CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,133 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
169,961 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-1307 EXP | Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML via an email message with the… | Patch early | 6.8 medium | 4% | 2002-11-29 |
| CVE-2006-4915 EXP | Cross-site scripting (XSS) vulnerability in index.php in Innovate Portal 2.0 allows remote attackers to inject arbitrary web script or HTML via the co… | Patch early | 4.3 medium | 4% | 2006-09-21 |
| CVE-2014-9265 EXP | Stack-based buffer overflow in the BackupToAvi method in the CNC_Ctrl ActiveX control in Samsung SmartViewer allows remote attackers to execute arbitr… | Patch early | 6.8 medium | 4% | 2014-12-08 |
| CVE-2006-1711 EXP | Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword me… | Patch early | 5.0 medium | 4% | 2006-04-11 |
| CVE-2007-5911 EXP | Multiple stack-based buffer overflows in the AxMetaStream ActiveX control in AxMetaStream.dll 3.3.2.26 in Viewpoint Media Player 3.2 allow remote atta… | Patch early | 6.8 medium | 4% | 2007-11-10 |
| CVE-2006-2758 EXP | Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the… | Patch early | 5.0 medium | 4% | 2006-06-02 |
| CVE-2006-0869 EXP | Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and… | Patch early | 6.4 medium | 4% | 2006-02-23 |
| CVE-2006-1128 EXP | Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and… | Patch early | 6.4 medium | 4% | 2006-03-09 |
| CVE-2004-2732 EXP | nbmember.cgi in Netbilling 2.0 allows remote attackers to obtain sensitive information via the cmd=test option, which can be leveraged to determine th… | Patch early | 4.3 medium | 4% | 2004-12-31 |
| CVE-2006-0532 EXP | Cross-site scripting (XSS) vulnerability in resultat.asp in SoftMaker Shop allows remote attackers to inject arbitrary web script or HTML via a strSok… | Patch early | 4.3 medium | 4% | 2006-02-04 |
| CVE-2018-19915 EXP | DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field. | Patch early | 4.8 medium | 4% | 2018-12-06 |
| CVE-2015-2223 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the web-based console management interface in Palo Alto Networks Traps (formerly Cyvera Endpoin… | Patch early | 4.3 medium | 4% | 2015-04-14 |
| CVE-2016-8019 EXP | Cross-site scripting (XSS) vulnerability in attributes in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows unauthenticated… | Patch early | 6.1 medium | 4% | 2017-03-14 |
| CVE-2008-2186 EXP | Cross-site scripting (XSS) vulnerability in index.php in Chilek Content Management System (aka ChiCoMaS) 2.0.4 allows remote attackers to inject arbit… | Patch early | 4.3 medium | 4% | 2008-05-13 |
| CVE-2008-2335 EXP | Cross-site scripting (XSS) vulnerability in search_results.php in Vastal I-Tech phpVID 1.1 and 1.2 allows remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 4% | 2008-05-19 |
| CVE-2011-0504 EXP | Multiple cross-site scripting (XSS) vulnerabilities in VaM Shop 1.6, 1.6.1, and probably earlier versions llow remote attackers to inject arbitrary we… | Patch early | 4.3 medium | 4% | 2011-01-20 |
| CVE-2006-0524 EXP | Cross-site scripting (XSS) vulnerability in ashnews.php in Derek Ashauer ashNews 0.83 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 4% | 2006-02-02 |
| CVE-2004-2522 EXP | Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 4% | 2004-12-31 |
| CVE-2003-1385 EXP | ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_… | Patch early | 6.8 medium | 4% | 2003-12-31 |
| CVE-2013-6492 EXP | The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication… | Patch early | 5.8 medium | 4% | 2014-02-14 |
| CVE-2006-2222 EXP | Buffer overflow in zawhttpd 0.8.23, and possibly previous versions, allows remote attackers to cause a denial of service (daemon crash) via a request… | Patch early | 5.0 medium | 4% | 2006-05-05 |
| CVE-2015-5529 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 4% | 2015-07-16 |
| CVE-2016-4316 EXP | Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) set… | Patch early | 6.1 medium | 4% | 2017-02-17 |
| CVE-2005-1053 EXP | Multiple cross-site scripting (XSS) vulnerabilities in orderwiz.php in ModernBill 4.3.0 and earlier allow remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 4% | 2005-05-02 |
| CVE-2005-1486 EXP | Multiple cross-site scripting vulnerabilities in FishCart 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) trackingnum, (… | Patch early | 5.0 medium | 4% | 2005-05-11 |
| CVE-2014-3441 EXP | codec\libpng_plugin.dll in VideoLAN VLC Media Player 2.1.3 allows remote attackers to cause a denial of service (crash) via a crafted .png file, as de… | Patch early | 4.3 medium | 4% | 2014-05-14 |
| CVE-2019-7438 EXP | cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter. | Patch early | 6.1 medium | 4% | 2019-03-21 |
| CVE-2005-0928 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 5.x allow remote attackers to inject arbitrary web script or HTML via the (1)… | Patch early | 4.3 medium | 4% | 2005-05-02 |
| CVE-2007-2632 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PHP Multi User Randomizer (phpMUR) 2006.09.13 allow remote attackers to inject arbitrary web sc… | Patch early | 6.8 medium | 4% | 2007-05-13 |
| CVE-2006-5186 EXP | PHP remote file inclusion vulnerability in functions.php in phpMyProfiler 0.9.6 and earlier, when register_globals is enabled, allows remote attackers… | Patch early | 5.1 medium | 4% | 2006-10-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt