CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,997 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
170,228 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-42750 EXP | A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrar… | Patch early | 4.8 medium | 3.1% | 2022-08-12 |
| CVE-2021-42751 EXP | A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrar… | Patch early | 4.8 medium | 3.1% | 2022-08-12 |
| CVE-2010-3841 EXP | Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 3.1% | 2010-10-18 |
| CVE-2006-0444 EXP | SQL injection vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.1 allows remote attackers to execute arbitrary SQL commands via the (1) par… | Patch early | 6.8 medium | 3% | 2006-01-26 |
| CVE-2005-3493 EXP | Battle Carry .005 and earlier allows remote attackers to cause a denial of service (inaccessible port) via a large packet, which triggers a socket err… | Patch early | 5.0 medium | 3% | 2005-11-04 |
| CVE-2021-3111 EXP | The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/v… | Patch early | 4.8 medium | 3% | 2021-01-08 |
| CVE-2008-3265 EXP | SQL injection vulnerability in the DT Register (com_dtregister) 2.2.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands… | Patch early | 6.8 medium | 3% | 2008-07-24 |
| CVE-2017-8685 EXP | Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows information disclosure by the way it discloses kernel memory ad… | Patch early | 5.5 medium | 3% | 2017-09-13 |
| CVE-2009-4610 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 3% | 2010-01-13 |
| CVE-2007-4812 EXP | Buffer overflow in Apple Safari 3.0.3 522.15.5, and other versions before Beta Update 3.0.4, allows remote attackers to cause a denial of service (cra… | Patch early | 5.0 medium | 3% | 2007-09-11 |
| CVE-2003-1207 EXP | Crob FTP Server 3.5.1 allows remote authenticated users to cause a denial of service (crash) via a dir command with a large number of "." characters f… | Patch early | 5.0 medium | 3% | 2004-02-01 |
| CVE-2013-2504 EXP | Cross-site scripting (XSS) vulnerability in SPS/Portal/default.aspx in Service Desk in Matrix42 Service Store 5.3 SP3 (aka 5.33.946.0) allows remote a… | Patch early | 4.3 medium | 3% | 2013-12-29 |
| CVE-2008-3569 EXP | Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.6.7, when register_globals is enabled, allow remote attackers to inject arbitrary web s… | Patch early | 4.3 medium | 3% | 2008-08-10 |
| CVE-2017-14096 EXP | A stored cross site scripting (XSS) vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker t… | Patch early | 6.1 medium | 3% | 2018-01-19 |
| CVE-2019-1345 EXP | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosur… | Patch early | 5.5 medium | 3% | 2019-10-10 |
| CVE-2006-4427 EXP | index.php in eFiction before 2.0.7 allows remote attackers to bypass authentication and gain privileges by setting the (1) adminloggedin, (2) loggedin… | Patch early | 5.1 medium | 3% | 2006-08-29 |
| CVE-2008-6676 EXP | QuickerSite 1.8.5 allows remote attackers to obtain sensitive information via a request to showThumb.aspx without any parameters, which reveals the in… | Patch early | 5.0 medium | 3% | 2009-04-08 |
| CVE-2005-0796 EXP | Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot d… | Patch early | 5.0 medium | 3% | 2005-05-02 |
| CVE-2003-0338 EXP | Directory traversal vulnerability in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allows remote attackers to read and execute arbitrary files via .. (dot… | Patch early | 5.0 medium | 3% | 2003-05-21 |
| CVE-1999-1083 EXP | Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack. | Patch early | 5.0 medium | 3% | 1999-10-08 |
| CVE-2006-4270 EXP | PHP remote file inclusion vulnerability in mambelfish.class.php in the mambelfish component (com_mambelfish) 1.1 and earlier for Mambo allows remote a… | Patch early | 6.8 medium | 3% | 2006-08-21 |
| CVE-2003-1541 EXP | PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain t… | Patch early | 5.0 medium | 3% | 2003-12-31 |
| CVE-2007-3127 EXP | content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to obtain sensitive information via a "';" (quote semicolon) s… | Patch early | 5.0 medium | 3% | 2007-06-19 |
| CVE-2004-2480 EXP | Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via "@@" sequences in a URL within… | Patch early | 5.0 medium | 3% | 2004-12-31 |
| CVE-2009-3601 EXP | Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 3% | 2009-10-08 |
| CVE-2015-2805 EXP | Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lucent OmniS… | Patch early | 6.8 medium | 3% | 2015-06-16 |
| CVE-2014-1665 EXP | Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the fil… | Patch early | 5.4 medium | 3% | 2018-03-20 |
| CVE-2004-2344 EXP | Unknown vulnerability in the ASN.1/H.323/H.225 stack of VocalTec VGW120 and VGW480 allows remote attackers to cause a denial of service. | Patch early | 5.0 medium | 3% | 2004-12-31 |
| CVE-2002-1862 EXP | SmartMail Server 2.0 allows remote attackers to cause a denial of service (crash) by sending data and closing the connection before all the data has b… | Patch early | 5.0 medium | 3% | 2002-12-31 |
| CVE-2005-1033 EXP | CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to… | Patch early | 5.0 medium | 3% | 2005-05-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt