CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,534 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-1095 EXP | Cross-site scripting (XSS) vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.9% | 2005-05-02 |
| CVE-2005-1886 EXP | Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.9% | 2005-06-09 |
| CVE-2005-3685 EXP | Cross-site scripting (XSS) vulnerability in shopadmin.asp in VP-ASP Shopping Cart 5.50 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.9% | 2005-11-19 |
| CVE-2005-4627 EXP | Cross-site scripting (XSS) vulnerability in index.php in (1) GmailSite 1.0 through 1.0.4 and (2) GFHost 0.1.1 through 0.4.2 allows remote attackers to… | Patch early | 4.3 medium | 1.9% | 2005-12-31 |
| CVE-2006-0251 EXP | Cross-site scripting (XSS) vulnerability in fom.cgi in Faq-O-Matic 2.711 allows remote attackers to inject arbitrary web script or HTML via the (1) _d… | Patch early | 4.3 medium | 1.9% | 2006-01-18 |
| CVE-2006-0880 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 allow remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.9% | 2006-02-24 |
| CVE-2006-0974 EXP | Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.9% | 2006-03-03 |
| CVE-2006-1070 EXP | Cross-site scripting (XSS) vulnerability in dv_gbook.php in DVguestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the f p… | Patch early | 4.3 medium | 1.9% | 2006-03-08 |
| CVE-2006-1071 EXP | Cross-site scripting (XSS) vulnerability in index.php in DVguestbook 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the page… | Patch early | 4.3 medium | 1.9% | 2006-03-08 |
| CVE-2006-1080 EXP | Cross-site scripting (XSS) vulnerability in login.php in Game-Panel 2.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 1.9% | 2006-03-09 |
| CVE-2006-1414 EXP | Multiple cross-site scripting (XSS) vulnerabilities in toast.asp in Toast Forums 1.6 and earlier allow remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.9% | 2006-03-28 |
| CVE-2006-1496 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1)… | Patch early | 4.3 medium | 1.9% | 2006-03-30 |
| CVE-2007-6233 EXP | Directory traversal vulnerability in index.php in FTP Admin 0.1.0 allows remote authenticated users to include and execute arbitrary local files via a… | Patch early | 4.9 medium | 1.9% | 2007-12-04 |
| CVE-2005-4374 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Allinta 2.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.9% | 2005-12-20 |
| CVE-2006-5528 EXP | Directory traversal vulnerability in mod.php in SchoolAlumni Portal 2.26 allows remote attackers to include and execute arbitrary local files via a ..… | Patch early | 5.0 medium | 1.9% | 2006-10-26 |
| CVE-2010-1712 EXP | Multiple cross-site scripting (XSS) vulnerabilities in base/Comments.php in Webmobo WB News 2.3.3 allow remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 1.9% | 2010-05-04 |
| CVE-2008-0207 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PRO-Search 0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.9% | 2008-01-10 |
| CVE-2008-7156 EXP | EkinBoard 1.1.0 and earlier, when register_globals is enabled, allows remote attackers to bypass authorization and gain administrator privileges by se… | Patch early | 6.8 medium | 1.9% | 2009-09-02 |
| CVE-2002-1802 EXP | Cross-site scripting (XSS) vulnerability in Xoops 1.0 RC3 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag… | Patch early | 4.3 medium | 1.9% | 2002-12-31 |
| CVE-2008-4075 EXP | Directory traversal vulnerability in index.php in D-iscussion Board 3.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the top… | Patch early | 6.8 medium | 1.9% | 2008-09-15 |
| CVE-2008-4780 EXP | Directory traversal vulnerability in admin/centre.php in MyForum 1.3, when register_globals is enabled, allows remote attackers to include and execute… | Patch early | 6.8 medium | 1.9% | 2008-10-29 |
| CVE-2008-6025 EXP | Directory traversal vulnerability in scr/form.php in openElec 3.01 and earlier allows remote attackers to include and execute arbitrary local files vi… | Patch early | 6.8 medium | 1.9% | 2009-02-03 |
| CVE-2008-2415 EXP | Directory traversal vulnerability in template/purpletech/base_include.php in DigitalHive (aka hive) 2.0 RC2 allows remote attackers to include and exe… | Patch early | 6.8 medium | 1.9% | 2008-05-22 |
| CVE-2008-3312 EXP | Directory traversal vulnerability in lemon_includes/FCKeditor/editor/filemanager/browser/browser.php in Lemon CMS 1.10 allows remote attackers to incl… | Patch early | 6.8 medium | 1.9% | 2008-07-25 |
| CVE-2008-6522 EXP | Multiple directory traversal vulnerabilities in the RenderFile function in ContentRender.class.php in Terracotta (aka OpenTerracotta) 0.6.1, and possi… | Patch early | 6.8 medium | 1.9% | 2009-03-25 |
| CVE-2010-0953 EXP | Directory traversal vulnerability in mod.php in phpCOIN 1.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter. | Patch early | 6.8 medium | 1.9% | 2010-03-10 |
| CVE-2012-4259 EXP | Cross-site scripting (XSS) vulnerability in the contacts in (1) XPhone UC Web and the (2) web frontend for XPhone Virtual Directory in C4B XPhone Unif… | Patch early | 4.3 medium | 1.9% | 2012-08-13 |
| CVE-2006-6197 EXP | Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTM… | Patch early | 6.8 medium | 1.9% | 2006-12-01 |
| CVE-2006-6211 EXP | Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) msg pa… | Patch early | 6.8 medium | 1.9% | 2006-12-01 |
| CVE-2006-6389 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via the (1) Taaa para… | Patch early | 6.8 medium | 1.9% | 2006-12-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt