CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,932 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
171,043 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-0260 EXP | minimal Gallery 0.8 allows remote attackers to obtain configuration information via a direct request to php_info.php, which calls the phpinfo function… | Patch early | 5.0 medium | 1.6% | 2008-01-15 |
| CVE-2008-7180 EXP | del_query1.php in Telephone Directory 2008 allows remote attackers to delete arbitrary contacts via a direct request with a modified id variable. | Patch early | 5.0 medium | 1.6% | 2009-09-08 |
| CVE-2012-2914 EXP | Cross-site scripting (XSS) vulnerability in captchademo.php in Unijimpe Captcha allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.6% | 2012-05-21 |
| CVE-2012-2941 EXP | Cross-site scripting (XSS) vulnerability in search/ in Yandex.Server 2010 9.0 Enterprise allows remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 1.6% | 2012-05-27 |
| CVE-2007-0925 EXP | Cross-site scripting (XSS) vulnerability in search/SearchResults.aspx in Community Server allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.6% | 2007-02-14 |
| CVE-2002-2343 EXP | Cross-site scripting (XSS) vulnerability in NOCC 0.9 through 0.9.5 allows remote attackers to inject arbitrary web script or HTML via email messages. | Patch early | 4.3 medium | 1.6% | 2002-12-31 |
| CVE-2012-1038 EXP | Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility System Software (MSS) 7.6.x b… | Patch early | 4.3 medium | 1.6% | 2013-04-03 |
| CVE-2025-6082 EXP | The Birth Chart Compatibility plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to ins… | Patch early | 5.3 medium | 1.6% | 2025-07-22 |
| CVE-2008-1174 EXP | Cross-site scripting (XSS) vulnerability in editUser.asp in AuthentiX 6.3b1 Trial allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.6% | 2008-03-06 |
| CVE-2006-6995 EXP | mycontacts.php in V3 Chat allows remote authenticated users to gain privileges as other users via a modified membername parameter. | Patch early | 6.0 medium | 1.6% | 2007-02-12 |
| CVE-2007-1902 EXP | Multiple SQL injection vulnerabilities in SonicBB 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) part and (2) by parameters… | Patch early | 6.8 medium | 1.6% | 2007-05-14 |
| CVE-2007-1231 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) d… | Patch early | 4.3 medium | 1.6% | 2007-03-03 |
| CVE-2013-4946 EXP | Multiple cross-site scripting (XSS) vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.6% | 2013-07-29 |
| CVE-2013-5314 EXP | Cross-site scripting (XSS) vulnerability in serendipity_admin_image_selector.php in Serendipity 1.6.2 and earlier allows remote attackers to inject ar… | Patch early | 4.3 medium | 1.6% | 2013-08-19 |
| CVE-2011-5108 EXP | Cross-site scripting (XSS) vulnerability in config.php in AdaptCMS 2.0.0 and 2.0.1 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.6% | 2012-08-23 |
| CVE-2011-5177 EXP | Multiple cross-site scripting (XSS) vulnerabilities in admin/controller.php in eSyndiCat Pro 2.3.05 allow remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 1.6% | 2012-09-20 |
| CVE-2012-5099 EXP | Cross-site scripting (XSS) vulnerability in list.php in PHPB2B 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.6% | 2012-09-23 |
| CVE-2012-5226 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Peel SHOPPING 2.8 and 2.9 allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.6% | 2012-10-01 |
| CVE-2012-5315 EXP | Multiple cross-site scripting (XSS) vulnerabilities in php ireport 1.0 allow remote attackers to inject arbitrary web script or HTML via the message p… | Patch early | 4.3 medium | 1.6% | 2012-10-08 |
| CVE-2012-6040 EXP | Cross-site scripting (XSS) vulnerability in users.php in File King Advanced File Management 1.4 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.6% | 2012-11-26 |
| CVE-2012-6513 EXP | Cross-site scripting (XSS) vulnerability in index.php/Admin_Preferences in gpEasy CMS 2.3.3 allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.6% | 2013-01-24 |
| CVE-2018-10580 EXP | The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displays that user's most recent po… | Patch early | 5.4 medium | 1.6% | 2018-05-11 |
| CVE-2003-0336 EXP | Qualcomm Eudora 5.2.1 allows remote attackers to read arbitrary files via an email message with a carriage return (CR) character in a spoofed "Attachm… | Patch early | 5.0 medium | 1.6% | 2003-05-22 |
| CVE-2006-5810 EXP | Cross-site scripting (XSS) vulnerability in modules/wfdownloads/newlist.php in XOOPS 1.0 allows remote attackers to inject arbitrary web script or HTM… | Patch early | 6.8 medium | 1.6% | 2006-11-08 |
| CVE-2010-0725 EXP | Cross-site scripting (XSS) vulnerability in showimg.php in Arab Cart 1.0.2.0 allows remote attackers to inject arbitrary web script or HTML via the id… | Patch early | 4.3 medium | 1.6% | 2010-02-26 |
| CVE-2010-1872 EXP | Cross-site scripting (XSS) vulnerability in cPlayer.php in FlashCard 2.6.5 and 3.0.1 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.6% | 2010-05-12 |
| CVE-2008-6259 EXP | Cross-site scripting (XSS) vulnerability in search.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attackers to inject arbitrary web s… | Patch early | 4.3 medium | 1.6% | 2009-02-24 |
| CVE-2012-1990 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric Kerweb before 3.0.1 and Kerwin before 6.0.1 allow remote attackers to inject… | Patch early | 4.3 medium | 1.6% | 2012-05-22 |
| CVE-2011-0546 EXP | Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, wh… | Patch early | 6.5 medium | 1.6% | 2011-05-31 |
| CVE-2012-2909 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Viscacha 0.8.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) text… | Patch early | 4.3 medium | 1.6% | 2012-05-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt