CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,289 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-11628 EXP | Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malicious attackers to send a crafte… | Patch early | 6.1 medium | 3.5% | 2018-06-01 |
| CVE-2006-4753 EXP | Directory traversal vulnerability in index.php in PHProg before 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang par… | Patch early | 5.0 medium | 3.5% | 2006-09-13 |
| CVE-2019-11398 EXP | Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 6.1 medium | 3.5% | 2019-05-08 |
| CVE-2005-3285 EXP | Cross-site scripting (XSS) vulnerability in comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus allows remote attackers to inject arbit… | Patch early | 4.3 medium | 3.5% | 2005-10-23 |
| CVE-2004-1698 EXP | The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via… | Patch early | 5.0 medium | 3.5% | 2004-09-24 |
| CVE-2006-6800 EXP | PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to execute arbitrary PHP code via… | Patch early | 6.8 medium | 3.5% | 2006-12-28 |
| CVE-2008-5160 EXP | Unspecified vulnerability in MyServer 0.8.11 allows remote attackers to cause a denial of service (daemon crash) via multiple invalid requests with th… | Patch early | 5.0 medium | 3.5% | 2008-11-18 |
| CVE-2007-2660 EXP | PHP remote file inclusion vulnerability in pcltrace.lib.php in the PclTar module in Vincent Blavet PhpConcept Library, as used in CJG EXPLORER PRO 3.3… | Patch early | 6.8 medium | 3.5% | 2007-05-14 |
| CVE-2006-4490 EXP | Multiple directory traversal vulnerabilities in Cybozu Office before 6.6 Build 1.3 and Share 360 before 2.5 Build 0.3 allow remote authenticated users… | Patch early | 4.0 medium | 3.5% | 2006-08-31 |
| CVE-2009-3173 EXP | Unrestricted file upload vulnerability in admin/add_album.php in The Rat CMS Alpha 2 allows remote attackers to execute arbitrary code by uploading a… | Patch early | 6.8 medium | 3.5% | 2009-09-11 |
| CVE-2009-0372 EXP | Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote authenticated users to execute… | Patch early | 6.5 medium | 3.5% | 2009-01-30 |
| CVE-2001-0276 EXP | ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly calling ext.dl… | Patch early | 6.4 medium | 3.5% | 2001-05-03 |
| CVE-2014-3878 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the web client interface in Ipswitch IMail Server 12.3 and 12.4, possibly before 12.4.1.15, all… | Patch early | 4.3 medium | 3.5% | 2014-06-05 |
| CVE-2008-2022 EXP | Mulatiple cross-site scripting (XSS) vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 3.5% | 2008-04-30 |
| CVE-2007-6028 EXP | Multiple stack-based buffer overflows in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne FlexGrid 7.1 Light allow remote attackers to cause… | Patch early | 6.8 medium | 3.5% | 2007-11-20 |
| CVE-2007-1513 EXP | PHP remote file inclusion vulnerability in comanda.php in GraFX Company WebSite Builder (CWB) PRO 1.9.8, when register_globals is enabled, allows remo… | Patch early | 6.8 medium | 3.5% | 2007-03-20 |
| CVE-2014-2598 EXP | Cross-site request forgery (CSRF) vulnerability in the Quick Page/Post Redirect plugin before 5.0.5 for WordPress allows remote attackers to hijack th… | Patch early | 6.8 medium | 3.5% | 2015-01-05 |
| CVE-2018-19933 EXP | Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry. | Patch early | 6.1 medium | 3.5% | 2018-12-17 |
| CVE-2006-6185 EXP | Directory traversal vulnerability in script.php in Wabbit PHP Gallery 0.9 allows remote attackers to read arbitrary files via a .. (dot dot) in the di… | Patch early | 5.0 medium | 3.5% | 2006-12-01 |
| CVE-2009-3748 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Web Administrator in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security… | Patch early | 4.3 medium | 3.5% | 2009-10-22 |
| CVE-2013-7097 EXP | Directory traversal vulnerability in 7 Media Web Solutions eduTrac before 1.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in… | Patch early | 5.0 medium | 3.5% | 2014-01-08 |
| CVE-2002-0227 EXP | KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message. | Patch early | 5.0 medium | 3.5% | 2002-05-16 |
| CVE-2009-3038 EXP | A certain ActiveX control in lnresobject.dll 7.1.1.119 in the Research In Motion (RIM) Lotus Notes connector for BlackBerry Desktop Manager 5.0.0.11 a… | Patch early | 4.3 medium | 3.5% | 2009-09-01 |
| CVE-2009-3247 EXP | Cross-site scripting (XSS) vulnerability in the Activities module in vtiger CRM 5.0.4 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 3.5% | 2009-09-18 |
| CVE-2009-4521 EXP | Cross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT) before 2.5.0, as used in KonaK… | Patch early | 4.3 medium | 3.5% | 2009-12-31 |
| CVE-2010-2147 EXP | Cross-site scripting (XSS) vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 3.5% | 2010-06-03 |
| CVE-2020-7108 EXP | The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field. | Patch early | 5.4 medium | 3.5% | 2020-01-16 |
| CVE-2006-5568 EXP | FtpXQ Server 3.0.1 allows remote attackers to cause a denial of service (CPU exhaustion) via a long MKD command. | Patch early | 5.0 medium | 3.5% | 2006-10-27 |
| CVE-2008-3210 EXP | rutil/dns/DnsStub.cxx in ReSIProcate 1.3.2, as used by repro, allows remote attackers to cause a denial of service (daemon crash) via a SIP (1) INVITE… | Patch early | 5.0 medium | 3.5% | 2008-07-18 |
| CVE-2007-0297 EXP | Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.47.11 and 8.48.06 has unknown impact and attack vectors in Pe… | Patch early | 4.0 medium | 3.5% | 2007-01-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt