CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,932 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
171,043 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-2911 EXP | Cross-site scripting (XSS) vulnerability in backupDB.php in SiliSoftware backupDB() 1.2.7a allows remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 1.6% | 2012-05-21 |
| CVE-2012-2918 EXP | Cross-site scripting (XSS) vulnerability in Upload/engine.php in Chevereto 1.91 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.6% | 2012-05-21 |
| CVE-2003-20001 EXP | An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an external ca… | Patch early | 5.6 medium | 1.6% | 2025-04-01 |
| CVE-2018-14869 EXP | PHP Template Store Script 3.0.6 allows XSS via the Address line 1, Address Line 2, Bank name, or A/C Holder name field in a profile. | Patch early | 5.4 medium | 1.6% | 2018-08-06 |
| CVE-2002-2341 EXP | Cross-site scripting (XSS) vulnerability in content blocking in SonicWALL SOHO3 6.3.0.0 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.6% | 2002-12-31 |
| CVE-2002-2362 EXP | Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the no… | Patch early | 4.3 medium | 1.6% | 2002-12-31 |
| CVE-2007-1142 EXP | Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the link_paramete… | Patch early | 4.3 medium | 1.6% | 2007-03-02 |
| CVE-2011-5026 EXP | Cross-site scripting (XSS) vulnerability in the addPost function in data/functions.php in Winn GuestBook before 2.4.8d allows remote attackers to inje… | Patch early | 4.3 medium | 1.6% | 2011-12-29 |
| CVE-2008-4426 EXP | Cross-site scripting (XSS) vulnerability in events.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to inject arbitr… | Patch early | 4.3 medium | 1.6% | 2008-10-03 |
| CVE-2010-1950 EXP | SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows rem… | Patch early | 6.8 medium | 1.6% | 2010-05-19 |
| CVE-2010-2613 EXP | Cross-site scripting (XSS) vulnerability in the JExtensions JE Awd Song (com_awd_song) component for Joomla! allows remote attackers to inject arbitra… | Patch early | 4.3 medium | 1.6% | 2010-07-02 |
| CVE-2008-6087 EXP | Cross-site scripting (XSS) vulnerability in topic.php in Camera Life 2.6.2b4 allows remote attackers to inject arbitrary web script or HTML via the na… | Patch early | 4.3 medium | 1.6% | 2009-02-06 |
| CVE-2008-6529 EXP | Cross-site scripting (XSS) vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.6% | 2009-03-26 |
| CVE-2006-1912 EXP | MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to i… | Patch early | 5.8 medium | 1.6% | 2006-04-20 |
| CVE-2012-1782 EXP | Multiple cross-site scripting (XSS) vulnerabilities in questions/ask in OSQA 3b allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.6% | 2012-03-19 |
| CVE-2015-3214 EXP | The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, wh… | Patch early | 6.9 medium | 1.6% | 2015-08-31 |
| CVE-2005-3555 EXP | Multiple SQL injection vulnerabilities in PHPlist 2.10.1 and earlier allow authenticated remote attackers with administrator privileges to execute arb… | Patch early | 6.5 medium | 1.6% | 2005-11-16 |
| CVE-2024-1234 EXP | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute in all versions up to, and inc… | Patch early | 6.4 medium | 1.6% | 2024-03-13 |
| CVE-2024-41358 EXP | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php. | Patch early | 6.1 medium | 1.6% | 2024-08-29 |
| CVE-1999-0672 EXP | Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics. | Patch early | 5.1 medium | 1.6% | 1999-08-01 |
| CVE-1999-0673 EXP | Buffer overflow in ALMail32 POP3 client via From: or To: headers. | Patch early | 5.1 medium | 1.6% | 1999-08-08 |
| CVE-1999-0685 EXP | Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option. | Patch early | 5.1 medium | 1.6% | 1999-09-02 |
| CVE-2007-0023 EXP | The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows loca… | Patch early | 6.9 medium | 1.6% | 2007-01-24 |
| CVE-2002-2321 EXP | Cross-site scripting (XSS) vulnerability in (1) showcat.php and (2) addyoursite.php in phpLinkat 0.1.0 allows remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 1.6% | 2002-12-31 |
| CVE-2007-1151 EXP | Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter to the top… | Patch early | 4.3 medium | 1.6% | 2007-03-02 |
| CVE-2024-46528 EXP | An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x before 4.1… | Patch early | 4.3 medium | 1.6% | 2024-10-14 |
| CVE-2006-6733 EXP | Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 1.6% | 2006-12-26 |
| CVE-2008-1463 EXP | Cross-site scripting (XSS) vulnerability in the management GUI in Imperva SecureSphere MX Management Server 5.0 allows remote attackers to inject arbi… | Patch early | 4.3 medium | 1.6% | 2008-03-24 |
| CVE-2019-13493 EXP | In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded fi… | Patch early | 5.4 medium | 1.6% | 2019-07-17 |
| CVE-2019-15814 EXP | Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or HTML. | Patch early | 5.4 medium | 1.6% | 2019-09-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt