CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,092 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-5043 EXP | Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for Joomla! allow remote attacker… | Patch early | 6.8 medium | 4% | 2006-09-27 |
| CVE-2013-0807 EXP | Cross-site scripting (XSS) vulnerability in the NewSectionPrompt function in include/tool/editing_page.php in gpEasy CMS 3.5.2 and earlier allows remo… | Patch early | 4.3 medium | 4% | 2014-03-28 |
| CVE-2019-11419 EXP | vcodec2_hls_filter in libvoipCodec_v7a.so in the WeChat application through 7.0.3 for Android allows attackers to cause a denial of service (applicati… | Patch early | 5.5 medium | 4% | 2019-05-14 |
| CVE-2009-4834 EXP | lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibly related to now_connect.php. | Patch early | 6.8 medium | 4% | 2010-05-04 |
| CVE-2010-3272 EXP | accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for re… | Patch early | 4.3 medium | 4% | 2011-02-17 |
| CVE-2019-17220 EXP | Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line. | Patch early | 6.1 medium | 4% | 2019-10-21 |
| CVE-2006-4825 EXP | Multiple cross-site scripting (XSS) vulnerabilities in cl_files/index.php in SoftComplex PHP Event Calendar 1.5.1, and possibly earlier, allow remote… | Patch early | 4.3 medium | 4% | 2006-09-15 |
| CVE-2006-4894 EXP | Cross-site scripting (XSS) vulnerability in forms/lostpassword.php in iDevSpot NixieAffiliate 1.9 and earlier allows remote attackers to inject arbitr… | Patch early | 4.3 medium | 4% | 2006-09-19 |
| CVE-2002-1307 EXP | Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML via an email message with the… | Patch early | 6.8 medium | 4% | 2002-11-29 |
| CVE-2006-4915 EXP | Cross-site scripting (XSS) vulnerability in index.php in Innovate Portal 2.0 allows remote attackers to inject arbitrary web script or HTML via the co… | Patch early | 4.3 medium | 4% | 2006-09-21 |
| CVE-2014-9265 EXP | Stack-based buffer overflow in the BackupToAvi method in the CNC_Ctrl ActiveX control in Samsung SmartViewer allows remote attackers to execute arbitr… | Patch early | 6.8 medium | 4% | 2014-12-08 |
| CVE-2006-1711 EXP | Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword me… | Patch early | 5.0 medium | 4% | 2006-04-11 |
| CVE-2007-5911 EXP | Multiple stack-based buffer overflows in the AxMetaStream ActiveX control in AxMetaStream.dll 3.3.2.26 in Viewpoint Media Player 3.2 allow remote atta… | Patch early | 6.8 medium | 4% | 2007-11-10 |
| CVE-2006-2758 EXP | Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the… | Patch early | 5.0 medium | 4% | 2006-06-02 |
| CVE-2006-0869 EXP | Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and… | Patch early | 6.4 medium | 4% | 2006-02-23 |
| CVE-2006-1128 EXP | Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and… | Patch early | 6.4 medium | 4% | 2006-03-09 |
| CVE-2004-2732 EXP | nbmember.cgi in Netbilling 2.0 allows remote attackers to obtain sensitive information via the cmd=test option, which can be leveraged to determine th… | Patch early | 4.3 medium | 4% | 2004-12-31 |
| CVE-2006-0532 EXP | Cross-site scripting (XSS) vulnerability in resultat.asp in SoftMaker Shop allows remote attackers to inject arbitrary web script or HTML via a strSok… | Patch early | 4.3 medium | 4% | 2006-02-04 |
| CVE-2018-19915 EXP | DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field. | Patch early | 4.8 medium | 4% | 2018-12-06 |
| CVE-2015-2223 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the web-based console management interface in Palo Alto Networks Traps (formerly Cyvera Endpoin… | Patch early | 4.3 medium | 4% | 2015-04-14 |
| CVE-2016-8019 EXP | Cross-site scripting (XSS) vulnerability in attributes in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows unauthenticated… | Patch early | 6.1 medium | 4% | 2017-03-14 |
| CVE-2011-0504 EXP | Multiple cross-site scripting (XSS) vulnerabilities in VaM Shop 1.6, 1.6.1, and probably earlier versions llow remote attackers to inject arbitrary we… | Patch early | 4.3 medium | 4% | 2011-01-20 |
| CVE-2008-2186 EXP | Cross-site scripting (XSS) vulnerability in index.php in Chilek Content Management System (aka ChiCoMaS) 2.0.4 allows remote attackers to inject arbit… | Patch early | 4.3 medium | 4% | 2008-05-13 |
| CVE-2008-2335 EXP | Cross-site scripting (XSS) vulnerability in search_results.php in Vastal I-Tech phpVID 1.1 and 1.2 allows remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 4% | 2008-05-19 |
| CVE-2006-0524 EXP | Cross-site scripting (XSS) vulnerability in ashnews.php in Derek Ashauer ashNews 0.83 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 4% | 2006-02-02 |
| CVE-2004-2522 EXP | Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 4% | 2004-12-31 |
| CVE-2003-1385 EXP | ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_… | Patch early | 6.8 medium | 4% | 2003-12-31 |
| CVE-2013-6492 EXP | The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication… | Patch early | 5.8 medium | 4% | 2014-02-14 |
| CVE-2006-2222 EXP | Buffer overflow in zawhttpd 0.8.23, and possibly previous versions, allows remote attackers to cause a denial of service (daemon crash) via a request… | Patch early | 5.0 medium | 4% | 2006-05-05 |
| CVE-2015-5529 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 4% | 2015-07-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt