CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,887 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-2321 EXP | Cross-site scripting (XSS) vulnerability in (1) showcat.php and (2) addyoursite.php in phpLinkat 0.1.0 allows remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 1.6% | 2002-12-31 |
| CVE-2007-1151 EXP | Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter to the top… | Patch early | 4.3 medium | 1.6% | 2007-03-02 |
| CVE-2024-46528 EXP | An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x before 4.1… | Patch early | 4.3 medium | 1.6% | 2024-10-14 |
| CVE-2006-6733 EXP | Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 1.6% | 2006-12-26 |
| CVE-2008-1463 EXP | Cross-site scripting (XSS) vulnerability in the management GUI in Imperva SecureSphere MX Management Server 5.0 allows remote attackers to inject arbi… | Patch early | 4.3 medium | 1.6% | 2008-03-24 |
| CVE-2017-16781 EXP | The installer in MyBB before 1.8.13 has XSS. | Patch early | 5.4 medium | 1.6% | 2017-11-10 |
| CVE-2018-5263 EXP | The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS. | Patch early | 5.4 medium | 1.6% | 2018-01-08 |
| CVE-2019-13493 EXP | In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded fi… | Patch early | 5.4 medium | 1.6% | 2019-07-17 |
| CVE-2019-15814 EXP | Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or HTML. | Patch early | 5.4 medium | 1.6% | 2019-09-04 |
| CVE-2008-1726 EXP | Multiple SQL injection vulnerabilities in KnowledgeQuest 2.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL comma… | Patch early | 6.8 medium | 1.6% | 2008-04-11 |
| CVE-2008-6985 EXP | Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magic_quotes_gpc is disabled, allo… | Patch early | 6.8 medium | 1.6% | 2009-08-19 |
| CVE-2018-10259 EXP | An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user. | Patch early | 5.4 medium | 1.6% | 2018-05-01 |
| CVE-2021-22557 EXP | SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Generat… | Patch early | 5.3 medium | 1.6% | 2021-10-04 |
| CVE-2018-6190 EXP | Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page. | Patch early | 5.4 medium | 1.6% | 2018-01-24 |
| CVE-2016-8769 EXP | Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service que… | Patch early | 6.7 medium | 1.6% | 2017-04-02 |
| CVE-2004-2134 EXP | Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the passwords. | Patch early | 4.6 medium | 1.6% | 2004-01-28 |
| CVE-2007-0982 EXP | Cross-site scripting (XSS) vulnerability in error.php in TaskFreak! 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the tznMe… | Patch early | 4.3 medium | 1.6% | 2007-02-16 |
| CVE-2007-1433 EXP | Cross-site scripting (XSS) vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 1.6% | 2007-03-13 |
| CVE-2009-2218 EXP | Multiple PHP remote file inclusion vulnerabilities in phpCollegeExchange 0.1.5c, when register_globals is enabled, allow remote attackers to execute a… | Patch early | 6.8 medium | 1.6% | 2009-06-25 |
| CVE-2018-6226 EXP | Reflected cross-site scripting (XSS) vulnerabilities in two Trend Micro Email Encryption Gateway 5.5 configuration files could allow an attacker to in… | Patch early | 5.4 medium | 1.6% | 2018-03-15 |
| CVE-2018-6227 EXP | A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject client-side scripts in… | Patch early | 5.4 medium | 1.6% | 2018-03-15 |
| CVE-2021-28935 EXP | CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field. | Patch early | 5.4 medium | 1.6% | 2021-03-30 |
| CVE-2022-25630 EXP | An authenticated user can embed malicious content with XSS into the admin group policy page. | Patch early | 5.4 medium | 1.6% | 2022-12-09 |
| CVE-2009-3359 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1)… | Patch early | 4.3 medium | 1.6% | 2009-09-24 |
| CVE-2007-1482 EXP | Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script or HTML via the e_id parameter… | Patch early | 4.3 medium | 1.6% | 2007-03-16 |
| CVE-2007-3291 EXP | Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via an article name… | Patch early | 4.3 medium | 1.6% | 2007-06-20 |
| CVE-2007-6479 EXP | Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows… | Patch early | 4.9 medium | 1.6% | 2007-12-20 |
| CVE-2008-2048 EXP | Cross-site scripting (XSS) vulnerability in hpz/admin/Default.asp in Angelo-Emlak 1.0 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 1.6% | 2008-05-01 |
| CVE-2008-2181 EXP | Multiple cross-site scripting (XSS) vulnerabilities in search.php in cpLinks 1.03 allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 1.6% | 2008-05-13 |
| CVE-2008-2644 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SMEWeb 1.4b and 1.4f allow remote attackers to inject arbitrary web script or HTML via the (1)… | Patch early | 4.3 medium | 1.6% | 2008-06-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt