CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,887 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-3180 EXP | Multiple cross-site scripting (XSS) vulnerabilities in upload/file/language_menu.php in ContentNow CMS 1.4.1 allow remote attackers to inject arbitrar… | Patch early | 4.3 medium | 1.6% | 2008-07-15 |
| CVE-2008-3581 EXP | Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links allows remote attackers to inject arbitrary web script or HTML via the login_me… | Patch early | 4.3 medium | 1.6% | 2008-08-10 |
| CVE-2008-3923 EXP | Multiple cross-site scripting (XSS) vulnerabilities in statistics.php in Content Management Made Easy (CMME) 1.12 allow remote attackers to inject arb… | Patch early | 4.3 medium | 1.6% | 2008-09-04 |
| CVE-2008-5193 EXP | Cross-site scripting (XSS) vulnerability in search.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.6% | 2008-11-21 |
| CVE-2008-5487 EXP | Cross-site scripting (XSS) vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 1.6% | 2008-12-12 |
| CVE-2008-5591 EXP | Cross-site scripting (XSS) vulnerability in login.asp in Nightfall Personal Diary 1.0 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 1.6% | 2008-12-16 |
| CVE-2008-5854 EXP | Multiple cross-site scripting (XSS) vulnerabilities in login.php in myPHPscripts Login Session 2.0 allow remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 1.6% | 2009-01-06 |
| CVE-2022-47529 EXP | Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify… | Patch early | 6.7 medium | 1.6% | 2023-03-28 |
| CVE-2007-2547 EXP | Cross-site scripting (XSS) vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 1.6% | 2007-05-09 |
| CVE-2007-2991 EXP | Cross-site scripting (XSS) vulnerability in includes/send.inc.php in Evenzia CMS allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 1.6% | 2007-06-04 |
| CVE-2013-6167 EXP | Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows rem… | Patch early | 6.8 medium | 1.6% | 2014-02-15 |
| CVE-2006-2061 EXP | SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execu… | Patch early | 5.0 medium | 1.6% | 2006-04-26 |
| CVE-2011-1427 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite 5.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) La… | Patch early | 4.3 medium | 1.6% | 2011-03-15 |
| CVE-2005-2569 EXP | Multiple cross-site scripting (XSS) vulnerabilities in FunkBoard 0.66CF, and possibly earlier versions, allow remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 1.6% | 2005-08-16 |
| CVE-2000-1173 EXP | Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information durin… | Patch early | 5.0 medium | 1.6% | 2001-01-09 |
| CVE-2012-4385 EXP | letodms 3.3.6 has CSRF via change password | Patch early | 6.5 medium | 1.6% | 2019-11-13 |
| CVE-2009-3493 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Zenas PaoBacheca Guestbook 2.1 allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.6% | 2009-09-30 |
| CVE-2009-2145 EXP | Multiple cross-site scripting (XSS) vulnerabilities in transLucid 1.75 allow remote attackers to inject arbitrary web script or HTML via the (a) NodeI… | Patch early | 4.3 medium | 1.6% | 2009-06-22 |
| CVE-2013-4867 EXP | Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking | Patch early | 6.3 medium | 1.6% | 2019-12-27 |
| CVE-2013-0268 EXP | The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended capability restrictions by execu… | Patch early | 6.2 medium | 1.6% | 2013-02-18 |
| CVE-2008-6381 EXP | SQL injection vulnerability in modules/adresses/viewcat.php in bcoos 1.0.13, and possibly earlier, allows remote authenticated users with Addresses mo… | Patch early | 4.6 medium | 1.6% | 2009-03-02 |
| CVE-2008-6499 EXP | security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof critic… | Patch early | 5.5 medium | 1.6% | 2009-03-20 |
| CVE-2026-58057 EXP | Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where envir… | Patch early | 5.0 medium | 1.6% | 2026-06-28 |
| CVE-2012-1049 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 1.6% | 2012-02-13 |
| CVE-2012-4384 EXP | letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar | Patch early | 6.1 medium | 1.6% | 2019-11-13 |
| CVE-2018-8903 EXP | Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen. | Patch early | 5.4 medium | 1.6% | 2018-03-22 |
| CVE-2009-4544 EXP | Cross-site scripting (XSS) vulnerability in kbase/kbase.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to inject arbitr… | Patch early | 4.3 medium | 1.6% | 2010-01-04 |
| CVE-2012-4905 EXP | Cross-site scripting (XSS) vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 1.6% | 2012-09-13 |
| CVE-2007-6232 EXP | Cross-site scripting (XSS) vulnerability in index.php in FTP Admin 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the error… | Patch early | 4.3 medium | 1.6% | 2007-12-04 |
| CVE-2007-0693 EXP | SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist… | Patch early | 6.8 medium | 1.6% | 2007-05-30 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt