CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,247 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
171,177 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-0535 EXP | Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authentication of adm… | Patch early | 6.8 medium | 1.4% | 2011-02-08 |
| CVE-2005-0741 EXP | Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the username p… | Patch early | 4.3 medium | 1.4% | 2005-03-08 |
| CVE-2013-7057 EXP | Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to hijack the authentication of u… | Patch early | 6.8 medium | 1.4% | 2014-11-04 |
| CVE-2005-2011 EXP | Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web script or HTML, as demonstrated… | Patch early | 4.3 medium | 1.4% | 2005-06-20 |
| CVE-2004-0291 EXP | SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter. | Patch early | 5.0 medium | 1.4% | 2004-11-23 |
| CVE-2006-1034 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbitrary web script or HTML via (… | Patch early | 4.3 medium | 1.4% | 2006-03-07 |
| CVE-2014-10008 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Stark CRM 1.0 allow remote attackers to hijack the authentication of administrators for… | Patch early | 6.8 medium | 1.4% | 2015-01-13 |
| CVE-2018-10906 EXP | In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root user… | Patch early | 5.3 medium | 1.4% | 2018-07-24 |
| CVE-2024-51464 EXP | IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially crafted request, an authenticated a… | Patch early | 4.3 medium | 1.4% | 2024-12-21 |
| CVE-2014-2016 EXP | Multiple cross-site scripting (XSS) vulnerabilities in OXID eShop Professional and Community Edition 4.6.8 and earlier, 4.7.x before 4.7.11, and 4.8.x… | Patch early | 4.3 medium | 1.4% | 2014-03-25 |
| CVE-2006-5557 EXP | Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions allows local users to execute… | Patch early | 4.6 medium | 1.4% | 2006-10-27 |
| CVE-2016-7386 EXP | For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability… | Patch early | 5.5 medium | 1.4% | 2016-11-08 |
| CVE-2013-6852 EXP | Cross-site request forgery (CSRF) vulnerability in html/json.html on HP 2620 switches allows remote attackers to hijack the authentication of administ… | Patch early | 6.8 medium | 1.4% | 2013-11-22 |
| CVE-2013-2639 EXP | Cross-site scripting (XSS) vulnerability in CTERA Cloud Storage OS before 3.2.29.0, 3.2.42.0, and earlier allows remote attackers to inject arbitrary… | Patch early | 4.3 medium | 1.4% | 2014-02-11 |
| CVE-2013-6162 EXP | Cross-site scripting (XSS) vulnerability in Code-Crafters Ability Mail Server 3.1.1 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.4% | 2013-12-21 |
| CVE-2013-4624 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.4% | 2013-11-27 |
| CVE-2017-14712 EXP | In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter. | Patch early | 5.4 medium | 1.4% | 2017-09-22 |
| CVE-2017-14717 EXP | In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter. | Patch early | 5.4 medium | 1.4% | 2017-09-22 |
| CVE-2003-1031 EXP | Cross-site scripting (XSS) vulnerability in register.php for vBulletin 3.0 Beta 2 allows remote attackers to inject arbitrary HTML or web script via o… | Patch early | 4.3 medium | 1.4% | 2004-02-17 |
| CVE-2005-2318 EXP | Cross-site scripting (XSS) vulnerability in showerr.asp in DVBBS 7.1 SP2 allows remote attackers to inject arbitrary web script or HTML via the action… | Patch early | 4.3 medium | 1.4% | 2005-07-19 |
| CVE-2005-3397 EXP | Cross-site scripting (XSS) vulnerability in Comersus BackOffice allows remote attackers to inject arbitrary web script or HTML via the error parameter… | Patch early | 4.3 medium | 1.4% | 2005-11-01 |
| CVE-2012-1922 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Sitecom WLM-2501 allow remote attackers to hijack the authentication of administrators f… | Patch early | 6.8 medium | 1.4% | 2013-01-24 |
| CVE-2007-5316 EXP | SQL injection vulnerability in browsecats.php in Softbiz Jobs and Recruitment Script allows remote attackers to execute arbitrary SQL commands via the… | Patch early | 5.0 medium | 1.4% | 2007-10-09 |
| CVE-2014-0620 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 1.4% | 2014-01-08 |
| CVE-2020-29469 EXP | WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacker to inject the XSS payload in… | Patch early | 5.4 medium | 1.4% | 2020-12-30 |
| CVE-2005-2523 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.4% | 2005-08-19 |
| CVE-2005-2386 EXP | Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ 1.20 allows remote attackers to inject arbitrary web script or HTML via the messag… | Patch early | 4.3 medium | 1.4% | 2005-07-27 |
| CVE-2005-3083 EXP | Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 0.10 allows remote attackers to inject arbitrary web script or HTML via the p… | Patch early | 4.3 medium | 1.4% | 2005-09-27 |
| CVE-2005-3584 EXP | Cross-site scripting (XSS) vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to inject arbitrary web script or HTML via the for… | Patch early | 4.3 medium | 1.4% | 2005-11-16 |
| CVE-2005-4289 EXP | Cross-site scripting (XSS) vulnerability in EDCstore.pl in eDatCat 0.3 allows remote attackers to inject arbitrary web script or HTML via the user_act… | Patch early | 4.3 medium | 1.4% | 2005-12-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt