CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,941 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-6877 EXP | Directory traversal vulnerability in index.php in Matteo Lucarelli 3editor CMS 0.42 and earlier, when register_globals is enabled, allows remote attac… | Patch early | 6.8 medium | 2.3% | 2006-12-31 |
| CVE-2009-0463 EXP | PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 6.8 medium | 2.3% | 2009-02-10 |
| CVE-2000-1180 EXP | Buffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a long command line argument. | Patch early | 4.6 medium | 2.3% | 2001-01-09 |
| CVE-2010-4895 EXP | Cross-site scripting (XSS) vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 2.3% | 2011-10-08 |
| CVE-2015-7889 EXP | The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the com.samsung.android.ema… | Patch early | 5.5 medium | 2.3% | 2017-12-28 |
| CVE-2006-3608 EXP | The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files t… | Patch early | 4.6 medium | 2.3% | 2006-07-18 |
| CVE-2008-0259 EXP | Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to read arbitrary files via a .. (… | Patch early | 6.4 medium | 2.3% | 2008-01-15 |
| CVE-2012-1260 EXP | Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possib… | Patch early | 6.1 medium | 2.3% | 2020-01-09 |
| CVE-2008-1301 EXP | Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allow… | Patch early | 4.0 medium | 2.3% | 2008-03-12 |
| CVE-2006-0173 EXP | Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a f… | Patch early | 4.0 medium | 2.3% | 2006-01-11 |
| CVE-2008-3400 EXP | XRMS CRM 1.99.2 allows remote attackers to obtain configuration information via a direct request to tests/info.php, which calls the phpinfo function. | Patch early | 4.3 medium | 2.3% | 2008-07-31 |
| CVE-2008-3924 EXP | The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access… | Patch early | 4.3 medium | 2.3% | 2008-09-04 |
| CVE-2014-6137 EXP | Cross-site scripting (XSS) vulnerability in the Relay Diagnostic page in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229 allows remote attackers to in… | Patch early | 4.3 medium | 2.3% | 2015-02-16 |
| CVE-2005-1610 EXP | Cross-site scripting (XSS) vulnerability in security.php for Tru-Zone NukeET 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTM… | Patch early | 6.8 medium | 2.3% | 2005-05-16 |
| CVE-2006-5566 EXP | CRLF injection vulnerability in premium/index.php in Shop-Script allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response sp… | Patch early | 5.0 medium | 2.3% | 2006-10-27 |
| CVE-2011-5289 EXP | The SaveDecrypted method in the ChilkatCrypt2.ChilkatOmaDrm.1 ActiveX control in ChilkatCrypt2.dll in aTube Catcher 2.3.570 allows remote attackers to… | Patch early | 6.4 medium | 2.3% | 2015-01-01 |
| CVE-2008-2123 EXP | Cross-site scripting (XSS) vulnerability in WGate in SAP Internet Transaction Server (ITS) 6.20 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 2.2% | 2008-05-09 |
| CVE-2009-1637 EXP | profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to change the admin e-mail address an… | Patch early | 6.4 medium | 2.2% | 2009-05-15 |
| CVE-2007-1364 EXP | DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie info… | Patch early | 6.4 medium | 2.2% | 2007-04-11 |
| CVE-2023-25439 EXP | Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitrary code via the description o… | Patch early | 6.1 medium | 2.2% | 2023-05-25 |
| CVE-2006-6750 EXP | Format string vulnerability in XM Easy Personal FTP Server 5.0.1 allows remote attackers to cause a denial of service (application crash) via format s… | Patch early | 5.0 medium | 2.2% | 2006-12-27 |
| CVE-2018-12090 EXP | There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introduce arbitrary JavaScript via m… | Patch early | 6.1 medium | 2.2% | 2018-06-11 |
| CVE-2006-6040 EXP | Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitrary web scr… | Patch early | 6.8 medium | 2.2% | 2006-11-22 |
| CVE-2018-7465 EXP | An XSS issue was discovered in VirtueMart before 3.2.14. All the textareas in the backend of the plugin can be closed by simply adding </textarea> to… | Patch early | 5.4 medium | 2.2% | 2018-04-26 |
| CVE-2008-5304 EXP | Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via the %URLPARAM{}% var… | Patch early | 4.3 medium | 2.2% | 2008-12-10 |
| CVE-2014-8429 EXP | Cross-site request forgery (CSRF) vulnerability in Xavoc Technocrats xEpan CMS 1.0.4.1, 1.0.4, 1.0.1, and earlier allows remote attackers to hijack th… | Patch early | 6.8 medium | 2.2% | 2014-11-28 |
| CVE-2017-12984 EXP | PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php. | Patch early | 6.1 medium | 2.2% | 2017-08-21 |
| CVE-2023-6710 EXP | A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the… | Patch early | 5.4 medium | 2.2% | 2023-12-12 |
| CVE-2009-5089 EXP | Directory traversal vulnerability in index.php in IdeaCart 0.02 and 0.02a allows remote attackers to read arbitrary files via a .. (dot dot) in the pa… | Patch early | 4.3 medium | 2.2% | 2011-09-12 |
| CVE-2006-1822 EXP | Cross-site scripting (XSS) vulnerability in search.php in FarsiNews 2.5.3 Pro and earlier allows remote attackers to inject arbitrary web script or HT… | Patch early | 5.8 medium | 2.2% | 2006-04-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt