| CVE-2009-0321 EXP | Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a l… | Patch early | 4.3 medium | 2.4% | 2009-01-28 |
| CVE-2006-1334 EXP | Multiple SQL injection vulnerabilities in Maian Weblog 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) entry and (2) email pa… | Patch early | 6.4 medium | 2.4% | 2006-03-21 |
| CVE-2013-2559 EXP | SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter to… | Patch early | 6.5 medium | 2.4% | 2014-03-27 |
| CVE-2007-2801 EXP | Multiple cross-site scripting (XSS) vulnerabilities in open.php in eTicket 1.5.5 and 1.5.5.1, when register_globals is enabled, allow remote attackers… | Patch early | 4.3 medium | 2.4% | 2007-06-30 |
| CVE-2012-1507 EXP | Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.7 allow remote attackers to inject arbitrary web script or HTML via the (1)… | Patch early | 4.3 medium | 2.4% | 2014-09-17 |
| CVE-2006-6644 EXP | PHP remote file inclusion vulnerability in pages/meeting_constants.php in the Meeting (mx_meeting) 1.1.2 and earlier module for mxBB allows remote att… | Patch early | 6.8 medium | 2.4% | 2006-12-20 |
| CVE-2006-6650 EXP | PHP remote file inclusion vulnerability in charts_constants.php in the Charts (mx_charts) 1.0.0 and earlier module for mxBB allows remote attackers to… | Patch early | 6.8 medium | 2.4% | 2006-12-20 |
| CVE-2012-4679 EXP | Cross-site scripting (XSS) vulnerability in admin/login.php in Newscoop before 3.5.5 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 2.4% | 2012-08-27 |
| CVE-2010-2336 EXP | index.php in Yamamah Photo Gallery 1.00 allows remote attackers to obtain the source code of executable files within the web document root via the dow… | Patch early | 5.0 medium | 2.4% | 2010-06-18 |
| CVE-2019-3501 EXP | The OUGC Awards plugin before 1.8.19 for MyBB allows XSS via a crafted award reason that is mishandled on the awards page or in a user profile. | Patch early | 4.8 medium | 2.4% | 2019-01-02 |
| CVE-2002-1230 EXP | NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem… | Patch early | 4.6 medium | 2.4% | 2002-11-04 |
| CVE-2008-2198 EXP | PHP remote file inclusion vulnerability in kmitaadmin/kmitat/htmlcode.php in Kmita Tellfriend 2.0 and earlier, when register_globals is enabled, allow… | Patch early | 6.8 medium | 2.4% | 2008-05-14 |
| CVE-2008-5072 EXP | vsfilter.dll in K-Lite Mega Codec Pack 3.5.7.0 allows remote attackers to cause a denial of service (application crash) via a malformed FLV file. | Patch early | 4.3 medium | 2.4% | 2008-11-14 |
| CVE-2008-0357 EXP | Directory traversal vulnerability in pages/upload.php in Galaxyscripts Mini File Host 1.2.1 and earlier allows remote attackers to include and execute… | Patch early | 4.3 medium | 2.4% | 2008-01-18 |
| CVE-2018-7198 EXP | October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page. | Patch early | 6.1 medium | 2.3% | 2018-02-18 |
| CVE-2009-3167 EXP | Directory traversal vulnerability in index.php in Anantasoft Gazelle CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbit… | Patch early | 4.3 medium | 2.3% | 2009-09-11 |
| CVE-2008-4041 EXP | The IMAP server in Softalk Mail Server (formerly WorkgroupMail) 8.5.1.431 allows remote authenticated users to cause a denial of service (resource con… | Patch early | 4.0 medium | 2.3% | 2008-09-11 |
| CVE-2004-2128 EXP | Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as other users via the query string… | Patch early | 6.8 medium | 2.3% | 2004-12-31 |
| CVE-2012-5331 EXP | Directory traversal vulnerability in asaanCart 0.9 allows remote attackers to include arbitrary local files via a .. (dot dot) in the page parameter t… | Patch early | 6.8 medium | 2.3% | 2012-10-08 |
| CVE-2008-4187 EXP | Directory traversal vulnerability in index.php in ProActive CMS allows remote attackers to read arbitrary files via a .. (dot dot) in the template par… | Patch early | 4.3 medium | 2.3% | 2008-09-23 |
| CVE-2009-3823 EXP | Directory traversal vulnerability in myhtml.php in Mobilelib GOLD 3.0, when magic_quotes_gpc is enabled, allows remote attackers to read arbitrary fil… | Patch early | 4.3 medium | 2.3% | 2009-10-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt