CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,734 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
170,949 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-6949 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Collabtive 0.4.8 allow remote attackers to hijack the authentication of administrators f… | Patch early | 6.8 medium | 1.8% | 2009-08-12 |
| CVE-2009-1230 EXP | Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary P… | Patch early | 6.5 medium | 1.8% | 2009-04-02 |
| CVE-2006-2051 EXP | Multiple cross-site scripting (XSS) vulnerabilities in myadmin/index.php in NextAge Shopping Cart allow remote attackers to inject arbitrary web scrip… | Patch early | 5.8 medium | 1.8% | 2006-04-26 |
| CVE-2006-2176 EXP | Multiple cross-site scripting (XSS) vulnerabilities in links.php in PHP Linkliste 1.0b allow remote attackers to inject arbitrary web script or HTML v… | Patch early | 5.8 medium | 1.8% | 2006-05-04 |
| CVE-2006-3405 EXP | Cross-site scripting (XSS) vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1)… | Patch early | 5.8 medium | 1.8% | 2006-07-07 |
| CVE-2016-3139 EXP | The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial o… | Patch early | 4.6 medium | 1.8% | 2016-04-27 |
| CVE-2016-3140 EXP | The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a… | Patch early | 4.6 medium | 1.8% | 2016-05-02 |
| CVE-2007-5426 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ActiveKB NX 2.5.4 allow remote attackers to inject arbitrary web script or HTML via the page pa… | Patch early | 4.3 medium | 1.8% | 2007-10-12 |
| CVE-2007-5562 EXP | Cross-site scripting (XSS) vulnerability in cgi-bin/welcome (aka the login page) in Netgear SSL312 PROSAFE SSL VPN-Concentrator 25 allows remote attac… | Patch early | 4.3 medium | 1.8% | 2007-10-18 |
| CVE-2004-1418 EXP | Cross-site scripting (XSS) vulnerability in WPKontakt 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an e-mail a… | Patch early | 4.3 medium | 1.8% | 2004-12-31 |
| CVE-2009-1458 EXP | Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in razorCMS before 0.4 allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.8% | 2009-04-28 |
| CVE-2008-1180 EXP | Cross-site scripting (XSS) vulnerability in dana-na/auth/rdremediate.cgi in Juniper Networks Secure Access 2000 5.5 R1 build 11711 allows remote attac… | Patch early | 4.3 medium | 1.8% | 2008-03-06 |
| CVE-2008-2187 EXP | Cross-site scripting (XSS) vulnerability in mjguest.php in Mjguest 6.7 GT Rev.01 allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 1.8% | 2008-05-13 |
| CVE-2008-4393 EXP | Cross-site scripting (XSS) vulnerability in VeriSign Kontiki Delivery Management System (DMS) 5.0 and earlier allows remote attackers to inject arbitr… | Patch early | 4.3 medium | 1.8% | 2008-10-07 |
| CVE-2008-4742 EXP | Multiple cross-site scripting (XSS) vulnerabilities in interface/Login.php in TimeTrex 2.2.11 allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.8% | 2008-10-27 |
| CVE-2010-4836 EXP | Cross-site scripting (XSS) vulnerability in register.html in PHPShop 2.1 EE and earlier allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.8% | 2011-09-14 |
| CVE-2006-6936 EXP | Cross-site scripting (XSS) vulnerability in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary HTML or web script via (1) the catnam… | Patch early | 6.8 medium | 1.8% | 2007-01-17 |
| CVE-2018-1186 EXP | Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a… | Patch early | 4.8 medium | 1.8% | 2018-03-26 |
| CVE-2018-1187 EXP | Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6 is affected by a cross-site scripting vulnerability in th… | Patch early | 4.8 medium | 1.8% | 2018-03-26 |
| CVE-2009-2772 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PG Roommate Finder Solution allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.8% | 2009-08-14 |
| CVE-2018-8772 EXP | Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen. | Patch early | 6.1 medium | 1.8% | 2018-04-10 |
| CVE-2010-5046 EXP | Cross-site scripting (XSS) vulnerability in admin.php in ecoCMS allows remote attackers to inject arbitrary web script or HTML via the p parameter. | Patch early | 4.3 medium | 1.8% | 2011-11-23 |
| CVE-2007-5370 EXP | Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/dnewsweb.exe in NetWin DNewsWeb (DNews News Server) 57e1 allow remote attackers to inje… | Patch early | 4.3 medium | 1.8% | 2007-10-11 |
| CVE-2007-5944 EXP | Cross-site scripting (XSS) vulnerability in Servlet Engine / Web Container in IBM WebSphere Application Server (WAS) 5.1.1.4 through 5.1.1.16 allows r… | Patch early | 4.3 medium | 1.8% | 2007-11-14 |
| CVE-2023-0938 EXP | A vulnerability classified as critical has been found in SourceCodester Music Gallery Site 1.0. This affects an unknown part of the file music_list.ph… | Patch early | 6.3 medium | 1.8% | 2023-02-21 |
| CVE-2005-1895 EXP | Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or back param… | Patch early | 4.3 medium | 1.8% | 2005-06-09 |
| CVE-2012-1787 EXP | Multiple cross-site scripting (XSS) vulnerabilities in wgarcmin.cgi in Webglimpse 2.20.0 and earlier allow remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 1.8% | 2012-03-19 |
| CVE-2012-2903 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 7.0 and earlier allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.8% | 2012-05-21 |
| CVE-2012-5992 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow remote attacke… | Patch early | 6.8 medium | 1.8% | 2012-12-19 |
| CVE-2005-0883 EXP | Multiple cross-site scripting (XSS) vulnerabilities in base.php for DigitalHive 2.0 allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.8% | 2005-03-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt