CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,851 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-6363 EXP | Cross-site scripting (XSS) vulnerability in admin.pl in BlueSocket Secure Controller (BSC) before 5.2, or without 5.1.1-BluePatch, allows remote attac… | Patch early | 6.8 medium | 2.4% | 2006-12-07 |
| CVE-2006-6451 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 6.8 medium | 2.4% | 2006-12-10 |
| CVE-2001-1259 EXP | Avaya Argent Office allows remote attackers to cause a denial of service by sending UDP packets to port 53 with no payload. | Patch early | 5.0 medium | 2.4% | 2001-08-07 |
| CVE-2005-4080 EXP | Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting… | Patch early | 4.3 medium | 2.4% | 2005-12-08 |
| CVE-2009-0374 EXP | Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to… | Patch early | 4.3 medium | 2.4% | 2009-01-30 |
| CVE-2010-0966 EXP | PHP remote file inclusion vulnerability in inc/config.php in deV!L`z Clanportal (DZCP) 1.5.2, when register_globals is enabled, allows remote attacker… | Patch early | 6.8 medium | 2.4% | 2010-03-16 |
| CVE-2005-0895 EXP | Netcomm 1300NB DSL Modem allows remote attackers to cause a denial of service (device hang) via a large number of ping packets. | Patch early | 5.0 medium | 2.4% | 2005-05-02 |
| CVE-2005-3002 EXP | Multi-Computer Control System (MCCS) 1.0 allows remote attackers to cause a denial of service via a malformed UDP packet. | Patch early | 5.0 medium | 2.4% | 2005-09-20 |
| CVE-2012-1912 EXP | Cross-site scripting (XSS) vulnerability in preferences.php in PHP Address Book 7.0 and earlier allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 2.4% | 2012-09-09 |
| CVE-2010-3437 EXP | Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users t… | Patch early | 6.6 medium | 2.4% | 2010-10-04 |
| CVE-2007-3523 EXP | Multiple directory traversal vulnerabilities in Module/Galerie.php in XCMS 1.1 allow remote attackers to include and execute arbitrary local files via… | Patch early | 6.4 medium | 2.4% | 2007-07-03 |
| CVE-2007-3772 EXP | Directory traversal vulnerability in news/show.php in PsNews 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot do… | Patch early | 6.4 medium | 2.4% | 2007-07-15 |
| CVE-2017-6982 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. The issue involves the "Notifications" component. It allows attacker… | Patch early | 5.5 medium | 2.4% | 2017-05-22 |
| CVE-2010-0983 EXP | PHP remote file inclusion vulnerability in include/mail.inc.php in Rezervi 3.0.2 and earlier, when register_globals is enabled, allows remote attacker… | Patch early | 6.8 medium | 2.4% | 2010-03-16 |
| CVE-2008-5938 EXP | PHP remote file inclusion vulnerability in assets/snippets/reflect/snippet.reflect.php in MODx CMS 0.9.6.2 and earlier, when magic_quotes_gpc is disab… | Patch early | 6.8 medium | 2.4% | 2009-01-22 |
| CVE-2022-29727 EXP | Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter. | Patch early | 5.4 medium | 2.4% | 2022-05-11 |
| CVE-2006-6941 EXP | index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to obtain sensitive information via an invalid action parameter in an info operatio… | Patch early | 5.0 medium | 2.4% | 2007-01-19 |
| CVE-2009-2181 EXP | Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attackers to inject arbitrary web s… | Patch early | 4.3 medium | 2.4% | 2009-06-23 |
| CVE-2012-4237 EXP | Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to execute arbit… | Patch early | 6.8 medium | 2.4% | 2012-08-20 |
| CVE-2007-3613 EXP | Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 2.4% | 2007-07-06 |
| CVE-2005-4880 EXP | Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain I… | Patch early | 5.0 medium | 2.4% | 2009-03-31 |
| CVE-2012-2588 EXP | Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 2.4% | 2014-09-19 |
| CVE-2008-3770 EXP | Multiple directory traversal vulnerabilities in Freeway 1.4.1.171, when register_globals is enabled, allow remote attackers to include and execute arb… | Patch early | 6.8 medium | 2.4% | 2008-08-22 |
| CVE-2006-1568 EXP | Multiple cross-site scripting (XSS) vulnerabilities in register.php in RedCMS 0.1 allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 5.1 medium | 2.4% | 2006-04-01 |
| CVE-2009-2116 EXP | Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to list directory contents via a .… | Patch early | 4.0 medium | 2.4% | 2009-06-18 |
| CVE-2008-2352 EXP | Directory traversal vulnerability in index.php in Smeego 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitr… | Patch early | 6.8 medium | 2.4% | 2008-05-20 |
| CVE-2008-5570 EXP | Directory traversal vulnerability in index.php in PHP Multiple Newsletters 2.7, when magic_quotes_gpc is disabled, allows remote attackers to include… | Patch early | 6.8 medium | 2.4% | 2008-12-15 |
| CVE-2008-5604 EXP | Directory traversal vulnerability in index.php in My Simple Forum 3.0 and 4.1, when magic_quotes_gpc is disabled, allows remote attackers to include a… | Patch early | 6.8 medium | 2.4% | 2008-12-16 |
| CVE-2007-0301 EXP | PHP remote file inclusion vulnerability in _admin/admin_menu.php in FdWeB Espace Membre 2.1 and earlier allows remote attackers to execute arbitrary P… | Patch early | 6.8 medium | 2.4% | 2007-01-18 |
| CVE-2012-4262 EXP | Multiple cross-site scripting (XSS) vulnerabilities in myCare2x allow remote attackers to inject arbitrary web script or HTML via the (1) name_last, (… | Patch early | 4.3 medium | 2.4% | 2012-08-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt