CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,729 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-6838 EXP | Cross-site scripting (XSS) vulnerability in search.php in Zoph 0.7.2.1 allows remote attackers to inject arbitrary web script or HTML via the _off par… | Patch early | 4.3 medium | 1.8% | 2009-06-27 |
| CVE-2005-1077 EXP | Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web script or HTML via (1) cds.php, (2)… | Patch early | 4.3 medium | 1.8% | 2005-04-12 |
| CVE-2002-2178 EXP | Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary Javascript script via… | Patch early | 4.3 medium | 1.7% | 2002-12-31 |
| CVE-2012-2179 EXP | libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file. | Patch early | 6.9 medium | 1.7% | 2012-06-22 |
| CVE-2006-2374 EXP | The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users t… | Patch early | 5.5 medium | 1.7% | 2006-06-13 |
| CVE-1999-0671 EXP | Buffer overflow in ToxSoft NextFTP client through CWD command. | Patch early | 5.1 medium | 1.7% | 1999-08-03 |
| CVE-2005-4400 EXP | Cross-site scripting (XSS) vulnerability in downloads/portal_ent in Liferay Portal Enterprise 3.6.1 and earlier allows remote attackers to inject arbi… | Patch early | 4.3 medium | 1.7% | 2005-12-20 |
| CVE-2005-4483 EXP | Cross-site scripting (XSS) vulnerability in login.asp in SiteEnable 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.7% | 2005-12-22 |
| CVE-2005-4496 EXP | Cross-site scripting (XSS) vulnerability in search in SyntaxCMS 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.7% | 2005-12-22 |
| CVE-2005-4596 EXP | Cross-site scripting (XSS) vulnerability in read.php in AdesGuestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the total… | Patch early | 4.3 medium | 1.7% | 2005-12-31 |
| CVE-2005-4598 EXP | Cross-site scripting (XSS) vulnerability in home.php in OoApp Guestbook 2.1 allows remote attackers to inject arbitrary web script or HTML via the pag… | Patch early | 4.3 medium | 1.7% | 2005-12-31 |
| CVE-2005-4637 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kayako SupportSuite 3.00.26 and earlier allow remote attackers to inject arbitrary… | Patch early | 4.3 medium | 1.7% | 2005-12-31 |
| CVE-2009-1655 EXP | Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenticated users to execute arbitra… | Patch early | 6.5 medium | 1.7% | 2009-05-16 |
| CVE-2009-1315 EXP | Multiple cross-site scripting (XSS) vulnerabilities in AbleSpace 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) gid par… | Patch early | 4.3 medium | 1.7% | 2009-04-17 |
| CVE-2013-2289 EXP | Cross-site scripting (XSS) vulnerability in admin/templates/default.php in Batavi 1.2.2 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.7% | 2014-03-11 |
| CVE-2010-5048 EXP | Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.1.0.0 for Joomla! allows remot… | Patch early | 4.3 medium | 1.7% | 2011-11-23 |
| CVE-2004-1960 EXP | Cross-site scripting (XSS) vulnerability in blocker_query.php in Protector System 1.15b1 allows remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 1.7% | 2004-12-31 |
| CVE-2005-3919 EXP | Cross-site scripting (XSS) vulnerability in PBLang 4.65 allows remote attackers to inject arbitrary web script or HTML via multiple fields in (1) UCP.… | Patch early | 4.3 medium | 1.7% | 2005-11-30 |
| CVE-2005-4327 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Michael Arndt WebCal 1.11-3.04 allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.7% | 2005-12-17 |
| CVE-2009-2095 EXP | PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when register_globals is enabled, allow… | Patch early | 6.8 medium | 1.7% | 2009-06-17 |
| CVE-2011-5267 EXP | Multiple cross-site scripting (XSS) vulnerabilities in spell-check-savedicts.php in the SpellChecker module in Xinha, as used in WikiWig 5.01 and poss… | Patch early | 4.3 medium | 1.7% | 2013-11-05 |
| CVE-2006-6124 EXP | Cross-site scripting (XSS) vulnerability in SeleniumServer Web Server 1.0 allows remote attackers to inject arbitrary web script or HTML via unspecifi… | Patch early | 6.8 medium | 1.7% | 2006-11-26 |
| CVE-2019-6192 EXP | A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a buffer overflow which could ca… | Patch early | 4.4 medium | 1.7% | 2019-12-10 |
| CVE-2023-0962 EXP | A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been declared as critical. This vulnerability affects unknown code of the f… | Patch early | 6.3 medium | 1.7% | 2023-02-22 |
| CVE-2005-1619 EXP | Multiple cross-site scripting (XSS) vulnerabilities in (1) start_page.css.php3 (aka start-page.css.php3) or (2) style.css.php3 in PHPMyChat 0.14.5 all… | Patch early | 4.3 medium | 1.7% | 2005-05-16 |
| CVE-2011-1670 EXP | Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra Blog Machine 1.84, and possibly earlier versions, allows remote attackers to in… | Patch early | 4.3 medium | 1.7% | 2011-04-10 |
| CVE-2005-2112 EXP | Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.7% | 2005-07-05 |
| CVE-2005-4364 EXP | Cross-site scripting (XSS) vulnerability in index.cfm in Hot Banana Web Content Management Suite 5.3 allows remote attackers to inject arbitrary web s… | Patch early | 5.8 medium | 1.7% | 2005-12-20 |
| CVE-2004-1939 EXP | Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double encoded slashe… | Patch early | 4.3 medium | 1.7% | 2004-04-14 |
| CVE-2005-4361 EXP | Cross-site scripting (XSS) vulnerability in search.html in Magnolia Content Management Suite 2.1 allows remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 1.7% | 2005-12-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt