CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,941 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-2109 EXP | Cross-site scripting (XSS) vulnerability in the parse_query_str function in include/print.php in JSBoard 2.0.10 and 2.0.11, and possibly other version… | Patch early | 6.8 medium | 2.3% | 2006-05-02 |
| CVE-2006-7072 EXP | Cross-site scripting (XSS) vulnerability in GeoClassifieds Enterprise 2.0.5.2 and earlier allows remote attackers to inject arbitrary web script and H… | Patch early | 4.3 medium | 2.3% | 2007-03-02 |
| CVE-2007-5676 EXP | PHP remote file inclusion vulnerability in modules/Forums/favorites.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execute arbitrary PHP… | Patch early | 6.8 medium | 2.3% | 2007-10-24 |
| CVE-2010-2655 EXP | Directory traversal vulnerability in private/file_management.php on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48… | Patch early | 4.0 medium | 2.3% | 2010-07-08 |
| CVE-2006-5834 EXP | Directory traversal vulnerability in general.php in OpenSolution Quick.Cms.Lite 0.3 allows remote attackers to include arbitrary files via a .. (dot d… | Patch early | 5.0 medium | 2.3% | 2006-11-10 |
| CVE-2012-4234 EXP | Cross-site scripting (XSS) vulnerability in the group moderation screen in the control center (control.php) in Phorum before 5.2.19 allows remote atta… | Patch early | 4.3 medium | 2.3% | 2014-09-04 |
| CVE-2006-3184 EXP | Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to execute arbitrary ASP code via… | Patch early | 4.0 medium | 2.3% | 2006-06-23 |
| CVE-2010-5281 EXP | Directory traversal vulnerability in ibrowser.php in the CMScout 2.09 IBrowser TinyMCE Plugin 1.4.1, when magic_quotes_gpc is disabled, allows remote… | Patch early | 6.8 medium | 2.3% | 2012-11-26 |
| CVE-2020-23835 EXP | A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0 allows remo… | Patch early | 6.4 medium | 2.3% | 2020-09-01 |
| CVE-2006-2683 EXP | PHP remote file inclusion vulnerability in 404.php in open-medium.CMS 0.25 allows remote attackers to execute arbitrary PHP code via a URL in the REDS… | Patch early | 6.4 medium | 2.3% | 2006-05-31 |
| CVE-2006-3568 EXP | Multiple cross-site scripting (XSS) vulnerabilities in guestbook.php in Fantastic Guestbook 2.0.1, and possibly earlier versions, allow remote attacke… | Patch early | 4.3 medium | 2.3% | 2006-07-13 |
| CVE-2009-3216 EXP | Multiple directory traversal vulnerabilities in iWiccle 1.01, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a… | Patch early | 4.3 medium | 2.3% | 2009-09-16 |
| CVE-2014-3443 EXP | JetMPAd.ax in JetAudio 8.1.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg file. | Patch early | 4.3 medium | 2.3% | 2014-05-14 |
| CVE-2005-1087 EXP | CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and po… | Patch early | 6.4 medium | 2.3% | 2005-04-07 |
| CVE-2011-5147 EXP | Static code injection vulnerability in ajax_save_name.php in the Ajax File Manager module in the tinymce plugin in FreeWebshop 2.2.9 R2 and earlier al… | Patch early | 5.0 medium | 2.3% | 2012-08-31 |
| CVE-2005-2461 EXP | Multiple SQL injection vulnerabilities in the calendar feature in Kayako liveResponse 2.x allow remote attackers to execute arbitrary SQL commands via… | Patch early | 6.4 medium | 2.3% | 2005-12-31 |
| CVE-2008-6090 EXP | Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a .. (dot d… | Patch early | 4.3 medium | 2.3% | 2009-02-06 |
| CVE-2008-6453 EXP | Directory traversal vulnerability in section.php in 6rbScript 3.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files… | Patch early | 4.3 medium | 2.3% | 2009-03-13 |
| CVE-2008-0812 EXP | Directory traversal vulnerability in DMS/index.php in BanPro DMS 1.0 allows remote attackers to include and execute arbitrary files via a .. (dot dot)… | Patch early | 6.4 medium | 2.3% | 2008-02-19 |
| CVE-2007-4457 EXP | Directory traversal vulnerability in forumreply.php in Dalai Forum 1.1 allows remote attackers to include and execute arbitrary local files via a .. (… | Patch early | 6.4 medium | 2.3% | 2007-08-21 |
| CVE-2013-1414 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow… | Patch early | 5.1 medium | 2.3% | 2013-07-08 |
| CVE-2009-3756 EXP | phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in adv… | Patch early | 5.0 medium | 2.3% | 2009-10-22 |
| CVE-2009-0249 EXP | Katy Whitton RankEm stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a data… | Patch early | 5.0 medium | 2.3% | 2009-01-22 |
| CVE-2009-0336 EXP | Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the d… | Patch early | 5.0 medium | 2.3% | 2009-01-29 |
| CVE-2009-1322 EXP | ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a… | Patch early | 5.0 medium | 2.3% | 2009-04-17 |
| CVE-2009-1550 EXP | Zakkis Technology ABC Advertise 1.0 does not properly restrict access to admin.inc.php, which allows remote attackers to obtain the administrator logi… | Patch early | 5.0 medium | 2.3% | 2009-05-06 |
| CVE-2009-1941 EXP | PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which allows remote attackers to downl… | Patch early | 5.0 medium | 2.3% | 2009-06-05 |
| CVE-2009-2024 EXP | Vlad Titarenko ASP VT Auth 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to down… | Patch early | 5.0 medium | 2.3% | 2009-06-09 |
| CVE-2007-2368 EXP | picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter. | Patch early | 5.0 medium | 2.3% | 2007-04-30 |
| CVE-2003-1411 EXP | PHP remote file inclusion vulnerability in emailreader_execute_on_each_page.inc.php in Cedric Email Reader 0.4 allows remote attackers to execute arbi… | Patch early | 6.8 medium | 2.3% | 2003-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt