CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,164 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
208,188 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-3848 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allow remot… | Patch early | 4.3 medium | 2.5% | 2012-07-31 |
| CVE-2006-0470 EXP | Cross-site scripting (XSS) vulnerability in search.php in MyBulletinBoard (MyBB) 1.02 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 2.5% | 2006-01-31 |
| CVE-2016-3670 EXP | Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1 allows remote attackers to in… | Patch early | 6.1 medium | 2.5% | 2016-06-13 |
| CVE-2000-0075 EXP | Super Mail Transfer Package (SMTP), later called MsgCore, has a memory leak which allows remote attackers to cause a denial of service by repeating mu… | Patch early | 5.0 medium | 2.5% | 2000-01-13 |
| CVE-2010-1735 EXP | The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service… | Patch early | 4.9 medium | 2.5% | 2010-05-06 |
| CVE-2026-61447 EXP | PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without… | Patch early | 10.0 critical | 2.5% | 2026-07-11 |
| CVE-2026-65008 EXP | Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), wh… | Patch early | 9.8 critical | 2.5% | 2026-07-21 |
| CVE-2006-1661 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SKForum 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (… | Patch early | 6.8 medium | 2.5% | 2006-04-07 |
| CVE-2017-7950 EXP | Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX file. | Patch early | 5.5 medium | 2.5% | 2017-07-07 |
| CVE-2002-2349 EXP | phpinfo.php in phpBBmod 1.3.3 executes the phpinfo function, which allows remote attackers to obtain sensitive environment information. | Patch early | 5.0 medium | 2.5% | 2002-12-31 |
| CVE-2010-1065 EXP | Lebisoft Ziyaretci Defteri 7.4 and 7.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers… | Patch early | 5.0 medium | 2.5% | 2010-03-23 |
| CVE-2010-1067 EXP | E-membres 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database v… | Patch early | 5.0 medium | 2.5% | 2010-03-23 |
| CVE-2007-3198 EXP | Cross-site scripting (XSS) vulnerability in comments.php in Maran PHP Blog (Maran Blog), possibly only versions before 20070610, allows remote attacke… | Patch early | 4.3 medium | 2.5% | 2007-06-12 |
| CVE-2022-29296 EXP | A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attackers to execute arbitrary web s… | Patch early | 6.1 medium | 2.5% | 2022-06-06 |
| CVE-2019-11504 EXP | Zotonic before version 0.47 has mod_admin XSS. | Patch early | 4.8 medium | 2.5% | 2019-04-24 |
| CVE-2008-1772 EXP | iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sensitive information. | Patch early | 5.0 medium | 2.5% | 2008-04-14 |
| CVE-2007-1934 EXP | Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to include and execute arbitrary local… | Patch early | 6.8 medium | 2.5% | 2007-04-10 |
| CVE-2005-0700 EXP | The export_index action in myadmin.php for Aztek Forum 4.0 allows remote attackers to obtain database files, possibly by setting the ATK_ADMIN cookie. | Patch early | 5.0 medium | 2.5% | 2005-03-07 |
| CVE-2000-1129 EXP | McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field. | Patch early | 5.0 medium | 2.5% | 2001-01-09 |
| CVE-2012-6044 EXP | M-Player 0.4 allows remote attackers to cause a denial of service (crash) via a crafted MP3 file. | Patch early | 4.3 medium | 2.5% | 2012-11-26 |
| CVE-2014-9243 EXP | Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) QU… | Patch early | 4.3 medium | 2.5% | 2014-12-03 |
| CVE-2006-3616 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Carbonize Lazarus Guestbook 1.6 and earlier allow remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 2.5% | 2006-07-18 |
| CVE-2010-1905 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allow remote attackers to inj… | Patch early | 4.3 medium | 2.5% | 2010-05-12 |
| CVE-2008-6540 EXP | DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey valu… | Patch early | 5.1 medium | 2.5% | 2009-03-30 |
| CVE-2000-1154 EXP | RHConsole in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request. | Patch early | 5.0 medium | 2.5% | 2001-01-09 |
| CVE-2012-2955 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and… | Patch early | 4.3 medium | 2.5% | 2012-07-20 |
| CVE-2018-15608 EXP | Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen. | Patch early | 6.1 medium | 2.5% | 2018-08-28 |
| CVE-2007-6632 EXP | showCode.php in xml2owl 0.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter. | Patch early | 6.8 medium | 2.5% | 2008-01-04 |
| CVE-2018-12111 EXP | Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 6.1 medium | 2.5% | 2018-06-11 |
| CVE-2019-13029 EXP | Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 before 8.10.20 and 9 before 9.1.2 allow an attacker… | Patch early | 4.8 medium | 2.5% | 2019-07-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt