CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,959 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-1960 EXP | Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express… | Patch early | 5.8 medium | 5.3% | 2006-04-21 |
| CVE-2023-38357 EXP | Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessions. | Patch early | 5.3 medium | 5.3% | 2023-08-01 |
| CVE-2009-5112 EXP | wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to obtain the installation path via a crafted request. | Patch early | 5.0 medium | 5.3% | 2012-03-19 |
| CVE-2007-6615 EXP | Directory traversal vulnerability in includes/block.php in Agares Media phpAutoVideo 2.21 allows remote attackers to include and execute arbitrary loc… | Patch early | 6.8 medium | 5.3% | 2008-01-03 |
| CVE-2014-3110 EXP | Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe c… | Patch early | 4.3 medium | 5.3% | 2014-07-24 |
| CVE-2009-4092 EXP | Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote attackers to hijack the authentica… | Patch early | 6.8 medium | 5.3% | 2009-11-29 |
| CVE-2013-6627 EXP | net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1xx) status codes, which allows… | Patch early | 5.0 medium | 5.3% | 2013-11-13 |
| CVE-2007-5958 EXP | X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program… | Patch early | 5.0 medium | 5.3% | 2008-01-18 |
| CVE-2018-8729 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote attackers to inject arbitrary J… | Patch early | 6.1 medium | 5.3% | 2018-03-15 |
| CVE-2019-9591 EXP | A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web sc… | Patch early | 6.1 medium | 5.3% | 2019-03-06 |
| CVE-2009-1729 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3 allow remote attackers to inj… | Patch early | 4.3 medium | 5.3% | 2009-05-21 |
| CVE-2012-0895 EXP | Cross-site scripting (XSS) vulnerability in map/map.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to inject arbit… | Patch early | 4.3 medium | 5.3% | 2012-01-20 |
| CVE-2004-2511 EXP | Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 5.3% | 2004-12-31 |
| CVE-2006-1377 EXP | Cross-site scripting (XSS) vulnerability in img.php in (1) EasyMoblog 0.5.1 and (2) CoMoblog 1.1 allows remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 5.3% | 2006-03-24 |
| CVE-2019-6804 EXP | An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascripts/workflowStepEditorKO.js and… | Patch early | 6.1 medium | 5.3% | 2019-01-25 |
| CVE-2023-36306 EXP | A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the ask… | Patch early | 6.1 medium | 5.3% | 2023-08-08 |
| CVE-2012-6506 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.0 for WordPress allow remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 5.3% | 2013-01-24 |
| CVE-1999-1566 EXP | Buffer overflow in iParty server 1.2 and earlier allows remote attackers to cause a denial of service (crash) by connecting to default port 6004 and s… | Patch early | 5.0 medium | 5.3% | 1999-05-08 |
| CVE-2016-5310 EXP | The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud;… | Patch early | 5.5 medium | 5.3% | 2017-04-14 |
| CVE-2009-0464 EXP | PHP remote file inclusion vulnerability in includes/header.php in Groone GBook 2.0 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 5.1 medium | 5.3% | 2009-02-10 |
| CVE-2019-9592 EXP | A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or… | Patch early | 6.1 medium | 5.3% | 2019-03-06 |
| CVE-2019-16118 EXP | Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php. | Patch early | 6.1 medium | 5.3% | 2019-09-08 |
| CVE-2001-0580 EXP | Hughes Technologies Virtual DNS (VDNS) Server 1.0 allows a remote attacker to create a denial of service by connecting to port 6070, sending some data… | Patch early | 5.0 medium | 5.3% | 2001-08-22 |
| CVE-2007-4145 EXP | Heap-based buffer overflow in the BlueSkychat (BlueSkyCat) ActiveX control (V2.V2Ctrl.1) in v2.ocx 8.1.2.0 and earlier allows remote attackers to exec… | Patch early | 4.3 medium | 5.3% | 2007-08-03 |
| CVE-2020-2231 EXP | Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resu… | Patch early | 5.4 medium | 5.3% | 2020-08-12 |
| CVE-2009-0821 EXP | Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print fun… | Patch early | 5.0 medium | 5.3% | 2009-03-05 |
| CVE-2017-6516 EXP | A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow a local attacker to gain elev… | Patch early | 6.7 medium | 5.3% | 2017-03-14 |
| CVE-2000-1085 EXP | The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before c… | Patch early | 4.6 medium | 5.3% | 2001-01-09 |
| CVE-2018-15181 EXP | JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS payload in the SSID name and Securi… | Patch early | 6.5 medium | 5.3% | 2018-08-09 |
| CVE-2009-0981 EXP | Unspecified vulnerability in the Application Express component in Oracle Database 11.1.0.7 allows remote authenticated users to affect confidentiality… | Patch early | 4.0 medium | 5.3% | 2009-04-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt