CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,557 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-5600 EXP | Incomplete blacklist vulnerability in index.php in Artmedic CMS 3.4 and earlier allows remote attackers to execute arbitrary PHP code via a (1) UNC sh… | Patch early | 6.8 medium | 1.9% | 2007-10-19 |
| CVE-2006-3904 EXP | SQL injection vulnerability in manager/index.php in Etomite CMS 0.6.1 and earlier, with magic_quotes_gpc disabled, allows remote attackers to execute… | Patch early | 6.8 medium | 1.9% | 2006-07-27 |
| CVE-2006-1404 EXP | Multiple cross-site scripting (XSS) vulnerabilities in bol.cgi in BlankOL 1.0 and earlier allow remote attackers to inject arbitrary web script or HTM… | Patch early | 5.8 medium | 1.9% | 2006-03-28 |
| CVE-2020-8825 EXP | index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS. | Patch early | 5.4 medium | 1.9% | 2020-02-10 |
| CVE-2006-0480 EXP | Cross-site scripting (XSS) vulnerability in the Articles module in sPaiz-Nuke allows remote attackers to inject arbitrary web script or HTML via the q… | Patch early | 4.3 medium | 1.9% | 2006-01-31 |
| CVE-2004-2064 EXP | Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web script via the (1) Email or (2) W… | Patch early | 4.3 medium | 1.9% | 2004-07-29 |
| CVE-2005-4075 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in CF_Nuke 4.6 and earlier allow remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 1.9% | 2005-12-08 |
| CVE-2005-4381 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Caravel CMS 3.0 Beta 1 and earlier allow remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 1.9% | 2005-12-20 |
| CVE-2015-5594 EXP | The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attack… | Patch early | 6.1 medium | 1.9% | 2017-07-25 |
| CVE-2021-45783 EXP | Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information. | Patch early | 4.6 medium | 1.9% | 2022-05-05 |
| CVE-2024-53586 EXP | An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injectin… | Patch early | 5.3 medium | 1.9% | 2025-02-06 |
| CVE-2024-12344 EXP | A vulnerability, which was classified as critical, was found in TP-Link VN020 F3v(T) TT_V6.2.1021. This affects an unknown part of the component FTP U… | Patch early | 6.3 medium | 1.9% | 2024-12-08 |
| CVE-2021-28417 EXP | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name" parameter. | Patch early | 4.8 medium | 1.9% | 2021-03-18 |
| CVE-2021-28418 EXP | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category" parameter. | Patch early | 4.8 medium | 1.9% | 2021-03-18 |
| CVE-2007-2011 EXP | Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the username… | Patch early | 4.3 medium | 1.9% | 2007-04-12 |
| CVE-2003-1151 EXP | Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrary web script or HTML via the U… | Patch early | 4.3 medium | 1.9% | 2003-10-28 |
| CVE-2009-3948 EXP | JetAudio 7.5.3 COWON Media Center allows remote attackers to cause a denial of service (memory consumption and application crash) via a long string at… | Patch early | 4.3 medium | 1.9% | 2009-11-16 |
| CVE-2009-4659 EXP | Unspecified vulnerability in MP3-Cutter Ease Audio Cutter 1.20 allows user-assisted remote attackers to cause a denial of service (application crash)… | Patch early | 4.3 medium | 1.9% | 2010-03-03 |
| CVE-2007-3267 EXP | Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.01b and earlier allows remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 1.9% | 2007-06-19 |
| CVE-2006-6022 EXP | Cross-site scripting (XSS) vulnerability in login_form.asp in BestWebApp Dating Site allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 6.8 medium | 1.9% | 2006-11-21 |
| CVE-2006-6118 EXP | Cross-site scripting (XSS) vulnerability in thumbs.php in mmgallery 1.55 allows remote attackers to inject arbitrary web script or HTML via the page p… | Patch early | 6.8 medium | 1.9% | 2006-11-26 |
| CVE-2006-6571 EXP | Multiple cross-site scripting (XSS) vulnerabilities in form.php in GenesisTrader 1.0 allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 6.8 medium | 1.9% | 2006-12-15 |
| CVE-2018-11124 EXP | Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject ar… | Patch early | 5.4 medium | 1.9% | 2018-07-06 |
| CVE-2006-2079 EXP | Cross-site scripting (XSS) vulnerability in portfolio.php in Verosky Media Instant Photo Gallery, possibly before 1.0.2, allows remote attackers to in… | Patch early | 4.3 medium | 1.9% | 2006-04-27 |
| CVE-2006-2208 EXP | Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php in MyNews 1.6.2 allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.9% | 2006-05-05 |
| CVE-2012-4251 EXP | Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML via the (1) pa… | Patch early | 4.3 medium | 1.9% | 2012-08-13 |
| CVE-2008-4320 EXP | Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.5.94 allow remote attackers to inject arbitrary web script or HTML via (1) the… | Patch early | 4.3 medium | 1.9% | 2008-09-29 |
| CVE-2015-5399 EXP | Cross-site scripting (XSS) vulnerability in PHPVibe before 4.21 allows remote authenticated users to inject arbitrary web script or HTML via a comment… | Patch early | 5.4 medium | 1.9% | 2016-08-26 |
| CVE-2009-4690 EXP | Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Programs Rating Script allow remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 1.9% | 2010-03-10 |
| CVE-2007-3448 EXP | Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.9% | 2007-06-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt