CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,908 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-3320 EXP | Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 6.1 medium | 2.3% | 2020-01-29 |
| CVE-2008-1170 EXP | Multiple PHP remote file inclusion vulnerabilities in KCWiki 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the page parameter… | Patch early | 6.8 medium | 2.3% | 2008-03-05 |
| CVE-2007-5092 EXP | Directory traversal vulnerability in index.php in the Dance Music module for phpNuke, when register_globals is enabled, allows remote attackers to inc… | Patch early | 6.8 medium | 2.3% | 2007-09-26 |
| CVE-2017-14126 EXP | The Participants Database plugin before 1.7.5.10 for WordPress has XSS. | Patch early | 6.1 medium | 2.3% | 2017-09-04 |
| CVE-2008-3926 EXP | Multiple directory traversal vulnerabilities in Content Management Made Easy (CMME) 1.12 allow remote attackers to (1) read arbitrary files via a .. (… | Patch early | 5.8 medium | 2.3% | 2008-09-04 |
| CVE-2019-6588 EXP | In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" par… | Patch early | 4.7 medium | 2.3% | 2019-06-03 |
| CVE-2007-2319 EXP | PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to execute arbitrary PHP code via… | Patch early | 6.8 medium | 2.3% | 2007-04-26 |
| CVE-2007-5697 EXP | Multiple PHP remote file inclusion vulnerabilities in PHP Image 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the xarg paramet… | Patch early | 6.8 medium | 2.3% | 2007-10-29 |
| CVE-2006-2029 EXP | Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (… | Patch early | 6.4 medium | 2.3% | 2006-04-26 |
| CVE-2014-4964 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to hijack the authentication of users… | Patch early | 6.8 medium | 2.3% | 2014-07-15 |
| CVE-2006-4449 EXP | Cross-site scripting (XSS) vulnerability in attachment.php in MyBulletinBoard (MyBB) 1.1.7 and possibly other versions allows remote attackers to inje… | Patch early | 5.1 medium | 2.3% | 2006-08-30 |
| CVE-2007-6471 EXP | Incomplete blacklist vulnerability in main.php in phPay 2.02.01 on Windows allows remote attackers to conduct directory traversal attacks and include… | Patch early | 5.8 medium | 2.3% | 2007-12-20 |
| CVE-2016-4807 EXP | Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (adm… | Patch early | 4.8 medium | 2.3% | 2017-01-11 |
| CVE-2006-2001 EXP | Cross-site scripting (XSS) vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the p par… | Patch early | 4.3 medium | 2.3% | 2006-04-25 |
| CVE-2006-2755 EXP | Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 2.3% | 2006-06-02 |
| CVE-2008-1555 EXP | Directory traversal vulnerability in system/_b/contentFiles/gbincluder.php in BolinOS 4.6.1 allows remote attackers to include and execute arbitrary l… | Patch early | 6.8 medium | 2.3% | 2008-03-31 |
| CVE-2008-3165 EXP | Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to inclu… | Patch early | 6.8 medium | 2.3% | 2008-07-14 |
| CVE-2008-3190 EXP | Directory traversal vulnerability in list.php in 1Scripts CodeDB 1.1.1 allows remote attackers to include and execute arbitrary local files via a .. (… | Patch early | 6.8 medium | 2.3% | 2008-07-16 |
| CVE-2010-1058 EXP | Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote… | Patch early | 6.8 medium | 2.3% | 2010-03-23 |
| CVE-2010-1268 EXP | Directory traversal vulnerability in index.php in justVisual CMS 2.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execut… | Patch early | 6.8 medium | 2.3% | 2010-04-06 |
| CVE-2010-1710 EXP | Directory traversal vulnerability in login.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to include and execute arbitr… | Patch early | 6.8 medium | 2.3% | 2010-05-04 |
| CVE-2008-0140 EXP | Directory traversal vulnerability in error.php in Uebimiau Webmail 2.7.10 and 2.7.2 allows remote authenticated users to read arbitrary files via a ..… | Patch early | 6.4 medium | 2.3% | 2008-01-08 |
| CVE-2018-17590 EXP | AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. | Patch early | 6.1 medium | 2.3% | 2018-10-02 |
| CVE-2018-17591 EXP | AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. | Patch early | 6.1 medium | 2.3% | 2018-10-02 |
| CVE-2018-17593 EXP | AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. | Patch early | 6.1 medium | 2.3% | 2018-10-02 |
| CVE-2004-2749 EXP | Directory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other product lines, allows remote attac… | Patch early | 4.3 medium | 2.3% | 2004-12-31 |
| CVE-2014-4939 EXP | SQL injection vulnerability in the ENL Newsletter (enl-newsletter) plugin 1.0.1 for WordPress allows remote authenticated administrators to execute ar… | Patch early | 6.5 medium | 2.3% | 2014-07-11 |
| CVE-2014-7153 EXP | SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remot… | Patch early | 6.5 medium | 2.3% | 2014-09-22 |
| CVE-2018-12705 EXP | DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side). | Patch early | 6.1 medium | 2.3% | 2018-06-24 |
| CVE-2021-43009 EXP | A Cross Site Scripting (XSS) vulnerability exists in OpServices OpMon through 9.11 via the search parameter in the request URL. | Patch early | 6.1 medium | 2.3% | 2022-04-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt