CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,084 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
169,946 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-2045 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 300 allow remote attackers to in… | Patch early | 6.1 medium | 4.5% | 2017-01-20 |
| CVE-2014-1906 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote att… | Patch early | 4.3 medium | 4.5% | 2014-03-06 |
| CVE-2013-1409 EXP | Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 4.5% | 2014-03-03 |
| CVE-2013-2643 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Sophos Web Appliance before 3.7.8.2 allow remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 4.5% | 2014-03-18 |
| CVE-2015-4084 EXP | Cross-site scripting (XSS) vulnerability in the Free Counter plugin 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 4.5% | 2015-05-28 |
| CVE-2011-2938 EXP | Multiple cross-site scripting (XSS) vulnerabilities in filter_api.php in MantisBT before 1.2.7 allow remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 4.5% | 2011-09-21 |
| CVE-2008-2333 EXP | Cross-site scripting (XSS) vulnerability in ldap_test.cgi in Barracuda Spam Firewall (BSF) before 3.5.11.025 allows remote attackers to inject arbitra… | Patch early | 4.3 medium | 4.5% | 2008-05-23 |
| CVE-2009-0275 EXP | Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into… | Patch early | 6.5 medium | 4.5% | 2009-01-26 |
| CVE-2011-0901 EXP | Multiple stack-based buffer overflows in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150, and possibly other… | Patch early | 6.8 medium | 4.5% | 2011-02-07 |
| CVE-2019-1125 EXP | An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully e… | Patch early | 5.6 medium | 4.5% | 2019-09-03 |
| CVE-2012-6550 EXP | Cross-site scripting (XSS) vulnerability in ZeroClipboard before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via "the clipTex… | Patch early | 4.3 medium | 4.5% | 2013-04-02 |
| CVE-1999-0752 EXP | Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake. | Patch early | 5.0 medium | 4.5% | 1999-07-06 |
| CVE-2006-3949 EXP | PHP remote file inclusion vulnerability in artlinks.dispnew.php in the Artlinks component (com_artlinks) for Mambo allows remote attackers to execute… | Patch early | 6.8 medium | 4.5% | 2006-08-01 |
| CVE-2014-3842 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow remote attackers to inject ar… | Patch early | 4.3 medium | 4.5% | 2014-05-22 |
| CVE-2005-0992 EXP | Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2-rc1 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 4.5% | 2005-05-02 |
| CVE-2002-1473 EXP | Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbi… | Patch early | 4.6 medium | 4.5% | 2003-04-22 |
| CVE-2006-0703 EXP | Unspecified vulnerability in index.php in imageVue 16.1 has unknown impact, probably a cross-site scripting (XSS) vulnerability involving the query st… | Patch early | 4.3 medium | 4.5% | 2006-02-15 |
| CVE-2008-1385 EXP | Cross-site scripting (XSS) vulnerability in the Top Referrers (aka referrer) plugin in Serendipity (S9Y) before 1.3.1 allows remote attackers to injec… | Patch early | 4.3 medium | 4.5% | 2008-04-23 |
| CVE-2009-2937 EXP | Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC att… | Patch early | 4.3 medium | 4.5% | 2009-09-18 |
| CVE-2020-7680 EXP | docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources… | Patch early | 6.1 medium | 4.5% | 2020-07-20 |
| CVE-2005-1807 EXP | The Data function in class.smtp.php in PHPMailer 1.7.2 and earlier allows remote attackers to cause a denial of service (infinite loop leading to memo… | Patch early | 5.0 medium | 4.5% | 2005-05-28 |
| CVE-2010-3171 EXP | The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random n… | Patch early | 5.8 medium | 4.5% | 2010-09-15 |
| CVE-2007-3183 EXP | Multiple SQL injection vulnerabilities in Calendarix 0.7.20070307, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL… | Patch early | 6.8 medium | 4.5% | 2007-06-26 |
| CVE-2007-6699 EXP | Multiple buffer overflows in the AIM PicEditor 9.5.1.8 ActiveX control in YGPPicEdit.dll in AOL You've Got Pictures (YGP) Picture Editor allow remote… | Patch early | 4.3 medium | 4.5% | 2008-02-04 |
| CVE-2007-4592 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, an… | Patch early | 4.3 medium | 4.5% | 2008-03-20 |
| CVE-2005-4503 EXP | httprint v202, and possibly other versions before v301, allows remote attackers to cause a denial of service (crash) via a long Server field in an HTT… | Patch early | 5.0 medium | 4.5% | 2005-12-22 |
| CVE-2017-5631 EXP | An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is transmitted in the l… | Patch early | 6.1 medium | 4.5% | 2017-05-01 |
| CVE-2006-1356 EXP | Stack-based buffer overflow in the count_vcards function in LibVC 3, as used in Rolo, allows user-assisted attackers to execute arbitrary code via a v… | Patch early | 5.1 medium | 4.5% | 2006-03-22 |
| CVE-2012-6534 EXP | Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllog… | Patch early | 4.3 medium | 4.5% | 2013-03-29 |
| CVE-2010-3514 EXP | Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 6.1 and 7.0 allows remo… | Patch early | 4.3 medium | 4.5% | 2010-10-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt