CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,370 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
171,270 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2001-0565 EXP | Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option. | Patch early | 4.6 medium | 1.3% | 2001-08-14 |
| CVE-2006-1113 EXP | SQL injection vulnerability in podcast.php in Loudblog before 0.42 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Patch early | 5.0 medium | 1.3% | 2006-03-09 |
| CVE-2020-29471 EXP | OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as a malicious code using JavaScr… | Patch early | 4.8 medium | 1.3% | 2020-12-29 |
| CVE-2007-3977 EXP | Cross-site scripting (XSS) vulnerability in bwired allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Patch early | 4.3 medium | 1.3% | 2007-07-25 |
| CVE-2009-2020 EXP | Cross-site scripting (XSS) vulnerability in news_detail.php in Virtue News Manager allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.3% | 2009-06-09 |
| CVE-2009-2149 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Campus Virtual-LMS allow remote attackers to inject arbitrary web script or HTML via the (1) co… | Patch early | 4.3 medium | 1.3% | 2009-06-22 |
| CVE-2009-3506 EXP | Multiple cross-site scripting (XSS) vulnerabilities in CMSphp 0.21 allow remote attackers to inject arbitrary web script or HTML via the (1) cook_user… | Patch early | 4.3 medium | 1.3% | 2009-10-01 |
| CVE-2009-4984 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Accessories Me PHP Affiliate Script 1.4 allow remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 1.3% | 2010-08-25 |
| CVE-2009-1951 EXP | Cross-site scripting (XSS) vulnerability in index.php in PropertyMax Pro FREE 0.3 allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.3% | 2009-06-05 |
| CVE-2009-3162 EXP | Cross-site scripting (XSS) vulnerability in Multi Website 1.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter… | Patch early | 4.3 medium | 1.3% | 2009-09-10 |
| CVE-2009-3260 EXP | Cross-site scripting (XSS) vulnerability in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTML via the header of the topic… | Patch early | 4.3 medium | 1.3% | 2009-09-18 |
| CVE-2009-3833 EXP | Cross-site scripting (XSS) vulnerability in index.php in TFTgallery 0.13 allows remote attackers to inject arbitrary web script or HTML via the album… | Patch early | 4.3 medium | 1.3% | 2009-11-02 |
| CVE-2009-3901 EXP | Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web script or HTML via the UserGUID pa… | Patch early | 4.3 medium | 1.3% | 2009-11-06 |
| CVE-2009-4234 EXP | Cross-site scripting (XSS) vulnerability in loginpages/error_user.shtml on the Micronet Network Access Controller SP1910 allows remote attackers to in… | Patch early | 4.3 medium | 1.3% | 2009-12-08 |
| CVE-2009-4858 EXP | Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 1.3% | 2010-05-11 |
| CVE-2009-4868 EXP | Cross-site scripting (XSS) vulnerability in Hitron Soft Answer Me 1.0 allows remote attackers to inject arbitrary web script or HTML via the q_id para… | Patch early | 4.3 medium | 1.3% | 2010-05-11 |
| CVE-2009-4991 EXP | Cross-site scripting (XSS) vulnerability in users/resume_register.php in Omnistar Recruiting allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.3% | 2010-08-25 |
| CVE-2010-1112 EXP | Cross-site scripting (XSS) vulnerability in cat.php in KloNews 2.0 allows remote attackers to inject arbitrary web script or HTML via the cat paramete… | Patch early | 4.3 medium | 1.3% | 2010-03-25 |
| CVE-2012-5377 EXP | Untrusted search path vulnerability in the installation functionality in ActivePerl 5.16.1.1601, when installed in the top-level C:\ directory, allows… | Patch early | 6.0 medium | 1.3% | 2012-10-11 |
| CVE-2002-2087 EXP | Buffer overflow in Borland InterBase 6.0 allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_d… | Patch early | 4.6 medium | 1.3% | 2002-12-31 |
| CVE-2006-2339 EXP | SQL injection vulnerability in index.php in evoTopsites 2.x and evoTopsites Pro 2.x allows remote attackers to execute arbitrary SQL commands via the… | Patch early | 6.4 medium | 1.3% | 2006-05-12 |
| CVE-2016-1885 EXP | Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1 before p31, and 10.2 before p1… | Patch early | 6.2 medium | 1.3% | 2016-04-12 |
| CVE-2009-2138 EXP | Multiple open redirect vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to redirect users to arbitrary web sites and conduct phishing atta… | Patch early | 4.3 medium | 1.3% | 2009-06-19 |
| CVE-2014-10019 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem allow remot… | Patch early | 6.8 medium | 1.3% | 2015-01-13 |
| CVE-2017-9150 EXP | The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value available for restricting the… | Patch early | 5.5 medium | 1.3% | 2017-05-22 |
| CVE-2002-1602 EXP | Buffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows local users to execute arbitrary code. | Patch early | 4.6 medium | 1.3% | 2002-04-23 |
| CVE-2009-3248 EXP | Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin us… | Patch early | 6.8 medium | 1.3% | 2009-09-18 |
| CVE-2009-1283 EXP | glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privileg… | Patch early | 6.8 medium | 1.3% | 2009-04-09 |
| CVE-2014-0794 EXP | SQL injection vulnerability in the JV Comment (com_jvcomment) component before 3.0.3 for Joomla! allows remote authenticated users to execute arbitrar… | Patch early | 4.3 medium | 1.3% | 2014-01-26 |
| CVE-2009-0672 EXP | SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated administrators to execute arbi… | Patch early | 6.5 medium | 1.3% | 2009-02-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt