CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,659 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-4111 EXP | Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.1.3712 allows remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 1.8% | 2010-12-22 |
| CVE-2007-3137 EXP | Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in WmsCMS 2.0 and earlier allow remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 1.8% | 2007-06-08 |
| CVE-2010-0415 EXP | The do_pages_move function in mm/migrate.c in the Linux kernel before 2.6.33-rc7 does not validate node values, which allows local users to read arbit… | Patch early | 4.6 medium | 1.8% | 2010-02-17 |
| CVE-2012-0988 EXP | Multiple cross-site scripting (XSS) vulnerabilities in config/dmsDefaults.php in KnowledgeTree 3.7.0.2 and possibly earlier allow remote attackers to… | Patch early | 4.3 medium | 1.8% | 2012-09-20 |
| CVE-2012-5102 EXP | Cross-site scripting (XSS) vulnerability in inc/extensions.php in VertrigoServ 2.25 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.8% | 2012-09-23 |
| CVE-2008-1556 EXP | Multiple cross-site scripting (XSS) vulnerabilities in BolinOS 4.6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url par… | Patch early | 4.3 medium | 1.8% | 2008-03-31 |
| CVE-2008-4876 EXP | Cross-site scripting (XSS) vulnerability in the web server component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 all… | Patch early | 4.3 medium | 1.8% | 2008-11-01 |
| CVE-2006-6734 EXP | Cross-site scripting (XSS) vulnerability in modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to… | Patch early | 4.3 medium | 1.8% | 2006-12-26 |
| CVE-2006-2848 EXP | links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct request with a modified txtAdministr… | Patch early | 5.0 medium | 1.8% | 2006-06-06 |
| CVE-2007-3070 EXP | Cross-site scripting (XSS) vulnerability in index.php in BDigital Web Solutions WebStudio allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.8% | 2007-06-06 |
| CVE-2007-3243 EXP | Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the re pa… | Patch early | 4.3 medium | 1.8% | 2007-06-15 |
| CVE-2004-1924 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 1.8% | 2004-04-11 |
| CVE-2010-1342 EXP | Multiple PHP remote file inclusion vulnerabilities in Direct News 4.10.2, when register_globals is enabled, allow remote attackers to execute arbitrar… | Patch early | 6.8 medium | 1.8% | 2010-04-09 |
| CVE-2007-0467 EXP | crashdump in Apple Mac OS X 10.4.8 allows local users in the admin group to modify arbitrary files or gain privileges via a symlink attack on applicat… | Patch early | 6.2 medium | 1.8% | 2007-01-31 |
| CVE-2008-1370 EXP | PHP remote file inclusion vulnerability in index.php in wildmary Yap Blog 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the p… | Patch early | 6.8 medium | 1.8% | 2008-03-18 |
| CVE-2018-10314 EXP | Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted na… | Patch early | 5.4 medium | 1.8% | 2018-05-10 |
| CVE-2015-7515 EXP | The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate attackers to cause a denial of s… | Patch early | 4.6 medium | 1.8% | 2016-04-27 |
| CVE-2006-6366 EXP | Cross-site scripting (XSS) vulnerability in includes/elements/spellcheck/spellwin.php in Cerberus Helpdesk 0.97.3, 2.0 through 2.7, 3.2.1, and 3.3 all… | Patch early | 6.8 medium | 1.8% | 2006-12-07 |
| CVE-2014-10033 EXP | SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote… | Patch early | 6.5 medium | 1.8% | 2015-01-13 |
| CVE-2015-1423 EXP | Multiple SQL injection vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote administrators to execute arbitrary SQL commands via the (1) jak_delete_l… | Patch early | 6.5 medium | 1.8% | 2015-01-29 |
| CVE-2017-15727 EXP | In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment. | Patch early | 5.4 medium | 1.8% | 2017-10-22 |
| CVE-2007-2962 EXP | Cross-site scripting (XSS) vulnerability in search.php in Particle Gallery 1.0.1 and earlier allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.8% | 2007-05-31 |
| CVE-2007-0567 EXP | Cross-site scripting (XSS) vulnerability in admin.php in Interactive-Scripts.Com PHP Membership Manager 1.5 allows remote attackers to inject arbitrar… | Patch early | 6.8 medium | 1.8% | 2007-01-30 |
| CVE-2016-3136 EXP | The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a… | Patch early | 4.6 medium | 1.8% | 2016-05-02 |
| CVE-2018-19750 EXP | DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Domain Fields. | Patch early | 5.4 medium | 1.8% | 2018-11-29 |
| CVE-2009-3234 EXP | Buffer overflow in the perf_copy_attr function in kernel/perf_counter.c in the Linux kernel 2.6.31-rc1 allows local users to cause a denial of service… | Patch early | 4.9 medium | 1.8% | 2009-09-17 |
| CVE-2012-5225 EXP | Cross-site scripting (XSS) vulnerability in webscr.php in xClick Cart 1.0.1 and 1.0.2 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 1.8% | 2012-10-01 |
| CVE-2017-8838 EXP | XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-… | Patch early | 6.1 medium | 1.8% | 2017-06-05 |
| CVE-2009-4658 EXP | Xerver 4.32 allows remote authenticated users to cause a denial of service (daemon crash) via a non-numeric web port assignment in the management inte… | Patch early | 4.0 medium | 1.8% | 2010-03-03 |
| CVE-2012-5193 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 6.1 medium | 1.8% | 2019-11-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt