CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,164 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
208,189 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-1915 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to hijack the au… | Patch early | 6.8 medium | 2.5% | 2014-02-07 |
| CVE-2012-3831 EXP | Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.1 allows remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 2.5% | 2012-07-03 |
| CVE-2013-6357 EXP | Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the a… | Patch early | 6.8 medium | 2.5% | 2013-11-13 |
| CVE-2006-1407 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary we… | Patch early | 5.8 medium | 2.5% | 2006-03-28 |
| CVE-2006-1965 EXP | Multiple cross-site scripting (XSS) vulnerabilities in aasi media Net Clubs Pro 4.0 and earlier allow remote attackers to inject arbitrary web script… | Patch early | 5.8 medium | 2.5% | 2006-04-21 |
| CVE-2021-24383 EXP | The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard… | Patch early | 5.4 medium | 2.5% | 2021-06-21 |
| CVE-2012-2578 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SmarterMail 9.2 allow remote attackers to inject arbitrary web script or HTML via an e-mail mes… | Patch early | 4.3 medium | 2.5% | 2012-09-19 |
| CVE-2012-2586 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Mailtraq 2.17.3.3150 allow remote attackers to inject arbitrary web script or HTML via an e-mai… | Patch early | 4.3 medium | 2.5% | 2012-09-19 |
| CVE-2006-1427 EXP | Multiple cross-site scripting (XSS) vulnerabilities in WebAPP 0.9.9.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 2.5% | 2006-03-28 |
| CVE-2014-5100 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the authentication of administrators… | Patch early | 6.8 medium | 2.5% | 2014-07-25 |
| CVE-2017-14620 EXP | SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in Stored Cros… | Patch early | 6.1 medium | 2.5% | 2017-09-30 |
| CVE-2018-9235 EXP | iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php. | Patch early | 6.1 medium | 2.5% | 2018-04-04 |
| CVE-2012-5345 EXP | Buffer overflow in the Remote command server (Rcmd.bat) in IpTools (aka Tiny TCP/IP server) 0.1.4 allows remote attackers to cause a denial of service… | Patch early | 5.0 medium | 2.5% | 2012-10-09 |
| CVE-2021-25680 EXP | The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These issues impact at minimum versi… | Patch early | 6.1 medium | 2.5% | 2021-04-20 |
| CVE-2017-6340 EXP | Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/report/template name field, which a… | Patch early | 5.4 medium | 2.5% | 2017-04-05 |
| CVE-2000-1228 EXP | Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, op… | Patch early | 5.0 medium | 2.5% | 2000-12-31 |
| CVE-1999-1504 EXP | Stalker Internet Mail Server 1.6 allows a remote attacker to cause a denial of service (crash) via a long HELO command. | Patch early | 5.0 medium | 2.5% | 1998-04-08 |
| CVE-1999-1532 EXP | Netscape Messaging Server 3.54, 3.55, and 3.6 allows a remote attacker to cause a denial of service (memory exhaustion) via a series of long RCPT TO c… | Patch early | 5.0 medium | 2.5% | 1999-10-29 |
| CVE-2010-1064 EXP | Erolife AjxGaleri VT stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a dat… | Patch early | 5.0 medium | 2.5% | 2010-03-23 |
| CVE-2010-1066 EXP | AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to d… | Patch early | 5.0 medium | 2.5% | 2010-03-23 |
| CVE-2010-4145 EXP | Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a dat… | Patch early | 5.0 medium | 2.5% | 2010-11-02 |
| CVE-2008-6871 EXP | Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers to obtain unspecified sensitive… | Patch early | 5.0 medium | 2.5% | 2009-07-23 |
| CVE-2008-7056 EXP | BandSite CMS 1.1.4 does not perform access control for adminpanel/phpmydump.php, which allows remote attackers to obtain copies of the database via a… | Patch early | 5.0 medium | 2.5% | 2009-08-24 |
| CVE-2009-0760 EXP | Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a d… | Patch early | 5.0 medium | 2.5% | 2009-03-06 |
| CVE-2006-1760 EXP | Multiple cross-site scripting (XSS) vulnerabilities in JetPhoto allow remote attackers to inject arbitrary web script or HTML via the page parameter i… | Patch early | 4.3 medium | 2.5% | 2006-04-13 |
| CVE-2005-2276 EXP | Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 2.5% | 2005-07-26 |
| CVE-2013-6872 EXP | SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execute arbitrary SQL commands via… | Patch early | 6.5 medium | 2.5% | 2014-01-21 |
| CVE-1999-0838 EXP | Buffer overflow in Serv-U FTP 2.5 allows remote users to conduct a denial of service via the SITE command. | Patch early | 5.0 medium | 2.5% | 1999-12-01 |
| CVE-1999-0991 EXP | Buffer overflow in GoodTech Telnet Server NT allows remote users to cause a denial of service via a long login name. | Patch early | 5.0 medium | 2.5% | 1999-12-06 |
| CVE-2010-3603 EXP | Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.3.4.3 and 2.3.5.1 allows remot… | Patch early | 6.8 medium | 2.5% | 2010-09-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt