CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,367 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
171,268 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-2585 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ServiceDesk Plus 8.1 allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.4% | 2012-08-12 |
| CVE-2012-6587 EXP | Cross-site scripting (XSS) vulnerability in vacation/1_mobile/alert_members.php in MYRE Vacation Rental Software allows remote attackers to inject arb… | Patch early | 4.3 medium | 1.4% | 2013-08-25 |
| CVE-2018-10828 EXP | An issue was discovered in Alps Pointing-device Driver 10.1.101.207. ApMsgFwd.exe allows the current user to map and write to the "ApMsgFwd File Mappi… | Patch early | 5.5 medium | 1.3% | 2018-05-09 |
| CVE-2002-0793 EXP | Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the… | Patch early | 5.5 medium | 1.3% | 2002-08-12 |
| CVE-2012-2573 EXP | Multiple cross-site scripting (XSS) vulnerabilities in T-dah WebMail 3.2.0-2.3 allow remote attackers to inject arbitrary web script or HTML via an e-… | Patch early | 4.3 medium | 1.3% | 2012-08-12 |
| CVE-2013-4624 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.3% | 2013-11-27 |
| CVE-2018-13441 EXP | qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-o… | Patch early | 5.5 medium | 1.3% | 2018-07-12 |
| CVE-2006-0972 EXP | SQL injection vulnerability in news.php in Tony Baird Fantastic News 2.1.1 allows remote attackers to execute arbitrary SQL commands via the page para… | Patch early | 5.0 medium | 1.3% | 2006-03-03 |
| CVE-2006-3011 EXP | The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restricti… | Patch early | 4.6 medium | 1.3% | 2006-06-26 |
| CVE-2008-0540 EXP | Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote attackers to inject arbitrary web script or HTML via the query str… | Patch early | 4.3 medium | 1.3% | 2008-02-01 |
| CVE-2003-1308 EXP | CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary comma… | Patch early | 4.6 medium | 1.3% | 2003-12-31 |
| CVE-2010-0695 EXP | Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web script or HTML via the nav_id… | Patch early | 4.3 medium | 1.3% | 2010-02-23 |
| CVE-2013-4665 EXP | SPBAS Business Automation Software 2012 has CSRF. | Patch early | 6.5 medium | 1.3% | 2019-12-27 |
| CVE-2024-27744 EXP | Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the i… | Patch early | 6.1 medium | 1.3% | 2024-03-01 |
| CVE-2010-5285 EXP | Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the authentication of administrator… | Patch early | 6.8 medium | 1.3% | 2012-11-26 |
| CVE-2011-5196 EXP | Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Systems 2.3.6 and earlier allows… | Patch early | 6.8 medium | 1.3% | 2012-09-23 |
| CVE-2011-5160 EXP | Cross-site scripting (XSS) vulnerability in setup.php in OpenEMR 4 allows remote attackers to inject arbitrary web script or HTML via the site paramet… | Patch early | 4.3 medium | 1.3% | 2012-09-09 |
| CVE-2008-2189 EXP | SQL injection vulnerability in viewfaqs.php in AnServ Auction XL allows remote attackers to execute arbitrary SQL commands via the cat parameter. | Patch early | 6.8 medium | 1.3% | 2008-05-14 |
| CVE-2014-3246 EXP | SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via the folder parameter in a filevi… | Patch early | 6.5 medium | 1.3% | 2014-05-13 |
| CVE-2011-5186 EXP | Cross-site scripting (XSS) vulnerability in jbshop.php in the jbShop plugin for e107 7 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.3% | 2012-09-20 |
| CVE-2018-8815 EXP | Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to inject arbitrary web script or H… | Patch early | 4.6 medium | 1.3% | 2018-03-20 |
| CVE-2006-4250 EXP | Buffer overflow in man and mandb (man-db) 2.4.3 and earlier allows local users to execute arbitrary code via crafted arguments to the -H flag. | Patch early | 4.6 medium | 1.3% | 2007-04-10 |
| CVE-2013-6794 EXP | Cross-site scripting (XSS) vulnerability in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.3% | 2013-11-14 |
| CVE-2013-1646 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow rem… | Patch early | 4.3 medium | 1.3% | 2013-09-05 |
| CVE-2006-5556 EXP | Buffer overflow in the localtime_r function, and certain other functions, in libc in HP-UX B.11.11 and possibly other versions allows local users to e… | Patch early | 4.6 medium | 1.3% | 2006-10-27 |
| CVE-2015-6493 EXP | Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenti… | Patch early | 6.8 medium | 1.3% | 2015-10-28 |
| CVE-2006-4855 EXP | The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, Ant… | Patch early | 4.9 medium | 1.3% | 2006-09-19 |
| CVE-2012-5367 EXP | Multiple SQL injection vulnerabilities in OrangeHRM 2.7.1 RC 1 allow remote authenticated administrators to execute arbitrary SQL commands via the sor… | Patch early | 6.0 medium | 1.3% | 2012-12-03 |
| CVE-2012-4932 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SimpleInvoices before stable-2012-1-CIS3000 allow remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 1.3% | 2012-12-28 |
| CVE-2012-6585 EXP | Cross-site scripting (XSS) vulnerability in search.php in MYRE Realty Manager allows remote attackers to inject arbitrary web script or HTML via the c… | Patch early | 4.3 medium | 1.3% | 2013-08-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt