CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,429 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-4362 EXP | Cross-site scripting (XSS) vulnerability in getad.php in Diesel Paid Mail allows remote attackers to inject arbitrary web script or HTML via the ps pa… | Patch early | 4.3 medium | 1.9% | 2006-08-27 |
| CVE-2013-5028 EXP | SQL injection vulnerability in IT/hardware-list.dll in Kwoksys Kwok Information Server before 2.8.5 allows remote authenticated users to execute arbit… | Patch early | 6.5 medium | 1.9% | 2013-10-11 |
| CVE-2014-3415 EXP | SQL injection vulnerability in Sharetronix before 3.4 allows remote authenticated users to execute arbitrary SQL commands via the invite_users[] param… | Patch early | 6.5 medium | 1.9% | 2014-05-29 |
| CVE-2014-5275 EXP | Multiple SQL injection vulnerabilities in includes/functions.php in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to execute a… | Patch early | 6.5 medium | 1.9% | 2014-10-20 |
| CVE-2010-0713 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote attackers to hijack the authen… | Patch early | 6.8 medium | 1.9% | 2010-02-26 |
| CVE-2016-2184 EXP | The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate… | Patch early | 4.6 medium | 1.9% | 2016-04-27 |
| CVE-2008-1795 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Academic Suite 7.x and earlier, and possibly some 8.0 versions, allow remote attacke… | Patch early | 4.3 medium | 1.9% | 2008-04-15 |
| CVE-2006-1033 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.9% | 2006-03-07 |
| CVE-2004-1911 EXP | Cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) l paramete… | Patch early | 4.3 medium | 1.9% | 2004-12-31 |
| CVE-2007-5231 EXP | Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to upload and… | Patch early | 4.6 medium | 1.9% | 2007-10-05 |
| CVE-2006-2883 EXP | Cross-site scripting (XSS) vulnerability in search.php in Kmita FAQ 1.0 allows remote attackers to inject arbitrary web script or HTML via the q param… | Patch early | 4.3 medium | 1.9% | 2006-06-07 |
| CVE-2006-3476 EXP | Cross-site scripting (XSS) vulnerability in comments.php in PhpWebGallery 1.5.2 and earlier, and possibly 1.6.0, allows remote attackers to inject arb… | Patch early | 4.3 medium | 1.9% | 2006-07-10 |
| CVE-2007-0144 EXP | Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated attackers to inject arb… | Patch early | 6.8 medium | 1.9% | 2007-01-09 |
| CVE-2006-5535 EXP | Multiple cross-site scripting (XSS) vulnerabilities in WebHostManager (WHM) 10.8.0 cPanel 10.9.0 R50 allow remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 1.9% | 2006-10-26 |
| CVE-2007-6624 EXP | Directory traversal vulnerability in printview.php in PNphpBB2 1.2i and earlier allows remote attackers to include and execute arbitrary local files v… | Patch early | 6.8 medium | 1.9% | 2008-01-04 |
| CVE-2009-4047 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PHD Help Desk 1.43 allow remote attackers to inject arbitrary web script or HTML via (1) the PA… | Patch early | 4.3 medium | 1.9% | 2009-11-23 |
| CVE-2011-0512 EXP | SQL injection vulnerability in team.php in the Teams Structure module 3.0 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via… | Patch early | 6.8 medium | 1.9% | 2011-01-20 |
| CVE-2015-5530 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers to hijack the authentication of… | Patch early | 6.8 medium | 1.9% | 2015-07-16 |
| CVE-2008-2488 EXP | admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated users to create new admin acco… | Patch early | 6.5 medium | 1.9% | 2008-05-28 |
| CVE-2009-0452 EXP | Multiple SQL injection vulnerabilities in parents/login.php in Online Grades 3.2.4, when magic_quotes_gpc is disabled, allow remote attackers to execu… | Patch early | 6.8 medium | 1.9% | 2009-02-10 |
| CVE-2009-1741 EXP | Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbi… | Patch early | 6.8 medium | 1.9% | 2009-05-20 |
| CVE-2006-2473 EXP | Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78 allows remote attackers to inject arbitrary web script or HTML via the p parameter… | Patch early | 4.3 medium | 1.9% | 2006-05-19 |
| CVE-2011-0903 EXP | Multiple directory traversal vulnerabilities in AR Web Content Manager (AWCM) 2.2 allow remote attackers to read arbitrary files and possibly have oth… | Patch early | 6.8 medium | 1.9% | 2011-02-07 |
| CVE-2009-2574 EXP | index.php in MiniTwitter 0.2 beta allows remote authenticated users to modify certain options of arbitrary accounts via an opt action. | Patch early | 6.5 medium | 1.9% | 2009-07-22 |
| CVE-2020-14166 EXP | The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remote attackers with project admi… | Patch early | 4.8 medium | 1.9% | 2020-07-01 |
| CVE-2007-3574 EXP | Multiple cross-site scripting (XSS) vulnerabilities in setup.cgi on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.00.06 firmware allow remo… | Patch early | 4.3 medium | 1.9% | 2007-07-05 |
| CVE-2019-17225 EXP | Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue. | Patch early | 5.4 medium | 1.9% | 2019-10-06 |
| CVE-2007-0896 EXP | Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbit… | Patch early | 4.3 medium | 1.9% | 2007-02-13 |
| CVE-2011-5043 EXP | TomatoSoft Free Mp3 Player 1.0 allows remote attackers to cause a denial of service (application crash) via a long string in an MP3 file, possibly a b… | Patch early | 4.3 medium | 1.9% | 2011-12-30 |
| CVE-2014-3778 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in goform/RgDdns in ARRIS (formerly Motorola) SBG901 SURFboard Wireless Cable Modem allow r… | Patch early | 6.8 medium | 1.9% | 2014-06-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt