CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,041 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-2132 EXP | Directory traversal vulnerability in global.php in 4images before 1.7.7, when magic_quotes_gpc is disabled, allows remote attackers to include and exe… | Patch early | 6.8 medium | 2.1% | 2009-06-19 |
| CVE-2006-5915 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ls.php in SAMEDIA LandShop allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 6.8 medium | 2.1% | 2006-11-15 |
| CVE-2014-4943 EXP | The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure diff… | Patch early | 6.9 medium | 2.1% | 2014-07-19 |
| CVE-2006-2803 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PHP ManualMaker 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1)… | Patch early | 6.8 medium | 2.1% | 2006-06-03 |
| CVE-2006-6738 EXP | PHP remote file inclusion vulnerability in statistic.php in cwmCounter 5.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a U… | Patch early | 6.8 medium | 2.1% | 2006-12-26 |
| CVE-2003-1553 EXP | Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which a… | Patch early | 4.3 medium | 2.1% | 2003-12-31 |
| CVE-2018-11512 EXP | Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wity… | Patch early | 4.8 medium | 2.1% | 2018-05-28 |
| CVE-2008-0329 EXP | LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_refuser.php in Admin/, which al… | Patch early | 5.0 medium | 2.1% | 2008-01-17 |
| CVE-2022-48110 EXP | CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the vend… | Patch early | 6.1 medium | 2.1% | 2023-02-13 |
| CVE-2007-5674 EXP | Directory traversal vulnerability in index.php in InstaGuide Weather (aka Weather for PHP) 1.0, when magic_quotes_gpc is disabled, allows remote attac… | Patch early | 6.8 medium | 2.1% | 2007-10-24 |
| CVE-2009-1625 EXP | Directory traversal vulnerability in index.php in Thickbox Gallery 2 allows remote attackers to include and execute arbitrary local files via a .. (do… | Patch early | 6.8 medium | 2.1% | 2009-05-12 |
| CVE-2010-3271 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Applicati… | Patch early | 6.8 medium | 2.1% | 2011-07-18 |
| CVE-2009-4661 EXP | Multiple buffer overflows in BigAnt Server 2.50 SP6 and earlier allow user-assisted remote attackers to cause a denial of service (application crash)… | Patch early | 4.3 medium | 2.1% | 2010-03-03 |
| CVE-2008-5870 EXP | FastStone Image Viewer 3.6 allows user-assisted attackers to cause a denial of service (application crash) via a malformed BMP image with large width… | Patch early | 4.3 medium | 2.1% | 2009-01-08 |
| CVE-2006-6778 EXP | Cross-site scripting (XSS) vulnerability in shownews.php in TimberWolf 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the ni… | Patch early | 6.8 medium | 2.1% | 2006-12-28 |
| CVE-2007-4384 EXP | Multiple PHP remote file inclusion vulnerabilities in depouilg.php3 in Stephane Pineau VOTE 1c allow remote attackers to execute arbitrary PHP code vi… | Patch early | 6.8 medium | 2.1% | 2007-08-17 |
| CVE-2019-11193 EXP | The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass t… | Patch early | 6.1 medium | 2.1% | 2019-04-30 |
| CVE-2006-6289 EXP | Woltlab Burning Board (wBB) Lite 1.0.2 does not properly unset variables when the input data includes a numeric parameter with a value matching an alp… | Patch early | 6.8 medium | 2.1% | 2006-12-05 |
| CVE-2004-0271 EXP | Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the… | Patch early | 6.8 medium | 2.1% | 2004-11-23 |
| CVE-2005-4460 EXP | Cross-site scripting (XSS) vulnerability in Beehive Forum 0.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1)… | Patch early | 5.1 medium | 2.1% | 2005-12-21 |
| CVE-2006-1971 EXP | Cross-site scripting (XSS) vulnerability in login.php in KRANKIKOM ContentBoxX allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 2.1% | 2006-04-21 |
| CVE-2006-2048 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Edwin van Wijk phpWebFTP 2.3 allow remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 2.1% | 2006-04-26 |
| CVE-2006-6364 EXP | Cross-site scripting (XSS) vulnerability in error.php in Inside Systems Mail (ISMail) 2.0 and earlier allows remote attackers to inject arbitrary web… | Patch early | 6.8 medium | 2.1% | 2006-12-07 |
| CVE-2007-1714 EXP | Cross-site scripting (XSS) vulnerability in index.php in CcCounter 2.0 allows remote attackers to inject arbitrary web script or HTML via dir paramete… | Patch early | 6.8 medium | 2.1% | 2007-03-27 |
| CVE-2011-5258 EXP | Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.6.11.2 allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 2.1% | 2013-02-12 |
| CVE-2005-4206 EXP | Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect… | Patch early | 6.1 medium | 2.1% | 2005-12-13 |
| CVE-2012-6042 EXP | GPSMapEdit 1.1.73.2 allows user-assisted remote attackers to cause a denial of service (crash) via a long string in a lst file. | Patch early | 4.3 medium | 2.1% | 2012-11-26 |
| CVE-2006-5096 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in VirtueMart (formerly known as mambo-phpShop) Joomla! eCommerce Edition CMS 1.0.11,… | Patch early | 6.8 medium | 2.1% | 2006-09-29 |
| CVE-2006-5524 EXP | Cross-site scripting (XSS) vulnerability in index.php in phplist 2.10.2 allows remote attackers to inject arbitrary web script or HTML via the p param… | Patch early | 6.8 medium | 2.1% | 2006-10-26 |
| CVE-2010-2618 EXP | PHP remote file inclusion vulnerability in inc/smarty/libs/init.php in AdaptCMS 2.0.0 Beta, when register_globals is enabled, allows remote attackers… | Patch early | 6.8 medium | 2.1% | 2010-07-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt