CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,058 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
169,925 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-8729 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote attackers to inject arbitrary J… | Patch early | 6.1 medium | 5.3% | 2018-03-15 |
| CVE-2019-9591 EXP | A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web sc… | Patch early | 6.1 medium | 5.3% | 2019-03-06 |
| CVE-2009-1729 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3 allow remote attackers to inj… | Patch early | 4.3 medium | 5.3% | 2009-05-21 |
| CVE-2012-0895 EXP | Cross-site scripting (XSS) vulnerability in map/map.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to inject arbit… | Patch early | 4.3 medium | 5.3% | 2012-01-20 |
| CVE-2004-2511 EXP | Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 5.3% | 2004-12-31 |
| CVE-2006-1377 EXP | Cross-site scripting (XSS) vulnerability in img.php in (1) EasyMoblog 0.5.1 and (2) CoMoblog 1.1 allows remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 5.3% | 2006-03-24 |
| CVE-2019-6804 EXP | An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascripts/workflowStepEditorKO.js and… | Patch early | 6.1 medium | 5.3% | 2019-01-25 |
| CVE-2023-36306 EXP | A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the ask… | Patch early | 6.1 medium | 5.3% | 2023-08-08 |
| CVE-2012-6506 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.0 for WordPress allow remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 5.3% | 2013-01-24 |
| CVE-1999-1566 EXP | Buffer overflow in iParty server 1.2 and earlier allows remote attackers to cause a denial of service (crash) by connecting to default port 6004 and s… | Patch early | 5.0 medium | 5.3% | 1999-05-08 |
| CVE-2016-5310 EXP | The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud;… | Patch early | 5.5 medium | 5.3% | 2017-04-14 |
| CVE-2009-0464 EXP | PHP remote file inclusion vulnerability in includes/header.php in Groone GBook 2.0 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 5.1 medium | 5.3% | 2009-02-10 |
| CVE-2019-9592 EXP | A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or… | Patch early | 6.1 medium | 5.3% | 2019-03-06 |
| CVE-2019-16118 EXP | Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php. | Patch early | 6.1 medium | 5.3% | 2019-09-08 |
| CVE-2001-0580 EXP | Hughes Technologies Virtual DNS (VDNS) Server 1.0 allows a remote attacker to create a denial of service by connecting to port 6070, sending some data… | Patch early | 5.0 medium | 5.3% | 2001-08-22 |
| CVE-2007-4145 EXP | Heap-based buffer overflow in the BlueSkychat (BlueSkyCat) ActiveX control (V2.V2Ctrl.1) in v2.ocx 8.1.2.0 and earlier allows remote attackers to exec… | Patch early | 4.3 medium | 5.3% | 2007-08-03 |
| CVE-2020-2231 EXP | Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resu… | Patch early | 5.4 medium | 5.3% | 2020-08-12 |
| CVE-2009-0821 EXP | Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print fun… | Patch early | 5.0 medium | 5.3% | 2009-03-05 |
| CVE-2017-6516 EXP | A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow a local attacker to gain elev… | Patch early | 6.7 medium | 5.3% | 2017-03-14 |
| CVE-2000-1085 EXP | The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before c… | Patch early | 4.6 medium | 5.3% | 2001-01-09 |
| CVE-2018-15181 EXP | JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS payload in the SSID name and Securi… | Patch early | 6.5 medium | 5.3% | 2018-08-09 |
| CVE-2009-0981 EXP | Unspecified vulnerability in the Application Express component in Oracle Database 11.1.0.7 allows remote authenticated users to affect confidentiality… | Patch early | 4.0 medium | 5.3% | 2009-04-15 |
| CVE-2000-0221 EXP | The Nautica Marlin bridge allows remote attackers to cause a denial of service via a zero length UDP packet to the SNMP port. | Patch early | 5.0 medium | 5.3% | 2000-02-25 |
| CVE-2007-6324 EXP | PHP remote file inclusion vulnerability in head.php in CityWriter 0.9.7 allows remote attackers to execute arbitrary PHP code via a URL in the path pa… | Patch early | 6.8 medium | 5.3% | 2007-12-13 |
| CVE-2018-20484 EXP | Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation. | Patch early | 6.1 medium | 5.3% | 2018-12-26 |
| CVE-2018-20485 EXP | Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature. | Patch early | 6.1 medium | 5.3% | 2018-12-26 |
| CVE-2006-2494 EXP | Stack-based buffer overflow in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a crafted .map file. | Patch early | 5.1 medium | 5.3% | 2006-05-20 |
| CVE-2007-3792 EXP | Multiple PHP remote file inclusion vulnerabilities in AzDG Dating Gold 3.0.5 allow remote attackers to execute arbitrary PHP code via a URL in the int… | Patch early | 4.3 medium | 5.3% | 2007-07-15 |
| CVE-2000-0647 EXP | WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before logging into the server. | Patch early | 5.0 medium | 5.3% | 2000-07-21 |
| CVE-2001-0460 EXP | Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory exhaustion) via a… | Patch early | 5.0 medium | 5.3% | 2001-06-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt