CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,659 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-6442 EXP | Insecure method vulnerability in Sina Inc. DLoader Class ActiveX Control allows remote attackers to overwrite arbitrary files via a URL in the first p… | Patch early | 5.8 medium | 1.8% | 2009-03-09 |
| CVE-2017-11320 EXP | Persistent XSS through the SSID of nearby Wi-Fi devices on Technicolor TC7337 routers 08.89.17.20.00 allows an attacker to cause DNS Poisoning and ste… | Patch early | 6.1 medium | 1.8% | 2017-08-03 |
| CVE-2014-10009 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Stark CRM 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) first_n… | Patch early | 4.3 medium | 1.8% | 2015-01-13 |
| CVE-2021-24272 EXP | The fitness calculators WordPress plugin before 1.9.6 add calculators for Water intake, BMI calculator, protein Intake, and Body Fat and was lacking C… | Patch early | 4.3 medium | 1.8% | 2021-05-05 |
| CVE-2012-5700 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.2f allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.8% | 2014-09-22 |
| CVE-2016-2188 EXP | The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial… | Patch early | 4.6 medium | 1.8% | 2016-05-02 |
| CVE-2007-4314 EXP | pixlie.php in Pixlie 1.7 allows remote attackers to trigger the reading and JPEG image processing of files in a remote directory tree via a URL in the… | Patch early | 6.8 medium | 1.8% | 2007-08-13 |
| CVE-2008-2220 EXP | Multiple PHP remote file inclusion vulnerabilities in Interact Learning Community Environment Interact 2.4.1, when register_globals is enabled, allow… | Patch early | 6.8 medium | 1.8% | 2008-05-14 |
| CVE-2008-2877 EXP | PHP remote file inclusion vulnerability in admin/include/lib.module.php in cmsWorks 2.2 RC4, when register_globals is enabled, allows remote attackers… | Patch early | 6.8 medium | 1.8% | 2008-06-26 |
| CVE-2008-6740 EXP | PHP remote file inclusion vulnerability in html/admin/modules/plugin_admin.php in HoMaP-CMS 0.1 allows remote attackers to execute arbitrary PHP code… | Patch early | 6.8 medium | 1.8% | 2009-04-21 |
| CVE-2008-7073 EXP | PHP remote file inclusion vulnerability in lib/action/rss.php in RSS module 0.1 for Pie Web M{a,e}sher, when register_globals is enabled, allows remot… | Patch early | 6.8 medium | 1.8% | 2009-08-25 |
| CVE-2002-1805 EXP | Cross-site scripting (XSS) vulnerability in DaCode 1.2.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. | Patch early | 4.3 medium | 1.8% | 2002-12-31 |
| CVE-2005-0274 EXP | Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.8% | 2005-01-03 |
| CVE-2005-2163 EXP | Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.8% | 2005-07-06 |
| CVE-2007-5915 EXP | Directory traversal vulnerability in index.php in phphelpdesk 0.6.16 allows remote attackers to include and execute arbitrary local files via a .. (do… | Patch early | 6.8 medium | 1.8% | 2007-11-10 |
| CVE-2007-0763 EXP | Cross-site scripting (XSS) vulnerability in the news comment functionality in F3Site 2.1 and earlier allows remote attackers to inject arbitrary web s… | Patch early | 6.8 medium | 1.8% | 2007-02-06 |
| CVE-2018-11332 EXP | Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remot… | Patch early | 4.8 medium | 1.8% | 2018-05-24 |
| CVE-2007-1506 EXP | Cross-site scripting (XSS) vulnerability in PORTAL.wwv_main.render_warning_screen in the Oracle Portal 10g allows remote attackers to inject arbitrary… | Patch early | 4.3 medium | 1.8% | 2007-03-19 |
| CVE-2007-3553 EXP | Cross-site scripting (XSS) vulnerability in Rapid Install Web Server in Oracle Application Server 11i allows remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 1.8% | 2007-07-03 |
| CVE-2004-1499 EXP | Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web scrip… | Patch early | 4.3 medium | 1.8% | 2004-12-31 |
| CVE-2004-1872 EXP | Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web script or HTML via the @impor… | Patch early | 4.3 medium | 1.8% | 2004-03-29 |
| CVE-2004-1935 EXP | Cross-site scripting (XSS) vulnerability in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via onload, onmouseover… | Patch early | 4.3 medium | 1.8% | 2004-04-15 |
| CVE-2004-2096 EXP | Cross-site scripting (XSS) vulnerability in Mephistoles httpd 0.6.0 final allows remote attackers to execute arbitrary script as other users by inject… | Patch early | 4.3 medium | 1.8% | 2004-12-31 |
| CVE-2015-2999 EXP | Multiple SQL injection vulnerabilities in SysAid Help Desk before 15.2 allow remote administrators to execute arbitrary SQL commands via the (1) group… | Patch early | 6.5 medium | 1.8% | 2015-06-08 |
| CVE-2006-1613 EXP | Multiple SQL injection vulnerabilities in aWebNews 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user123 variable in (a) lo… | Patch early | 5.0 medium | 1.8% | 2006-04-04 |
| CVE-2010-4513 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Zimplit CMS 3.0, and possibly earlier, allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.8% | 2010-12-09 |
| CVE-2010-4693 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Coppermine Photo Gallery 1.5.10 and earlier allow remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 1.8% | 2011-01-11 |
| CVE-2007-3517 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO… | Patch early | 4.3 medium | 1.8% | 2007-07-03 |
| CVE-2009-0541 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitrary web script or HTML via (1)… | Patch early | 4.3 medium | 1.8% | 2009-02-25 |
| CVE-2009-3360 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Datemill 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) return p… | Patch early | 4.3 medium | 1.8% | 2009-09-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt