CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,011 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-1677 EXP | Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allow (1) remote aut… | Patch early | 6.5 medium | 2.1% | 2009-05-18 |
| CVE-2018-1202 EXP | Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and version 7.1.1.11 is affected by a cross-site scripti… | Patch early | 4.8 medium | 2.1% | 2018-03-26 |
| CVE-2006-0310 EXP | Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode ur… | Patch early | 4.3 medium | 2.1% | 2006-01-19 |
| CVE-2006-0361 EXP | Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5 Blog 8.01 allows remote attackers to inject arbitrary web script or HTML via a jav… | Patch early | 4.3 medium | 2.1% | 2006-01-22 |
| CVE-2006-0443 EXP | Cross-site scripting (XSS) vulnerability in archive.php in CheesyBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) r… | Patch early | 4.3 medium | 2.1% | 2006-01-26 |
| CVE-2008-6726 EXP | Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers to include and execute arbitrar… | Patch early | 6.0 medium | 2.1% | 2009-04-17 |
| CVE-2008-6193 EXP | Sam Crew MyBlog stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information. | Patch early | 5.0 medium | 2.1% | 2009-02-19 |
| CVE-2009-2037 EXP | Multiple directory traversal vulnerabilities in Online Grades & Attendance 3.2.5 and earlier, and possibly 3.2.6, when register_globals is enabled, al… | Patch early | 6.8 medium | 2.1% | 2009-06-12 |
| CVE-2005-4454 EXP | Validate-before-filter vulnerability in cleanhtml.pl 1.129 in LiveJournal CVS before Dec 7 2005, when the cleancss option is enabled, allows remote at… | Patch early | 4.3 medium | 2.1% | 2005-12-21 |
| CVE-2018-6193 EXP | A Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph action to cgi-bin/routers2.pl… | Patch early | 4.7 medium | 2.1% | 2018-01-24 |
| CVE-2005-2441 EXP | Multiple cross-site scripting (XSS) vulnerabilities in VBzoom allow remote attackers to inject arbitrary web script and HTML via the (1) UserName para… | Patch early | 4.3 medium | 2.1% | 2005-08-03 |
| CVE-2015-4118 EXP | SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permissions to… | Patch early | 6.5 medium | 2.1% | 2015-06-15 |
| CVE-2008-6530 EXP | Unrestricted file upload vulnerability in editimage.php in eZoneScripts Living Local 1.1 allows remote authenticated administrators to execute arbitra… | Patch early | 6.5 medium | 2.1% | 2009-03-26 |
| CVE-2007-0399 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Simple Machines Forum (SMF) 1.1 RC3 allow remote authenticated users to inject arb… | Patch early | 6.0 medium | 2.1% | 2007-01-22 |
| CVE-2008-5884 EXP | AyeView 2.20 allows user-assisted attackers to cause a denial of service (application crash) via a GIF file with a malformed header. | Patch early | 4.3 medium | 2.1% | 2009-01-12 |
| CVE-2018-10313 EXP | WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI. | Patch early | 5.4 medium | 2.1% | 2018-04-24 |
| CVE-2006-6631 EXP | PHP remote file inclusion vulnerability in lib/xml/oai/GetRecord.php in osprey 1.0 and earlier allows remote attackers to execute arbitrary PHP code v… | Patch early | 6.8 medium | 2.1% | 2006-12-18 |
| CVE-2006-6632 EXP | PHP remote file inclusion vulnerability in genepi.php in Genepi 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 6.8 medium | 2.1% | 2006-12-18 |
| CVE-2006-6686 EXP | PHP remote file inclusion vulnerability in sender.php in Carsen Klock TextSend 1.5 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 6.8 medium | 2.1% | 2006-12-21 |
| CVE-2020-15599 EXP | Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field. | Patch early | 6.1 medium | 2.1% | 2020-07-07 |
| CVE-2020-20142 EXP | Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table & Charts 2.7.17. | Patch early | 6.1 medium | 2.1% | 2020-12-17 |
| CVE-2005-4260 EXP | Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote attackers to perform cross-site scripting (XSS) attacks by re… | Patch early | 4.3 medium | 2.1% | 2005-12-15 |
| CVE-2006-5164 EXP | Multiple cross-site scripting (XSS) vulnerabilities in cart.php in Sum Effect Software digiSHOP 4.0 allow remote attackers to inject arbitrary web scr… | Patch early | 6.8 medium | 2.1% | 2006-10-05 |
| CVE-2008-2857 EXP | AlstraSoft AskMe Pro 2.1 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive i… | Patch early | 5.0 medium | 2.1% | 2008-06-25 |
| CVE-2003-1488 EXP | The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.… | Patch early | 6.4 medium | 2.1% | 2003-12-31 |
| CVE-2004-1735 EXP | Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary we… | Patch early | 4.3 medium | 2.1% | 2004-08-21 |
| CVE-2007-6228 EXP | Stack-based buffer overflow in the Helper class in the yt.ythelper.2 ActiveX control in Yahoo! Toolbar 1.4.1 allows remote attackers to cause a denial… | Patch early | 6.8 medium | 2.1% | 2007-12-04 |
| CVE-2011-0503 EXP | Cross-site request forgery (CSRF) vulnerability in VaM Shop 1.6, 1.6.1, and probably earlier versions allows remote attackers to hijack the authentica… | Patch early | 6.8 medium | 2.1% | 2011-01-20 |
| CVE-2018-1203 EXP | In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2,… | Patch early | 6.7 medium | 2.1% | 2018-03-26 |
| CVE-2011-4918 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Elxis CMS 2009.2, 2009.3 and 2009.3 Aphrodite before revision 2684 allow remote attackers to in… | Patch early | 4.3 medium | 2.1% | 2012-08-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt