CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,893 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-4647 EXP | newswire/uploadmedia.cgi in 2coolcode Our Space (Ourspace) 2.0.9 allows remote attackers to upload certain files via unspecified vectors, probably inv… | Patch early | 5.0 medium | 2.4% | 2007-08-31 |
| CVE-2008-4740 EXP | Directory traversal vulnerability in templater.php in the ZZ_Templater module in TinyCMS 1.1.2, when register_globals is enabled and magic_quotes_gpc… | Patch early | 5.1 medium | 2.4% | 2008-10-27 |
| CVE-2018-9173 EXP | Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitr… | Patch early | 6.1 medium | 2.4% | 2018-04-02 |
| CVE-2007-6582 EXP | Directory traversal vulnerability in index.php in mBlog 1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter i… | Patch early | 6.4 medium | 2.4% | 2007-12-28 |
| CVE-2006-5065 EXP | PHP remote file inclusion vulnerability in libs/dbmax/mysql.php in ZoomStats 1.0.2 and earlier, when register_globals is enabled, allows remote attack… | Patch early | 5.1 medium | 2.4% | 2006-09-28 |
| CVE-2018-0901 EXP | The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold… | Patch early | 4.7 medium | 2.4% | 2018-03-14 |
| CVE-2011-0773 EXP | Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 2.4% | 2011-02-04 |
| CVE-1999-0683 EXP | Denial of service in Gauntlet Firewall via a malformed ICMP packet. | Patch early | 5.0 medium | 2.4% | 1999-07-30 |
| CVE-2009-0080 EXP | The ThreadPool class in Windows Vista Gold and SP1, and Server 2008, does not properly implement isolation among a set of distinct processes that (1)… | Patch early | 6.9 medium | 2.4% | 2009-04-15 |
| CVE-2008-3127 EXP | PHP remote file inclusion vulnerability in hioxBannerRotate.php in HIOX Banner Rotator (HBR) 1.3, when register_globals is enabled, allows remote atta… | Patch early | 6.8 medium | 2.4% | 2008-07-10 |
| CVE-2021-24664 EXP | The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them… | Patch early | 4.8 medium | 2.4% | 2021-11-08 |
| CVE-2007-6054 EXP | Cross-site scripting (XSS) vulnerability in the login page in the management interface in the Aruba 800 Mobility Controller 2.5.4.18 and earlier, and… | Patch early | 4.3 medium | 2.4% | 2007-11-20 |
| CVE-2008-0798 EXP | Multiple directory traversal vulnerabilities in artmedic webdesign weblog 1.0, when magic_quotes_gpc is disabled, allow remote attackers to read arbit… | Patch early | 4.3 medium | 2.4% | 2008-02-15 |
| CVE-2008-3589 EXP | Directory traversal vulnerability in download.php in moziloCMS 1.10.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary fi… | Patch early | 4.3 medium | 2.4% | 2008-08-11 |
| CVE-2007-5120 EXP | Multiple cross-site scripting (XSS) vulnerabilities in JSPWiki 2.4.103 and 2.5.139-beta allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 2.4% | 2007-09-27 |
| CVE-2018-11532 EXP | An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field. | Patch early | 6.1 medium | 2.4% | 2018-05-29 |
| CVE-2008-7246 EXP | Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a… | Patch early | 5.0 medium | 2.4% | 2009-09-18 |
| CVE-2009-0321 EXP | Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a l… | Patch early | 4.3 medium | 2.4% | 2009-01-28 |
| CVE-2006-1334 EXP | Multiple SQL injection vulnerabilities in Maian Weblog 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) entry and (2) email pa… | Patch early | 6.4 medium | 2.4% | 2006-03-21 |
| CVE-2013-2559 EXP | SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter to… | Patch early | 6.5 medium | 2.4% | 2014-03-27 |
| CVE-2012-1507 EXP | Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.7 allow remote attackers to inject arbitrary web script or HTML via the (1)… | Patch early | 4.3 medium | 2.4% | 2014-09-17 |
| CVE-2007-2801 EXP | Multiple cross-site scripting (XSS) vulnerabilities in open.php in eTicket 1.5.5 and 1.5.5.1, when register_globals is enabled, allow remote attackers… | Patch early | 4.3 medium | 2.4% | 2007-06-30 |
| CVE-2006-6644 EXP | PHP remote file inclusion vulnerability in pages/meeting_constants.php in the Meeting (mx_meeting) 1.1.2 and earlier module for mxBB allows remote att… | Patch early | 6.8 medium | 2.4% | 2006-12-20 |
| CVE-2006-6650 EXP | PHP remote file inclusion vulnerability in charts_constants.php in the Charts (mx_charts) 1.0.0 and earlier module for mxBB allows remote attackers to… | Patch early | 6.8 medium | 2.4% | 2006-12-20 |
| CVE-2012-4679 EXP | Cross-site scripting (XSS) vulnerability in admin/login.php in Newscoop before 3.5.5 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 2.4% | 2012-08-27 |
| CVE-2010-2336 EXP | index.php in Yamamah Photo Gallery 1.00 allows remote attackers to obtain the source code of executable files within the web document root via the dow… | Patch early | 5.0 medium | 2.4% | 2010-06-18 |
| CVE-2019-3501 EXP | The OUGC Awards plugin before 1.8.19 for MyBB allows XSS via a crafted award reason that is mishandled on the awards page or in a user profile. | Patch early | 4.8 medium | 2.4% | 2019-01-02 |
| CVE-2002-1230 EXP | NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem… | Patch early | 4.6 medium | 2.4% | 2002-11-04 |
| CVE-2008-2198 EXP | PHP remote file inclusion vulnerability in kmitaadmin/kmitat/htmlcode.php in Kmita Tellfriend 2.0 and earlier, when register_globals is enabled, allow… | Patch early | 6.8 medium | 2.4% | 2008-05-14 |
| CVE-2008-0357 EXP | Directory traversal vulnerability in pages/upload.php in Galaxyscripts Mini File Host 1.2.1 and earlier allows remote attackers to include and execute… | Patch early | 4.3 medium | 2.4% | 2008-01-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt