CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,746 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
170,956 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-35133 EXP | IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open… | Patch early | 6.8 medium | 1.8% | 2024-08-29 |
| CVE-2014-6420 EXP | Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web script or HTML via the name of a… | Patch early | 6.1 medium | 1.8% | 2019-12-27 |
| CVE-2009-4554 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitrary web script or HTML via (1)… | Patch early | 4.3 medium | 1.8% | 2010-01-04 |
| CVE-2008-6437 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeForum 1.0 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.8% | 2009-03-06 |
| CVE-2009-1288 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with B… | Patch early | 4.3 medium | 1.8% | 2009-04-13 |
| CVE-2007-4022 EXP | Cross-site scripting (XSS) vulnerability in frontend/x/htaccess/changepro.html in cPanel 10.9.1 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.8% | 2007-07-26 |
| CVE-2007-5480 EXP | Multiple cross-site scripting (XSS) vulnerabilities in InnovaAge InnovaShop allow remote attackers to inject arbitrary web script or HTML via the (1)… | Patch early | 4.3 medium | 1.8% | 2007-10-16 |
| CVE-2007-6574 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1)… | Patch early | 4.3 medium | 1.8% | 2007-12-28 |
| CVE-2005-4490 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SCOOP! 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1… | Patch early | 4.3 medium | 1.8% | 2005-12-22 |
| CVE-2005-1000 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the bid para… | Patch early | 4.3 medium | 1.8% | 2005-05-02 |
| CVE-2006-3607 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner Exchange Script (aka Banner Exchange Network Script) 1.0 allow remote attackers… | Patch early | 4.3 medium | 1.8% | 2006-07-18 |
| CVE-2005-4415 EXP | Cross-site scripting (XSS) vulnerability in index.php in TML CMS 0.5 allows remote attackers to inject arbitrary web script or HTML via the form param… | Patch early | 4.3 medium | 1.8% | 2005-12-20 |
| CVE-2006-0136 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the guestbook module in modules.php in Phanatic Softwares Chimera Web Portal System 0.2 allow r… | Patch early | 4.3 medium | 1.8% | 2006-01-09 |
| CVE-2019-9701 EXP | DLP 15.5 MP1 and all prior versions may be susceptible to a cross-site scripting (XSS) vulnerability, a type of issue that can enable attackers to inj… | Patch early | 4.8 medium | 1.8% | 2019-06-19 |
| CVE-2018-19913 EXP | DomainMOD through 4.11.01 has XSS via the assets/add/registrar-accounts.php UserName, Reseller ID, or notes field. | Patch early | 4.8 medium | 1.8% | 2018-12-06 |
| CVE-2006-6020 EXP | Cross-site scripting (XSS) vulnerability in announce.php in Blog Torrent Preview 0.92 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 6.8 medium | 1.8% | 2006-11-21 |
| CVE-2006-6272 EXP | Cross-site scripting (XSS) vulnerability in sp_index.php in Simple PHP Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 6.8 medium | 1.8% | 2006-12-04 |
| CVE-2006-6768 EXP | Multiple cross-site scripting (XSS) vulnerabilities in default.asp in PWP Technologies The Classified Ad System allow remote attackers to inject arbit… | Patch early | 6.8 medium | 1.8% | 2006-12-27 |
| CVE-2006-6845 EXP | Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 6.8 medium | 1.8% | 2006-12-31 |
| CVE-2006-6851 EXP | Multiple cross-site scripting (XSS) vulnerabilities in contact_us.php in ac4p Mobilelib gold 2 allow remote attackers to inject arbitrary web script o… | Patch early | 6.8 medium | 1.8% | 2006-12-31 |
| CVE-2006-7004 EXP | Cross-site scripting (XSS) vulnerability in email_request.php in PSY Auction allows remote attackers to inject arbitrary web script or HTML via the us… | Patch early | 6.8 medium | 1.8% | 2007-02-12 |
| CVE-2007-0054 EXP | Cross-site scripting (XSS) vulnerability in gbrowse.php in Belchior Foundry vCard PRO allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 6.8 medium | 1.8% | 2007-01-04 |
| CVE-2024-23922 EXP | Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to… | Patch early | 6.8 medium | 1.8% | 2024-09-23 |
| CVE-2007-2256 EXP | Cross-site scripting (XSS) vulnerability in you.php in TJSChat 0.95 allows remote attackers to inject arbitrary web script or HTML via the user parame… | Patch early | 4.3 medium | 1.8% | 2007-04-25 |
| CVE-2007-2887 EXP | Cross-site scripting (XSS) vulnerability in index.php in Web Icerik Yonetim Sistemi (WIYS) 1.0 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.8% | 2007-05-30 |
| CVE-2009-2569 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Verlihub Control Panel (VHCP) 1.7e allow remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 1.8% | 2009-07-22 |
| CVE-2008-0982 EXP | Spyce - Python Server Pages (PSP) 2.1.3 allows remote attackers to obtain sensitive information via a direct request for spyce/examples/automaton.spy,… | Patch early | 5.8 medium | 1.8% | 2008-02-25 |
| CVE-2018-7273 EXP | In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables using printk calls within the fun… | Patch early | 5.5 medium | 1.8% | 2018-02-21 |
| CVE-2007-4252 EXP | Absolute path traversal vulnerability in a certain ActiveX control in CkString.dll 1.1 and earlier in CHILKAT ASP String allows remote attackers to cr… | Patch early | 4.3 medium | 1.8% | 2007-08-08 |
| CVE-2008-4120 EXP | Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.804 allow remote attackers to inject arbitrary web script or HTML via the (1) user… | Patch early | 4.3 medium | 1.8% | 2008-09-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt