CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,166 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-6616 EXP | Cross-site scripting (XSS) vulnerability in index.php in Zen Software Zen Cart 2008 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.4% | 2009-04-06 |
| CVE-2008-7141 EXP | Cross-site scripting (XSS) vulnerability in setup.php in @lex Poll 2.1 allows remote attackers to inject arbitrary web script or HTML via the language… | Patch early | 4.3 medium | 1.4% | 2009-09-01 |
| CVE-2009-2228 EXP | Cross-site scripting (XSS) vulnerability in engine.php in Kasseler CMS allows remote attackers to inject arbitrary web script or HTML via the url para… | Patch early | 4.3 medium | 1.4% | 2009-06-26 |
| CVE-2002-2255 EXP | Cross-site scripting (XSS) vulnerability in search.php in phpBB 2.0.3 and possibly earlier versions allows remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 1.4% | 2002-12-31 |
| CVE-2002-2296 EXP | Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbitrary web s… | Patch early | 4.3 medium | 1.4% | 2002-12-31 |
| CVE-2003-1519 EXP | Cross-site scripting (XSS) vulnerability in Vivisimo clustering engine allows remote attackers to inject arbitrary web script or HTML via the query pa… | Patch early | 4.3 medium | 1.4% | 2003-12-31 |
| CVE-2010-3024 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in user/main/update_user in DiamondList 0.1.6, and possibly earlier, allow remote attackers… | Patch early | 6.8 medium | 1.4% | 2010-08-16 |
| CVE-2011-0535 EXP | Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authentication of adm… | Patch early | 6.8 medium | 1.4% | 2011-02-08 |
| CVE-2005-0741 EXP | Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the username p… | Patch early | 4.3 medium | 1.4% | 2005-03-08 |
| CVE-2013-7057 EXP | Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to hijack the authentication of u… | Patch early | 6.8 medium | 1.4% | 2014-11-04 |
| CVE-2005-2011 EXP | Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web script or HTML, as demonstrated… | Patch early | 4.3 medium | 1.4% | 2005-06-20 |
| CVE-2004-0291 EXP | SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter. | Patch early | 5.0 medium | 1.4% | 2004-11-23 |
| CVE-2006-1034 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbitrary web script or HTML via (… | Patch early | 4.3 medium | 1.4% | 2006-03-07 |
| CVE-2014-10008 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Stark CRM 1.0 allow remote attackers to hijack the authentication of administrators for… | Patch early | 6.8 medium | 1.4% | 2015-01-13 |
| CVE-2018-10906 EXP | In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root user… | Patch early | 5.3 medium | 1.4% | 2018-07-24 |
| CVE-2014-2016 EXP | Multiple cross-site scripting (XSS) vulnerabilities in OXID eShop Professional and Community Edition 4.6.8 and earlier, 4.7.x before 4.7.11, and 4.8.x… | Patch early | 4.3 medium | 1.4% | 2014-03-25 |
| CVE-2024-51464 EXP | IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially crafted request, an authenticated a… | Patch early | 4.3 medium | 1.4% | 2024-12-21 |
| CVE-2006-5557 EXP | Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions allows local users to execute… | Patch early | 4.6 medium | 1.4% | 2006-10-27 |
| CVE-2016-7386 EXP | For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability… | Patch early | 5.5 medium | 1.4% | 2016-11-08 |
| CVE-2013-6852 EXP | Cross-site request forgery (CSRF) vulnerability in html/json.html on HP 2620 switches allows remote attackers to hijack the authentication of administ… | Patch early | 6.8 medium | 1.4% | 2013-11-22 |
| CVE-2013-2639 EXP | Cross-site scripting (XSS) vulnerability in CTERA Cloud Storage OS before 3.2.29.0, 3.2.42.0, and earlier allows remote attackers to inject arbitrary… | Patch early | 4.3 medium | 1.4% | 2014-02-11 |
| CVE-2013-6162 EXP | Cross-site scripting (XSS) vulnerability in Code-Crafters Ability Mail Server 3.1.1 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.4% | 2013-12-21 |
| CVE-2013-4624 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.4% | 2013-11-27 |
| CVE-2017-14712 EXP | In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter. | Patch early | 5.4 medium | 1.4% | 2017-09-22 |
| CVE-2017-14717 EXP | In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter. | Patch early | 5.4 medium | 1.4% | 2017-09-22 |
| CVE-2003-1031 EXP | Cross-site scripting (XSS) vulnerability in register.php for vBulletin 3.0 Beta 2 allows remote attackers to inject arbitrary HTML or web script via o… | Patch early | 4.3 medium | 1.4% | 2004-02-17 |
| CVE-2005-2318 EXP | Cross-site scripting (XSS) vulnerability in showerr.asp in DVBBS 7.1 SP2 allows remote attackers to inject arbitrary web script or HTML via the action… | Patch early | 4.3 medium | 1.4% | 2005-07-19 |
| CVE-2005-3397 EXP | Cross-site scripting (XSS) vulnerability in Comersus BackOffice allows remote attackers to inject arbitrary web script or HTML via the error parameter… | Patch early | 4.3 medium | 1.4% | 2005-11-01 |
| CVE-2012-1922 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Sitecom WLM-2501 allow remote attackers to hijack the authentication of administrators f… | Patch early | 6.8 medium | 1.4% | 2013-01-24 |
| CVE-2007-5316 EXP | SQL injection vulnerability in browsecats.php in Softbiz Jobs and Recruitment Script allows remote attackers to execute arbitrary SQL commands via the… | Patch early | 5.0 medium | 1.4% | 2007-10-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt