CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,660 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
207,266 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-2193 EXP | Cross-site scripting (XSS) vulnerability in mojo.cgi for Mojo Mail 2.7 allows remote attackers to inject arbitrary web script via the email parameter. | Patch early | 4.3 medium | 3.5% | 2002-12-31 |
| CVE-2003-1243 EXP | Cross-site scripting vulnerability (XSS) in Sage 1.0 b3 allows remote attackers to insert arbitrary HTML or web script via the mod parameter. | Patch early | 4.3 medium | 3.5% | 2003-12-31 |
| CVE-2023-34635 EXP | Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user… | Patch early | 9.8 critical | 3.5% | 2023-07-31 |
| CVE-2020-22841 EXP | Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input fie… | Patch early | 4.8 medium | 3.5% | 2021-02-09 |
| CVE-2009-1583 EXP | Multiple cross-site scripting (XSS) vulnerabilities in TemaTres 1.0.3 and 1.031 allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 3.5% | 2009-05-07 |
| CVE-2010-0366 EXP | Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta all… | Patch early | 6.8 medium | 3.5% | 2010-01-21 |
| CVE-2009-3902 EXP | Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read arbitrary files via a /\.. (sla… | Patch early | 5.0 medium | 3.5% | 2009-11-06 |
| CVE-2002-1028 EXP | Multiple buffer overflows in the CGI programs for Oddsock Song Requester WinAmp plugin 2.1 allow remote attackers to cause a denial of service (crash)… | Patch early | 5.0 medium | 3.5% | 2002-10-04 |
| CVE-2000-1027 EXP | Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requ… | Patch early | 5.0 medium | 3.5% | 2000-12-11 |
| CVE-2007-0357 EXP | Directory traversal vulnerability in the AVM IGD CTRL Service in Fritz!DSL 02.02.29 allows remote attackers to read arbitrary files via ..%5C (URL-enc… | Patch early | 5.0 medium | 3.5% | 2007-01-19 |
| CVE-2005-3948 EXP | Directory traversal vulnerability in main.php in PHPAlbum 0.2.3 and earlier allows remote attackers to read arbitrary files via the (1) cmd and (2) va… | Patch early | 5.0 medium | 3.5% | 2005-12-01 |
| CVE-2008-3604 EXP | SQL injection vulnerability in bannerclick.php in ZeeBuddy 2.1 allows remote attackers to execute arbitrary SQL commands via the adid parameter. | Patch early | 9.8 critical | 3.5% | 2008-08-12 |
| CVE-2009-2229 EXP | Directory traversal vulnerability in engine.php in Kasseler CMS 1.3.5 lite allows remote attackers to read arbitrary files via a .. (dot dot) in the f… | Patch early | 5.0 medium | 3.5% | 2009-06-26 |
| CVE-2011-3856 EXP | Cross-site scripting (XSS) vulnerability in the Elegant Grunge theme before 1.0.4 for WordPress allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 3.5% | 2011-09-28 |
| CVE-2011-3858 EXP | Cross-site scripting (XSS) vulnerability in the Pixiv Custom theme before 2.1.6 for WordPress allows remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 3.5% | 2011-09-28 |
| CVE-2011-3861 EXP | Cross-site scripting (XSS) vulnerability in the Web Minimalist 200901 theme before 1.2 for WordPress allows remote attackers to inject arbitrary web s… | Patch early | 4.3 medium | 3.5% | 2011-09-28 |
| CVE-2011-3865 EXP | Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 3.5% | 2011-09-28 |
| CVE-2013-1604 EXP | Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to read arbitrary files via a… | Patch early | 5.0 medium | 3.5% | 2014-03-25 |
| CVE-2006-2012 EXP | Format string vulnerability in Skulltag 0.96f and earlier allows remote attackers to cause a denial of service via the version string. | Patch early | 5.0 medium | 3.5% | 2006-04-25 |
| CVE-2005-0853 EXP | betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a direct request… | Patch early | 5.0 medium | 3.5% | 2005-05-02 |
| CVE-2015-6518 EXP | Multiple cross-site scripting (XSS) vulnerabilities in phpLiteAdmin 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH… | Patch early | 4.3 medium | 3.5% | 2015-08-18 |
| CVE-2004-2077 EXP | Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed d… | Patch early | 5.0 medium | 3.5% | 2004-02-08 |
| CVE-2006-1275 EXP | GGZ Gaming Zone 0.0.12 allows remote attackers to cause a denial of service (client disconnect) via inputs that produce malformed XML, including (1) t… | Patch early | 5.0 medium | 3.5% | 2006-03-19 |
| CVE-2011-1569 EXP | download.aspx in Douran Portal 3.9.7.8 allows remote attackers to obtain source code of arbitrary files under the web root via (1) a trailing ".", (2)… | Patch early | 5.0 medium | 3.5% | 2011-04-05 |
| CVE-2010-4518 EXP | Cross-site scripting (XSS) vulnerability in wp-safe-search/wp-safe-search-jx.php in the Safe Search plugin 0.7 for WordPress allows remote attackers t… | Patch early | 4.3 medium | 3.5% | 2010-12-09 |
| CVE-2012-0974 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the getParam function in oc-includes/osclass/core/Params.php in OSClass before 2.3.5 allow remo… | Patch early | 4.3 medium | 3.5% | 2012-09-25 |
| CVE-2014-3080 EXP | Multiple cross-site scripting (XSS) vulnerabilities on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allow re… | Patch early | 4.3 medium | 3.5% | 2014-08-17 |
| CVE-2006-4525 EXP | Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary… | Patch early | 4.3 medium | 3.5% | 2006-09-01 |
| CVE-2004-1792 EXP | swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a long packet with two CRLF se… | Patch early | 5.0 medium | 3.5% | 2004-12-31 |
| CVE-2004-2151 EXP | Chatman 1.1.1 RC1 and earlier allows remote attackers to cause a denial of service (memory consumption or application crash) via a very large data siz… | Patch early | 5.0 medium | 3.5% | 2004-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt