CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,908 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
170,617 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-9243 EXP | Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) QU… | Patch early | 4.3 medium | 2.5% | 2014-12-03 |
| CVE-2006-3616 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Carbonize Lazarus Guestbook 1.6 and earlier allow remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 2.5% | 2006-07-18 |
| CVE-2010-1905 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allow remote attackers to inj… | Patch early | 4.3 medium | 2.5% | 2010-05-12 |
| CVE-2008-6540 EXP | DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey valu… | Patch early | 5.1 medium | 2.5% | 2009-03-30 |
| CVE-2000-1154 EXP | RHConsole in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request. | Patch early | 5.0 medium | 2.5% | 2001-01-09 |
| CVE-2012-2955 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and… | Patch early | 4.3 medium | 2.5% | 2012-07-20 |
| CVE-2006-1965 EXP | Multiple cross-site scripting (XSS) vulnerabilities in aasi media Net Clubs Pro 4.0 and earlier allow remote attackers to inject arbitrary web script… | Patch early | 5.8 medium | 2.5% | 2006-04-21 |
| CVE-2018-15608 EXP | Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen. | Patch early | 6.1 medium | 2.5% | 2018-08-28 |
| CVE-2007-6632 EXP | showCode.php in xml2owl 0.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter. | Patch early | 6.8 medium | 2.5% | 2008-01-04 |
| CVE-2018-12111 EXP | Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 6.1 medium | 2.5% | 2018-06-11 |
| CVE-2019-13029 EXP | Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 before 8.10.20 and 9 before 9.1.2 allow an attacker… | Patch early | 4.8 medium | 2.5% | 2019-07-11 |
| CVE-2014-1915 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to hijack the au… | Patch early | 6.8 medium | 2.5% | 2014-02-07 |
| CVE-2012-3831 EXP | Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.1 allows remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 2.5% | 2012-07-03 |
| CVE-2013-6357 EXP | Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the a… | Patch early | 6.8 medium | 2.5% | 2013-11-13 |
| CVE-2006-1407 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary we… | Patch early | 5.8 medium | 2.5% | 2006-03-28 |
| CVE-2021-24383 EXP | The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard… | Patch early | 5.4 medium | 2.5% | 2021-06-21 |
| CVE-2006-1427 EXP | Multiple cross-site scripting (XSS) vulnerabilities in WebAPP 0.9.9.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 2.5% | 2006-03-28 |
| CVE-2012-2578 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SmarterMail 9.2 allow remote attackers to inject arbitrary web script or HTML via an e-mail mes… | Patch early | 4.3 medium | 2.5% | 2012-09-19 |
| CVE-2012-2586 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Mailtraq 2.17.3.3150 allow remote attackers to inject arbitrary web script or HTML via an e-mai… | Patch early | 4.3 medium | 2.5% | 2012-09-19 |
| CVE-2014-5100 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the authentication of administrators… | Patch early | 6.8 medium | 2.5% | 2014-07-25 |
| CVE-2017-14620 EXP | SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in Stored Cros… | Patch early | 6.1 medium | 2.5% | 2017-09-30 |
| CVE-2018-9235 EXP | iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php. | Patch early | 6.1 medium | 2.5% | 2018-04-04 |
| CVE-2012-5345 EXP | Buffer overflow in the Remote command server (Rcmd.bat) in IpTools (aka Tiny TCP/IP server) 0.1.4 allows remote attackers to cause a denial of service… | Patch early | 5.0 medium | 2.5% | 2012-10-09 |
| CVE-2021-25680 EXP | The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These issues impact at minimum versi… | Patch early | 6.1 medium | 2.5% | 2021-04-20 |
| CVE-2017-6340 EXP | Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/report/template name field, which a… | Patch early | 5.4 medium | 2.5% | 2017-04-05 |
| CVE-2000-1228 EXP | Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, op… | Patch early | 5.0 medium | 2.5% | 2000-12-31 |
| CVE-1999-1504 EXP | Stalker Internet Mail Server 1.6 allows a remote attacker to cause a denial of service (crash) via a long HELO command. | Patch early | 5.0 medium | 2.5% | 1998-04-08 |
| CVE-1999-1532 EXP | Netscape Messaging Server 3.54, 3.55, and 3.6 allows a remote attacker to cause a denial of service (memory exhaustion) via a series of long RCPT TO c… | Patch early | 5.0 medium | 2.5% | 1999-10-29 |
| CVE-2008-6871 EXP | Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers to obtain unspecified sensitive… | Patch early | 5.0 medium | 2.5% | 2009-07-23 |
| CVE-2008-7056 EXP | BandSite CMS 1.1.4 does not perform access control for adminpanel/phpmydump.php, which allows remote attackers to obtain copies of the database via a… | Patch early | 5.0 medium | 2.5% | 2009-08-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt