CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,522 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-3974 EXP | Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3.2% | 2014-06-05 |
| CVE-2014-4166 EXP | Cross-site scripting (XSS) vulnerability in the song history in SHOUTcast DNAS 2.2.1 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 3.2% | 2014-06-16 |
| CVE-2014-4710 EXP | Cross-site scripting (XSS) vulnerability in zero_user_account.php in ZeroCMS 1.0 allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 3.2% | 2014-07-29 |
| CVE-2014-6619 EXP | Multiple cross-site scripting (XSS) vulnerabilities in register-exec.php in Restaurant Script (PizzaInn_Project) 1.0.0 allow remote attackers to injec… | Patch early | 4.3 medium | 3.2% | 2014-09-30 |
| CVE-2014-8469 EXP | Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 3.2% | 2014-11-21 |
| CVE-2014-8954 EXP | Multiple cross-site scripting (XSS) vulnerabilities in phpSound 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Title… | Patch early | 4.3 medium | 3.2% | 2014-11-17 |
| CVE-2014-9142 EXP | Cross-site scripting (XSS) vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 3.2% | 2014-12-05 |
| CVE-2014-9349 EXP | Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 3.2% | 2014-12-08 |
| CVE-2014-9580 EXP | Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) r561 allows remote attackers to inject arbitrary web script or HTML via the De… | Patch early | 4.3 medium | 3.2% | 2015-01-08 |
| CVE-2015-1478 EXP | Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to inject arbitrary web s… | Patch early | 4.3 medium | 3.2% | 2015-02-04 |
| CVE-2008-0372 EXP | 8e6 R3000 Internet Filter 2.0.05.33, and other versions before 2.0.11, allows remote attackers to bypass intended restrictions via a fragmented HTTP r… | Patch early | 5.0 medium | 3.2% | 2008-01-22 |
| CVE-2015-5999 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2.06.B09_BETA allow remote atta… | Patch early | 6.8 medium | 3.2% | 2015-11-18 |
| CVE-2007-0548 EXP | KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number of requests for nonexistent obj… | Patch early | 5.0 medium | 3.2% | 2007-01-29 |
| CVE-2011-4532 EXP | Absolute path traversal vulnerability in the ALMListView.ALMListCtrl ActiveX control in almaxcx.dll in the graphical user interface in Siemens Automat… | Patch early | 5.0 medium | 3.2% | 2012-01-08 |
| CVE-2019-1010124 EXP | WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in… | Patch early | 5.4 medium | 3.2% | 2019-07-23 |
| CVE-1999-1569 EXP | Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood of spoofed… | Patch early | 5.0 medium | 3.2% | 2001-07-17 |
| CVE-2001-0564 EXP | APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial of service v… | Patch early | 5.0 medium | 3.2% | 2001-08-22 |
| CVE-2001-0675 EXP | Rit Research Labs The Bat! 1.51 for Windows allows a remote attacker to cause a denial of service by sending an email to a user's account containing a… | Patch early | 5.0 medium | 3.2% | 2001-09-20 |
| CVE-2002-0431 EXP | XTux allows remote attackers to cause a denial of service (CPU consumption) via random inputs in the initial connection. | Patch early | 5.0 medium | 3.2% | 2002-07-26 |
| CVE-2002-1023 EXP | BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI. | Patch early | 5.0 medium | 3.2% | 2002-10-04 |
| CVE-2002-1029 EXP | Res Manager in Worldspan for Windows Gateway 4.1 allows remote attackers to cause a denial of service (crash) via a malformed request to TCP port 1799… | Patch early | 5.0 medium | 3.2% | 2002-10-04 |
| CVE-2002-1072 EXP | ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented "jolt"… | Patch early | 5.0 medium | 3.2% | 2002-10-04 |
| CVE-2004-2475 EXP | Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the Abou… | Patch early | 4.3 medium | 3.2% | 2004-12-31 |
| CVE-2007-4081 EXP | Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3.2% | 2007-07-30 |
| CVE-2013-6233 EXP | Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Descri… | Patch early | 4.3 medium | 3.2% | 2014-03-09 |
| CVE-2002-1539 EXP | Buffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service via long (1) DELE or (2) UIDL a… | Patch early | 5.0 medium | 3.2% | 2003-03-31 |
| CVE-2004-1878 EXP | LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl pr… | Patch early | 5.0 medium | 3.2% | 2004-03-30 |
| CVE-2010-0641 EXP | Cross-site scripting (XSS) vulnerability in webline/html/admin/wcs/LoginPage.jhtml in Cisco Collaboration Server (CCS) 5 allows remote attackers to in… | Patch early | 4.3 medium | 3.2% | 2010-02-17 |
| CVE-2018-18324 EXP | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter, or the admin/index.php modul… | Patch early | 6.1 medium | 3.2% | 2018-10-15 |
| CVE-2002-1982 EXP | Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine if a directory exists via a ..… | Patch early | 5.0 medium | 3.2% | 2002-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt