CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,367 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-2989 EXP | Cross-site request forgery (CSRF) vulnerability in Open Assessment Technologies TAO 2.5.6 allows remote attackers to hijack the authentication of admi… | Patch early | 6.8 medium | 1.2% | 2014-05-13 |
| CVE-2005-0155 EXP | The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG… | Patch early | 4.6 medium | 1.2% | 2005-05-02 |
| CVE-2012-1498 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Webfolio CMS 1.1.4 and earlier allow remote attackers to hijack the authentication of ad… | Patch early | 6.8 medium | 1.2% | 2012-03-19 |
| CVE-2010-1486 EXP | Multiple cross-site scripting (XSS) vulnerabilities in _invoice.asp in CactuShop before 6.155 allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.2% | 2010-04-22 |
| CVE-2010-4947 EXP | Cross-site scripting (XSS) vulnerability in advanced_search_result.php in ALLPC 2.5 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.2% | 2011-10-09 |
| CVE-2007-6003 EXP | Cross-site scripting (XSS) vulnerability in cgi/b/ic/connect in the Thomson SpeedTouch 716 with firmware 5.4.0.14 allows remote attackers to inject ar… | Patch early | 4.3 medium | 1.2% | 2007-11-15 |
| CVE-2008-0700 EXP | Cross-site scripting (XSS) vulnerability in search.php in Crux Software CruxCMS 3.0 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.2% | 2008-02-12 |
| CVE-2008-1479 EXP | Cross-site scripting (XSS) vulnerability in index.php in cyberfrogs.net cfnetgs 0.24 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.2% | 2008-03-24 |
| CVE-2008-1500 EXP | Cross-site scripting (XSS) vulnerability in index.php in TinyPortal 0.8.6 and 1.0.3 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.2% | 2008-03-25 |
| CVE-2008-2814 EXP | Cross-site scripting (XSS) vulnerability in WallCity-Server Shoutcast Admin Panel 2.0 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 1.2% | 2008-06-23 |
| CVE-2008-2871 EXP | Multiple cross-site scripting (XSS) vulnerabilities in template2.php in PEGames allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.2% | 2008-06-26 |
| CVE-2008-4803 EXP | Cross-site scripting (XSS) vulnerability in index.php in Simple PHP Scripts gallery 0.1, 0.3, and 0.4 allows remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 1.2% | 2008-10-31 |
| CVE-2008-5759 EXP | Cross-site scripting (XSS) vulnerability in FlatnuX CMS (aka Flatnuke3) 2008-12-11 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.2% | 2008-12-30 |
| CVE-2007-5142 EXP | Cross-site scripting (XSS) vulnerability in buscar.asp in Solidweb Novus 1.0 allows remote attackers to inject arbitrary web script or HTML via the p… | Patch early | 4.3 medium | 1.2% | 2007-09-28 |
| CVE-2005-3928 EXP | Buffer overflow in phgrafx in QNX 6.2.1 and 6.3.0 allows local users to execute arbitrary code via a long command line argument. | Patch early | 4.6 medium | 1.2% | 2005-11-30 |
| CVE-2012-1897 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack the authentication of adminis… | Patch early | 6.8 medium | 1.2% | 2012-10-01 |
| CVE-2000-0492 EXP | PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the password file to easliy decrypt the p… | Patch early | 5.0 medium | 1.2% | 2000-06-04 |
| CVE-2009-2907 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SpringSource tc Server 6.0.20.B and earlier, Application Management Suite (AMS) before 2.0.0.SR… | Patch early | 4.3 medium | 1.2% | 2010-03-24 |
| CVE-2009-3647 EXP | Cross-site scripting (XSS) vulnerability in emaullinks.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote attackers to inject… | Patch early | 4.3 medium | 1.2% | 2009-10-09 |
| CVE-2009-4209 EXP | Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in moziloCMS 1.11.1 allow remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.2% | 2009-12-04 |
| CVE-2008-1504 EXP | Cross-site scripting (XSS) vulnerability in setup.php3 in phpHeaven phpMyChat 0.14.5 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.2% | 2008-03-25 |
| CVE-2008-1800 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in DivXDB 2002 0.94b allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.2% | 2008-04-15 |
| CVE-2008-2264 EXP | Cross-site scripting (XSS) vulnerability in index.php in CyrixMED 1.4 allows remote attackers to inject arbitrary web script or HTML via the msg_erreu… | Patch early | 4.3 medium | 1.2% | 2008-05-16 |
| CVE-2008-3161 EXP | Multiple cross-site scripting (XSS) vulnerabilities in jsp/common/system/debug.jsp in IBM Maximo 4.1 and 5.2 allow remote attackers to inject arbitrar… | Patch early | 4.3 medium | 1.2% | 2008-07-14 |
| CVE-2009-0430 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Active Bids allow remote attackers to inject arbitrary web script or HTML via the (1) search pa… | Patch early | 4.3 medium | 1.2% | 2009-02-05 |
| CVE-2009-1225 EXP | Cross-site scripting (XSS) vulnerability in index.php in Turnkey Ebook Store 1.1 allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 1.2% | 2009-04-02 |
| CVE-2009-1349 EXP | Cross-site scripting (XSS) vulnerability in C2Net Stronghold 2.3 allows remote attackers to inject arbitrary web script or HTML via the URI. | Patch early | 4.3 medium | 1.2% | 2009-04-21 |
| CVE-2009-1620 EXP | Multiple cross-site scripting (XSS) vulnerabilities in input.php in MataChat allow remote attackers to inject arbitrary web script or HTML via the (1)… | Patch early | 4.3 medium | 1.2% | 2009-05-12 |
| CVE-2013-5091 EXP | SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute arbitrary SQL… | Patch early | 6.5 medium | 1.2% | 2013-10-04 |
| CVE-2007-1019 EXP | SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers to execute arbitrary SQL comman… | Patch early | 6.8 medium | 1.2% | 2007-02-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt