CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,984 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
207,508 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-5684 EXP | Cross-site scripting (XSS) vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the inFullnam… | Patch early | 4.3 medium | 3.2% | 2014-08-14 |
| CVE-2011-5283 EXP | Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier… | Patch early | 4.3 medium | 3.2% | 2014-12-31 |
| CVE-2008-0372 EXP | 8e6 R3000 Internet Filter 2.0.05.33, and other versions before 2.0.11, allows remote attackers to bypass intended restrictions via a fragmented HTTP r… | Patch early | 5.0 medium | 3.2% | 2008-01-22 |
| CVE-2015-5999 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2.06.B09_BETA allow remote atta… | Patch early | 6.8 medium | 3.2% | 2015-11-18 |
| CVE-2011-4532 EXP | Absolute path traversal vulnerability in the ALMListView.ALMListCtrl ActiveX control in almaxcx.dll in the graphical user interface in Siemens Automat… | Patch early | 5.0 medium | 3.2% | 2012-01-08 |
| CVE-2007-0548 EXP | KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number of requests for nonexistent obj… | Patch early | 5.0 medium | 3.2% | 2007-01-29 |
| CVE-2018-13045 EXP | SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands v… | Patch early | 9.8 critical | 3.2% | 2019-01-02 |
| CVE-2018-17376 EXP | SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter. | Patch early | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17377 EXP | SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter. | Patch early | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17382 EXP | SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter. | Patch early | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17383 EXP | SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter. | Patch early | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17385 EXP | SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter. | Patch early | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17391 EXP | SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter. | Patch early | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17394 EXP | SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter. | Patch early | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17397 EXP | SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter. | Patch early | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-18763 EXP | SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection. | Patch early | 9.8 critical | 3.2% | 2018-11-16 |
| CVE-2018-18795 EXP | School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter. | Patch early | 9.8 critical | 3.2% | 2018-11-16 |
| CVE-2018-18798 EXP | Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.ph… | Patch early | 9.8 critical | 3.2% | 2019-03-21 |
| CVE-2018-18800 EXP | The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=rooms&q=[SQL], or admin/login.… | Patch early | 9.8 critical | 3.2% | 2019-05-14 |
| CVE-2018-18801 EXP | The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=[SQL]. | Patch early | 9.8 critical | 3.2% | 2018-11-16 |
| CVE-2018-18803 EXP | Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb. | Patch early | 9.8 critical | 3.2% | 2018-11-16 |
| CVE-2018-18804 EXP | Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb. | Patch early | 9.8 critical | 3.2% | 2018-11-16 |
| CVE-2018-18923 EXP | AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and description in action/addproje… | Patch early | 9.8 critical | 3.2% | 2018-12-13 |
| CVE-2019-1010124 EXP | WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in… | Patch early | 5.4 medium | 3.2% | 2019-07-23 |
| CVE-2002-1023 EXP | BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI. | Patch early | 5.0 medium | 3.2% | 2002-10-04 |
| CVE-2002-1029 EXP | Res Manager in Worldspan for Windows Gateway 4.1 allows remote attackers to cause a denial of service (crash) via a malformed request to TCP port 1799… | Patch early | 5.0 medium | 3.2% | 2002-10-04 |
| CVE-2002-1072 EXP | ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented "jolt"… | Patch early | 5.0 medium | 3.2% | 2002-10-04 |
| CVE-1999-1569 EXP | Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood of spoofed… | Patch early | 5.0 medium | 3.2% | 2001-07-17 |
| CVE-2001-0564 EXP | APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial of service v… | Patch early | 5.0 medium | 3.2% | 2001-08-22 |
| CVE-2001-0675 EXP | Rit Research Labs The Bat! 1.51 for Windows allows a remote attacker to cause a denial of service by sending an email to a user's account containing a… | Patch early | 5.0 medium | 3.2% | 2001-09-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt