CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,286 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
170,799 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-0754 EXP | Cross-site scripting (XSS) vulnerability in index.php/Special/Main/Templates in WikyBlog 1.7.2 and 1.7.3 rc2 allows remote attackers to inject arbitra… | Patch early | 4.3 medium | 2.2% | 2010-02-27 |
| CVE-2010-4874 EXP | Multiple cross-site scripting (XSS) vulnerabilities in users.php in NinkoBB 1.3 RC5 allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 2.2% | 2011-10-07 |
| CVE-2007-6005 EXP | Unspecified vulnerability in the GpcContainer.GpcContainer.1 ActiveX control in WebEx allows remote attackers to cause a denial of service (memory acc… | Patch early | 4.3 medium | 2.2% | 2007-11-15 |
| CVE-2005-3208 EXP | Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execute arbitrary SQL code via (a) t… | Patch early | 6.8 medium | 2.2% | 2005-10-14 |
| CVE-2004-2670 EXP | Multiple cross-site scripting (XSS) vulnerabilities in mod.php in eNdonesia 8.3 allow remote attackers to inject arbitrary web script or HTML via (1)… | Patch early | 6.8 medium | 2.2% | 2004-12-31 |
| CVE-2008-7213 EXP | Cross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php in MOStlyCE before 2.4… | Patch early | 4.3 medium | 2.2% | 2009-09-11 |
| CVE-2018-9238 EXP | proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter. | Patch early | 6.1 medium | 2.2% | 2018-04-04 |
| CVE-2018-9857 EXP | PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" screen). | Patch early | 6.1 medium | 2.2% | 2018-04-09 |
| CVE-2006-4273 EXP | Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML by upload… | Patch early | 6.8 medium | 2.2% | 2006-08-21 |
| CVE-2015-8398 EXP | Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 6.1 medium | 2.2% | 2016-04-11 |
| CVE-2008-5621 EXP | Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unautho… | Patch early | 6.0 medium | 2.2% | 2008-12-17 |
| CVE-2008-7135 EXP | toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the IsChecked… | Patch early | 4.3 medium | 2.2% | 2009-09-01 |
| CVE-2003-1419 EXP | Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript… | Patch early | 4.3 medium | 2.2% | 2003-12-31 |
| CVE-2007-4635 EXP | Yahoo! Messenger 8.1.0.209 and 8.1.0.402 allows remote attackers to cause a denial of service (application crash) via certain file-transfer packets, p… | Patch early | 5.0 medium | 2.1% | 2007-08-31 |
| CVE-2013-7184 EXP | Gretech GOM Media Player 2.2.56.5158 and earlier allows remote attackers to cause a denial of service (memory corruption) via a crafted AVI file. | Patch early | 4.3 medium | 2.1% | 2014-01-24 |
| CVE-2012-4909 EXP | Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted application. | Patch early | 4.3 medium | 2.1% | 2012-09-13 |
| CVE-2018-6936 EXP | Cross Site Scripting (XSS) exists on the D-Link DIR-600M C1 3.01 via the SSID or the name of a user account. | Patch early | 5.4 medium | 2.1% | 2018-02-21 |
| CVE-2008-0158 EXP | Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to read arbitrary files via a ..… | Patch early | 5.0 medium | 2.1% | 2008-01-09 |
| CVE-2022-41413 EXP | perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted input into… | Patch early | 4.3 medium | 2.1% | 2022-11-30 |
| CVE-2006-1820 EXP | Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id paramete… | Patch early | 5.8 medium | 2.1% | 2006-04-18 |
| CVE-2021-3298 EXP | Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?a… | Patch early | 5.4 medium | 2.1% | 2021-01-29 |
| CVE-2006-6390 EXP | Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow… | Patch early | 6.8 medium | 2.1% | 2006-12-08 |
| CVE-2006-6153 EXP | Multiple cross-site scripting (XSS) vulnerabilities in vSpin.net Classified System 2004 allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 2.1% | 2006-11-28 |
| CVE-2006-1697 EXP | Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) Yo… | Patch early | 4.3 medium | 2.1% | 2006-04-11 |
| CVE-2006-1971 EXP | Cross-site scripting (XSS) vulnerability in login.php in KRANKIKOM ContentBoxX allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 2.1% | 2006-04-21 |
| CVE-2004-1640 EXP | Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 0.94 and 1.0 allow remote attackers to execute arbitrary web script and HTML via the (1)… | Patch early | 4.3 medium | 2.1% | 2004-08-28 |
| CVE-2005-3308 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Zomplog 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (… | Patch early | 4.3 medium | 2.1% | 2005-10-26 |
| CVE-2006-5958 EXP | Multiple cross-site scripting (XSS) vulnerabilities in INFINICART allow remote attackers to inject arbitrary web script or HTML via the (1) username a… | Patch early | 6.8 medium | 2.1% | 2006-11-17 |
| CVE-2006-6479 EXP | Multiple cross-site scripting (XSS) vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the email… | Patch early | 6.8 medium | 2.1% | 2006-12-12 |
| CVE-2006-6520 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Messageriescripthp 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1… | Patch early | 6.8 medium | 2.1% | 2006-12-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt