CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,696 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-5370 EXP | Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/dnewsweb.exe in NetWin DNewsWeb (DNews News Server) 57e1 allow remote attackers to inje… | Patch early | 4.3 medium | 1.8% | 2007-10-11 |
| CVE-2023-0938 EXP | A vulnerability classified as critical has been found in SourceCodester Music Gallery Site 1.0. This affects an unknown part of the file music_list.ph… | Patch early | 6.3 medium | 1.8% | 2023-02-21 |
| CVE-2012-1787 EXP | Multiple cross-site scripting (XSS) vulnerabilities in wgarcmin.cgi in Webglimpse 2.20.0 and earlier allow remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 1.8% | 2012-03-19 |
| CVE-2012-2903 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 7.0 and earlier allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.8% | 2012-05-21 |
| CVE-2005-1895 EXP | Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or back param… | Patch early | 4.3 medium | 1.8% | 2005-06-09 |
| CVE-2012-5992 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow remote attacke… | Patch early | 6.8 medium | 1.8% | 2012-12-19 |
| CVE-2013-5094 EXP | Cross-site scripting (XSS) vulnerability in index.exp in McAfee Vulnerability Manager 7.5 allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.8% | 2014-01-28 |
| CVE-2013-7316 EXP | Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versions before 6.5.0 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.8% | 2014-01-24 |
| CVE-2005-0883 EXP | Multiple cross-site scripting (XSS) vulnerabilities in base.php for DigitalHive 2.0 allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.8% | 2005-03-23 |
| CVE-2005-2638 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.8% | 2005-08-23 |
| CVE-2005-3991 EXP | Multiple cross-site scripting (XSS) vulnerabilities in phpMyChat 0.14.6 allow remote attackers to inject arbitrary web script or HTML via the medium p… | Patch early | 4.3 medium | 1.8% | 2005-12-04 |
| CVE-2005-4333 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Binary Board System (BBS) 0.2.5 and earlier allow remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 1.8% | 2005-12-17 |
| CVE-2016-9111 EXP | Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physi… | Patch early | 6.8 medium | 1.8% | 2016-11-07 |
| CVE-2018-9236 EXP | iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field. | Patch early | 5.4 medium | 1.8% | 2018-04-04 |
| CVE-2018-9237 EXP | iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field. | Patch early | 5.4 medium | 1.8% | 2018-04-04 |
| CVE-2009-2120 EXP | Multiple SQL injection vulnerabilities in TekBase All-in-One 3.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) ids pa… | Patch early | 6.5 medium | 1.8% | 2009-06-18 |
| CVE-2024-54761 EXP | BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter. | Patch early | 6.3 medium | 1.8% | 2025-01-09 |
| CVE-2006-1372 EXP | Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID pa… | Patch early | 5.0 medium | 1.8% | 2006-03-24 |
| CVE-2006-7042 EXP | Cross-site scripting (XSS) vulnerability in directory/index.php in Chipmunk directory allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 6.8 medium | 1.8% | 2007-02-24 |
| CVE-2008-5283 EXP | Google Hack Honeypot (GHH) File Upload Manager 1.3 allows remote attackers to delete uploaded files via unknown vectors related to the delall action t… | Patch early | 6.4 medium | 1.8% | 2008-11-29 |
| CVE-2008-0359 EXP | Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO… | Patch early | 4.3 medium | 1.8% | 2008-01-18 |
| CVE-2008-1414 EXP | Cross-site scripting (XSS) vulnerability in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.8% | 2008-03-20 |
| CVE-2008-1991 EXP | Cross-site scripting (XSS) vulnerability in admin_colors_swatch.asp in Acidcat CMS 3.4.1 allows remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 1.8% | 2008-04-27 |
| CVE-2008-4751 EXP | Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the pg… | Patch early | 4.3 medium | 1.8% | 2008-10-27 |
| CVE-2008-6510 EXP | Cross-site scripting (XSS) vulnerability in login.jsp in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to inject arbitrary… | Patch early | 4.3 medium | 1.8% | 2009-03-23 |
| CVE-2010-0703 EXP | Cross-site scripting (XSS) vulnerability in wa/auth in PortWise SSL VPN 4.6 allows remote attackers to inject arbitrary web script or HTML via the rel… | Patch early | 4.3 medium | 1.8% | 2010-02-23 |
| CVE-2010-4631 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ASPilot Pilot Cart 7.3 allow remote attackers to inject arbitrary web script or HTML via the (1… | Patch early | 4.3 medium | 1.8% | 2010-12-30 |
| CVE-2010-4873 EXP | Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via the id pa… | Patch early | 4.3 medium | 1.8% | 2011-10-07 |
| CVE-2010-5010 EXP | Cross-site scripting (XSS) vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.8% | 2011-11-02 |
| CVE-2010-5027 EXP | Cross-site scripting (XSS) vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to inject arbitrary w… | Patch early | 4.3 medium | 1.8% | 2011-11-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt