CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,074 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2003-1145 EXP | Cross-site scripting (XSS) vulnerability in friendmail.php in OpenAutoClassifieds 1.0 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 6.8 medium | 4.2% | 2003-11-03 |
| CVE-2003-1187 EXP | Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 6.8 medium | 4.2% | 2003-11-02 |
| CVE-2003-1197 EXP | Cross-site scripting (XSS) vulnerability in index.php for Ledscripts.com LedForums Beta 1 allows remote attackers to inject arbitrary web script or HT… | Patch early | 6.8 medium | 4.2% | 2003-10-30 |
| CVE-2004-0301 EXP | Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter. | Patch early | 6.8 medium | 4.2% | 2004-11-23 |
| CVE-2004-0358 EXP | Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1… | Patch early | 6.8 medium | 4.2% | 2004-11-23 |
| CVE-2009-3312 EXP | PHP remote file inclusion vulnerability in php/init.poll.php in phpPollScript 1.3 and earlier, when register_globals is enabled, allows remote attacke… | Patch early | 6.8 medium | 4.2% | 2009-09-23 |
| CVE-2006-3993 EXP | PHP remote file inclusion vulnerability in copyright.php in Olaf Noehring The Search Engine Project (TSEP) 0.942 allows remote attackers to execute ar… | Patch early | 5.1 medium | 4.2% | 2006-08-05 |
| CVE-2002-1703 EXP | Cross-site scripting vulnerability (XSS) in auction.cgi for Mewsoft NetAuction 3.0 allows remote attackers to execute arbitrary script as other users… | Patch early | 6.8 medium | 4.2% | 2002-12-31 |
| CVE-2005-0804 EXP | Format string vulnerability in MailEnable 1.8 allows remote attackers to cause a denial of service (application crash) via format string specifiers in… | Patch early | 5.0 medium | 4.2% | 2005-05-02 |
| CVE-2003-1478 EXP | Konqueror in KDE 3.0.3 allows remote attackers to cause a denial of service (core dump) via a web page that begins with a "xFFxFE" byte sequence and a… | Patch early | 4.3 medium | 4.2% | 2003-12-31 |
| CVE-2009-3271 EXP | Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel: URL in the SRC attribute of a… | Patch early | 4.3 medium | 4.2% | 2009-09-21 |
| CVE-2012-3183 EXP | Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6… | Patch early | 4.9 medium | 4.2% | 2012-10-17 |
| CVE-2012-3185 EXP | Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6… | Patch early | 4.9 medium | 4.2% | 2012-10-17 |
| CVE-2012-3186 EXP | Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6… | Patch early | 4.9 medium | 4.2% | 2012-10-17 |
| CVE-2011-1524 EXP | Cross-site scripting (XSS) vulnerability in the management login GUI page in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attacker… | Patch early | 4.3 medium | 4.2% | 2011-03-28 |
| CVE-2006-6015 EXP | Buffer overflow in the JavaScript implementation in Safari on Apple Mac OS X 10.4 allows remote attackers to cause a denial of service (application cr… | Patch early | 5.0 medium | 4.2% | 2006-11-21 |
| CVE-2009-4818 EXP | Unrestricted file upload vulnerability in upload.php in PHPSimplicity Simplicity oF Upload 1.3.2 allows remote attackers to execute arbitrary PHP code… | Patch early | 6.8 medium | 4.2% | 2010-04-27 |
| CVE-2014-5194 EXP | Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into settings/c… | Patch early | 6.5 medium | 4.2% | 2014-08-07 |
| CVE-2008-4340 EXP | Google Chrome 0.2.149.29 and 0.2.149.30 allows remote attackers to cause a denial of service (memory consumption) via an HTML document containing a ca… | Patch early | 4.3 medium | 4.2% | 2008-09-30 |
| CVE-2010-3977 EXP | Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers t… | Patch early | 4.3 medium | 4.2% | 2010-11-03 |
| CVE-2004-2444 EXP | Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script or HTML via the action parame… | Patch early | 4.3 medium | 4.2% | 2004-12-31 |
| CVE-2003-0864 EXP | Buffer overflow in m_join in channel.c for IRCnet IRCD 2.10.x to 2.10.3p3 allows remote attackers to cause a denial of service. | Patch early | 5.0 medium | 4.2% | 2003-11-17 |
| CVE-2015-8730 EXP | epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the number of items, wh… | Patch early | 5.5 medium | 4.2% | 2016-01-04 |
| CVE-2004-0281 EXP | Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP requ… | Patch early | 5.0 medium | 4.2% | 2004-11-23 |
| CVE-2005-4576 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the UpdateEngine program in Fatwire UpdateEngine 6.2 and earlier allow remote attackers to inje… | Patch early | 4.3 medium | 4.2% | 2005-12-29 |
| CVE-2012-3508 EXP | Cross-site scripting (XSS) vulnerability in program/lib/washtml.php in Roundcube Webmail 0.8.0 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 4.2% | 2012-08-25 |
| CVE-2006-4450 EXP | usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to t… | Patch early | 5.1 medium | 4.2% | 2006-08-30 |
| CVE-2015-8735 EXP | The get_value function in epan/dissectors/packet-btatt.c in the Bluetooth Attribute (aka BT ATT) dissector in Wireshark 2.0.x before 2.0.1 uses an inc… | Patch early | 5.5 medium | 4.2% | 2016-01-04 |
| CVE-2015-8739 EXP | The ipmi_fmt_udpport function in epan/dissectors/packet-ipmi.c in the IPMI dissector in Wireshark 2.0.x before 2.0.1 improperly attempts to access a p… | Patch early | 5.5 medium | 4.2% | 2016-01-04 |
| CVE-2024-0737 EXP | A vulnerability classified as problematic was found in Xlightftpd Xlight FTP Server 1.1. This vulnerability affects unknown code of the component Logi… | Patch early | 5.3 medium | 4.2% | 2024-01-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt