CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,041 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-4977 EXP | PHP remote file inclusion vulnerability in index.php in MyBackup 1.4.0 allows remote authenticated users to execute arbitrary PHP code via a URL in th… | Patch early | 6.5 medium | 2.1% | 2010-08-25 |
| CVE-2007-6470 EXP | phpRPG 0.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read session ID values i… | Patch early | 6.4 medium | 2.1% | 2007-12-20 |
| CVE-2006-2423 EXP | Cross-site scripting (XSS) vulnerability in ftplogin/index.php in Confixx 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 2.1% | 2006-05-17 |
| CVE-2006-5975 EXP | Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 6.8 medium | 2.1% | 2006-11-20 |
| CVE-2007-3166 EXP | Buffer overflow in Qualcomm Eudora 7.1.0.9 allows user-assisted, remote IMAP servers to execute arbitrary code via a long FLAGS response to a SELECT I… | Patch early | 6.8 medium | 2.1% | 2007-06-11 |
| CVE-2009-1826 EXP | modules/admuser.php in myGesuad 0.9.14 (aka 0.9) does not require administrative authentication, which allows remote authenticated users to list user… | Patch early | 6.5 medium | 2.1% | 2009-05-29 |
| CVE-2019-6979 EXP | An issue was discovered in the User IP History Logs (aka IP_History_Logs) plugin 1.0.2 for MyBB. There is XSS via the admin/modules/tools/ip_history_l… | Patch early | 6.1 medium | 2.1% | 2019-01-28 |
| CVE-2009-4512 EXP | Directory traversal vulnerability in index.php in Oscailt 3.3, when Use Friendly URL's is disabled, allows remote attackers to include and execute arb… | Patch early | 5.1 medium | 2.1% | 2009-12-31 |
| CVE-2006-6523 EXP | Cross-site scripting (XSS) vulnerability in mail/manage.html in BoxTrapper in cPanel 11 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 6.8 medium | 2.1% | 2006-12-14 |
| CVE-2017-16994 EXP | The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to obt… | Patch early | 5.5 medium | 2.1% | 2017-11-27 |
| CVE-2009-1767 EXP | admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary… | Patch early | 5.0 medium | 2.1% | 2009-05-22 |
| CVE-2006-4479 EXP | Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 2.1% | 2006-08-31 |
| CVE-2006-1425 EXP | Cross-site scripting (XSS) vulnerability in track.php in phpmyfamily 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the name… | Patch early | 4.3 medium | 2.1% | 2006-03-28 |
| CVE-2005-4053 EXP | Cross-site scripting (XSS) vulnerability in coWiki 0.3.4 allows remote attackers to inject arbitrary web script or HTML via the q parameter, as demons… | Patch early | 4.3 medium | 2.1% | 2005-12-07 |
| CVE-2008-1229 EXP | Cross-site scripting (XSS) vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 2.1% | 2008-03-10 |
| CVE-2018-20472 EXP | An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS. | Patch early | 5.4 medium | 2.1% | 2019-06-17 |
| CVE-2003-1350 EXP | List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl fi… | Patch early | 4.3 medium | 2.1% | 2003-12-31 |
| CVE-2012-5702 EXP | Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (… | Patch early | 4.3 medium | 2.1% | 2014-10-21 |
| CVE-2011-5149 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SpamTitan 5.08 and earlier allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 2.1% | 2012-08-31 |
| CVE-2004-2030 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject arbitrary… | Patch early | 4.3 medium | 2.1% | 2004-05-22 |
| CVE-2017-17737 EXP | The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diagnostics.html or /storage_info.… | Patch early | 6.1 medium | 2.1% | 2017-12-18 |
| CVE-2010-2025 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with fir… | Patch early | 6.8 medium | 2.1% | 2010-05-26 |
| CVE-2006-5239 EXP | Multiple cross-site scripting (XSS) vulnerabilities in eXpBlog 0.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1)… | Patch early | 4.3 medium | 2.1% | 2006-10-12 |
| CVE-2018-10109 EXP | Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the content section of a ne… | Patch early | 4.8 medium | 2.1% | 2018-04-16 |
| CVE-2006-2210 EXP | Cross-site scripting (XSS) vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 5.8 medium | 2.1% | 2006-05-05 |
| CVE-2003-1149 EXP | Cross-site scripting (XSS) vulnerability in Symantec Norton Internet Security 2003 6.0.4.34 allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 2.1% | 2003-10-27 |
| CVE-2012-6555 EXP | Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 2.1% | 2013-05-23 |
| CVE-2006-2249 EXP | Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject… | Patch early | 4.3 medium | 2.1% | 2006-05-09 |
| CVE-2006-2425 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PRV.php in PhpRemoteView, possibly 2003-10-23 and earlier, allow remote attackers to inject arb… | Patch early | 4.3 medium | 2.1% | 2006-05-17 |
| CVE-2006-4668 EXP | Cross-site scripting (XSS) vulnerability in index.php in Rob Hensley AckerTodo 4.0 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 2.1% | 2006-09-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt