CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,908 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-18776 EXP | Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the adm… | Patch early | 6.1 medium | 2.3% | 2018-11-01 |
| CVE-2013-7196 EXP | static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment on a private… | Patch early | 5.5 medium | 2.3% | 2014-04-18 |
| CVE-2017-2509 EXP | An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" component. It allows attackers to… | Patch early | 5.5 medium | 2.3% | 2017-05-22 |
| CVE-2007-3936 EXP | Directory traversal vulnerability in admin/filebrowser.asp in A-shop 0.70 and earlier, and possibly 0.71, allows remote attackers to delete arbitrary… | Patch early | 6.4 medium | 2.3% | 2007-07-21 |
| CVE-2007-5112 EXP | Cross-site scripting (XSS) vulnerability in session.cgi (aka the login page) in Google Urchin 5 5.7.03 and earlier allows remote attackers to inject a… | Patch early | 4.3 medium | 2.3% | 2007-09-26 |
| CVE-2010-1095 EXP | Cross-site scripting (XSS) vulnerability in login_reset_password_page.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 and earlier allows remote… | Patch early | 4.3 medium | 2.3% | 2010-03-24 |
| CVE-2012-5386 EXP | Directory traversal vulnerability in index.php in phpPaleo 4.8b180 allows remote attackers to include and execute arbitrary local files via a .. (dot… | Patch early | 6.8 medium | 2.3% | 2012-10-11 |
| CVE-2018-1204 EXP | Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected… | Patch early | 6.7 medium | 2.3% | 2018-03-26 |
| CVE-2015-1424 EXP | Cross-site request forgery (CSRF) vulnerability in Gecko CMS 2.2 and 2.3 allows remote attackers to hijack the authentication of administrators for re… | Patch early | 6.8 medium | 2.3% | 2015-01-29 |
| CVE-2008-6473 EXP | _blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary users via a modified "a" parame… | Patch early | 6.4 medium | 2.3% | 2009-03-16 |
| CVE-2021-24444 EXP | The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allow… | Patch early | 4.8 medium | 2.3% | 2021-08-02 |
| CVE-2009-4739 EXP | PHP remote file inclusion vulnerability in index.php in SkaDate Dating allows remote attackers to execute arbitrary PHP code via a URL in the language… | Patch early | 6.8 medium | 2.3% | 2010-03-26 |
| CVE-2006-2681 EXP | PHP remote file inclusion vulnerability in SocketMail Lite and Pro 2.2.6 and earlier, when register_globals and magic_quotes are enabled, allows remot… | Patch early | 6.8 medium | 2.3% | 2006-05-31 |
| CVE-2007-2248 EXP | Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Phorum before 5.1.22 allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 2.3% | 2007-04-25 |
| CVE-2006-3295 EXP | Cross-site scripting (XSS) vulnerability in header.php in Open Guestbook 0.5 allows remote attackers to inject arbitrary web script or HTML via the ti… | Patch early | 4.3 medium | 2.3% | 2006-06-29 |
| CVE-2006-0706 EXP | Cross-site scripting vulnerability in eintrag.php in Gästebuch (Gastebuch) before 1.3.3 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 2.3% | 2006-02-15 |
| CVE-2017-2489 EXP | An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graphics Driver" component. It allo… | Patch early | 5.5 medium | 2.3% | 2017-04-02 |
| CVE-2005-3064 EXP | MultiTheftAuto 0.5 patch 1 and earlier does not properly verify client privileges when running command 40, which allows remote attackers to change or… | Patch early | 5.0 medium | 2.3% | 2005-09-27 |
| CVE-2007-4318 EXP | Cross-site scripting (XSS) vulnerability in Forms/General_1 in the management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allo… | Patch early | 4.3 medium | 2.3% | 2007-08-13 |
| CVE-2007-6173 EXP | Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Enterprise Portal 4.3.1 allows remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 2.3% | 2007-11-30 |
| CVE-2012-6493 EXP | Cross-site request forgery (CSRF) vulnerability in Rapid7 Nexpose Security Console before 5.5.4 allows remote attackers to hijack the authentication o… | Patch early | 6.8 medium | 2.3% | 2014-02-04 |
| CVE-2006-1324 EXP | Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrar… | Patch early | 6.8 medium | 2.3% | 2006-03-21 |
| CVE-2014-5180 EXP | SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 for WordPress allows remote auth… | Patch early | 6.5 medium | 2.3% | 2014-08-06 |
| CVE-2008-4612 EXP | Cross-site scripting (XSS) vulnerability in PortalApp 4.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter to… | Patch early | 4.3 medium | 2.3% | 2008-10-20 |
| CVE-2014-4718 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Lunar CMS before 3.3-3 allow remote attackers to hijack the authentication of administra… | Patch early | 6.8 medium | 2.3% | 2014-07-03 |
| CVE-2011-4452 EXP | Cross-site request forgery (CSRF) vulnerability in the AdminUsers component in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to hijack the authent… | Patch early | 6.8 medium | 2.3% | 2012-09-05 |
| CVE-2008-4319 EXP | fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary… | Patch early | 6.4 medium | 2.3% | 2008-09-29 |
| CVE-2023-3320 EXP | The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing… | Patch early | 6.1 medium | 2.3% | 2023-06-20 |
| CVE-2004-2451 EXP | Roger Wilco 1.4.1.6 and earlier, or Roger Wilco Base Station 0.30a or earlier, allows remote attackers to send audio to arbitrary channels, aka the "V… | Patch early | 5.0 medium | 2.3% | 2004-12-31 |
| CVE-2006-0185 EXP | Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web script or… | Patch early | 5.0 medium | 2.3% | 2006-01-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt