CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,729 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
170,949 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-2712 EXP | Cross-site scripting (XSS) vulnerability in services/get_article.php in KrisonAV CMS before 3.0.2 allows remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 1.8% | 2014-05-23 |
| CVE-2007-1553 EXP | admin/configuration.php in Guestbara 1.2 and earlier allows remote attackers to modify the e-mail, name, and password of the admin account by setting… | Patch early | 5.0 medium | 1.8% | 2007-03-20 |
| CVE-2010-1146 EXP | The Linux kernel 2.6.33.2 and earlier, when a ReiserFS filesystem exists, does not restrict read or write access to the .reiserfs_priv directory, whic… | Patch early | 6.9 medium | 1.8% | 2010-04-12 |
| CVE-2006-1979 EXP | Cross-site scripting (XSS) vulnerability in mwguest.php in Manic Web MWGuest 2.1.0 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 5.8 medium | 1.8% | 2006-04-21 |
| CVE-2007-1248 EXP | Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.8% | 2007-03-03 |
| CVE-2012-2569 EXP | Cross-site scripting (XSS) vulnerability in Synametrics Technologies Xeams 4.4 Build 5720 allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.8% | 2014-06-19 |
| CVE-2012-2592 EXP | Cross-site scripting (XSS) vulnerability in Axigen Mail Server 8.0.1 allows remote attackers to inject arbitrary web script or HTML via the body of an… | Patch early | 4.3 medium | 1.8% | 2014-06-18 |
| CVE-2014-10018 EXP | Cross-site scripting (XSS) vulnerability in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem allows remote attackers to in… | Patch early | 4.3 medium | 1.8% | 2015-01-13 |
| CVE-2008-2224 EXP | Multiple PHP remote file inclusion vulnerabilities in SazCart 1.5.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP… | Patch early | 6.8 medium | 1.8% | 2008-05-14 |
| CVE-2010-0678 EXP | PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, when register_globals is en… | Patch early | 6.8 medium | 1.8% | 2010-02-22 |
| CVE-2008-6305 EXP | PHP remote file inclusion vulnerability in init.php in Free Directory Script 1.1.1, when register_globals is enabled, allows remote attackers to execu… | Patch early | 6.8 medium | 1.8% | 2009-02-26 |
| CVE-2008-6431 EXP | Multiple cross-site scripting (XSS) vulnerabilities in BMForum 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) outpused… | Patch early | 4.3 medium | 1.8% | 2009-03-06 |
| CVE-2007-2337 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS 0.96.6 Alpha and earlier allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.8% | 2007-04-27 |
| CVE-2006-2696 EXP | Cross-site scripting (XSS) vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) startl… | Patch early | 6.8 medium | 1.8% | 2006-05-31 |
| CVE-2006-2052 EXP | Cross-site scripting (XSS) vulnerability in Verosky Media Instant Photo Gallery allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 5.8 medium | 1.8% | 2006-04-26 |
| CVE-2012-5919 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Havalite 1.0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 1.8% | 2012-11-19 |
| CVE-2007-0890 EXP | Cross-site scripting (XSS) vulnerability in scripts/passwdmysql in cPanel WebHost Manager (WHM) 11.0.0 and earlier allows remote attackers to inject a… | Patch early | 4.3 medium | 1.8% | 2007-02-12 |
| CVE-2007-0225 EXP | Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to inject arbitrary web… | Patch early | 6.8 medium | 1.8% | 2007-01-13 |
| CVE-2012-4685 EXP | Cross-site scripting (XSS) vulnerability in Arbor Networks Peakflow SP 5.1.1 before patch 6, 5.5 before patch 4, and 5.6.0 before patch 1 allows remot… | Patch early | 4.3 medium | 1.8% | 2012-08-28 |
| CVE-2008-2637 EXP | Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN 6.0.2 hotfix 3, and possibly earlier versions, allow remote attackers to in… | Patch early | 4.3 medium | 1.8% | 2008-06-10 |
| CVE-2007-4874 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SimpNews 2.41.03 allow remote attackers to inject arbitrary web script or HTML via the (1) l_us… | Patch early | 4.3 medium | 1.8% | 2007-09-26 |
| CVE-2009-0294 EXP | Multiple PHP remote file inclusion vulnerabilities in WB News 2.0.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP… | Patch early | 6.8 medium | 1.8% | 2009-01-27 |
| CVE-2010-1351 EXP | Multiple PHP remote file inclusion vulnerabilities in Nodesforum 1.033 and 1.045, when register_globals is enabled, allow remote attackers to execute… | Patch early | 6.8 medium | 1.8% | 2010-04-12 |
| CVE-2008-6442 EXP | Insecure method vulnerability in Sina Inc. DLoader Class ActiveX Control allows remote attackers to overwrite arbitrary files via a URL in the first p… | Patch early | 5.8 medium | 1.8% | 2009-03-09 |
| CVE-2017-11320 EXP | Persistent XSS through the SSID of nearby Wi-Fi devices on Technicolor TC7337 routers 08.89.17.20.00 allows an attacker to cause DNS Poisoning and ste… | Patch early | 6.1 medium | 1.8% | 2017-08-03 |
| CVE-2012-5700 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.2f allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.8% | 2014-09-22 |
| CVE-2021-24272 EXP | The fitness calculators WordPress plugin before 1.9.6 add calculators for Water intake, BMI calculator, protein Intake, and Body Fat and was lacking C… | Patch early | 4.3 medium | 1.8% | 2021-05-05 |
| CVE-2014-10009 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Stark CRM 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) first_n… | Patch early | 4.3 medium | 1.8% | 2015-01-13 |
| CVE-2016-2188 EXP | The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial… | Patch early | 4.6 medium | 1.8% | 2016-05-02 |
| CVE-2008-6740 EXP | PHP remote file inclusion vulnerability in html/admin/modules/plugin_admin.php in HoMaP-CMS 0.1 allows remote attackers to execute arbitrary PHP code… | Patch early | 6.8 medium | 1.8% | 2009-04-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt