CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,108 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-2070 EXP | Cross-site scripting (XSS) vulnerability in member.php in DevBB 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 2.1% | 2006-04-27 |
| CVE-2006-2228 EXP | Cross-site scripting (XSS) vulnerability in w-Agora (aka Web-Agora) 4.2.0 allows remote attackers to inject arbitrary web script or HTML via a post wi… | Patch early | 4.3 medium | 2.1% | 2006-05-05 |
| CVE-2011-4333 EXP | Multiple cross-site scripting (XSS) vulnerabilities in LabWiki 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (… | Patch early | 6.1 medium | 2.1% | 2017-10-23 |
| CVE-2006-1582 EXP | Cross-site scripting (XSS) vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to inject arbitrary web script or HTML via the _path… | Patch early | 5.8 medium | 2.1% | 2006-04-02 |
| CVE-2008-6039 EXP | Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | Patch early | 6.8 medium | 2.1% | 2009-02-03 |
| CVE-2009-4067 EXP | Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 allows physically proximate attac… | Patch early | 6.8 medium | 2.1% | 2020-02-11 |
| CVE-2026-44596 EXP | Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java… | Patch early | 6.5 medium | 2.1% | 2026-07-16 |
| CVE-2012-4247 EXP | Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 2.1% | 2012-08-12 |
| CVE-2008-2195 EXP | Static code injection vulnerability in admincp.php in DeluxeBB 1.2 and earlier allows remote authenticated administrators to inject arbitrary PHP code… | Patch early | 6.5 medium | 2.1% | 2008-05-14 |
| CVE-2008-4602 EXP | Directory traversal vulnerability in index.php in Post Affiliate Pro 2.0 allows remote authenticated users to read and possibly execute arbitrary loca… | Patch early | 6.5 medium | 2.1% | 2008-10-18 |
| CVE-2008-0440 EXP | AlstraSoft Forum Pay Per Post Exchange 2.0 stores passwords in cleartext, which makes it easier for attackers to access user accounts. | Patch early | 5.0 medium | 2.1% | 2008-01-23 |
| CVE-2005-4516 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion 6.00.200 through 6.00.300 allow remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 2.1% | 2005-12-28 |
| CVE-2006-0461 EXP | Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 2.1% | 2006-01-27 |
| CVE-2006-6625 EXP | Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 6.8 medium | 2.1% | 2006-12-18 |
| CVE-2009-2393 EXP | admin/index.php in Virtuenetz Virtue Online Test Generator does not require administrative privileges, which allows remote authenticated users to have… | Patch early | 6.5 medium | 2.1% | 2009-07-09 |
| CVE-2002-2235 EXP | member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be refl… | Patch early | 5.0 medium | 2.1% | 2002-12-31 |
| CVE-2004-1827 EXP | Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the… | Patch early | 4.3 medium | 2.1% | 2004-03-15 |
| CVE-2008-6060 EXP | Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by InfoSoft FusionCharts allows remote attac… | Patch early | 4.3 medium | 2.1% | 2009-02-05 |
| CVE-2008-5989 EXP | Directory traversal vulnerability in defs.php in PHPcounter 1.3.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include a… | Patch early | 6.8 medium | 2.1% | 2009-01-28 |
| CVE-2006-6814 EXP | Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read and modify ar… | Patch early | 6.3 medium | 2.1% | 2006-12-29 |
| CVE-2004-0266 EXP | SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers to obtain the admini… | Patch early | 5.0 medium | 2.1% | 2004-11-23 |
| CVE-2009-1456 EXP | Directory traversal vulnerability in admin.php in Malleo 1.2.3 allows remote authenticated administrators to include and execute arbitrary local files… | Patch early | 6.5 medium | 2.1% | 2009-04-28 |
| CVE-2006-6640 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Omniture SiteCatalyst allow remote attackers to inject arbitrary web script or HTML via the (1)… | Patch early | 6.8 medium | 2% | 2006-12-19 |
| CVE-2012-1604 EXP | Cross-site scripting (XSS) vulnerability in NextBBS 0.6 allows remote attackers to inject arbitrary web script or HTML via the do parameter to index.p… | Patch early | 4.3 medium | 2% | 2012-10-01 |
| CVE-2008-5860 EXP | Directory traversal vulnerability in backend/template.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc… | Patch early | 5.1 medium | 2% | 2009-01-06 |
| CVE-2006-6871 EXP | Multiple cross-site scripting (XSS) vulnerabilities in eNdonesia 8.4 allow remote attackers to inject arbitrary web script or HTML via (1) the mod par… | Patch early | 6.8 medium | 2% | 2006-12-31 |
| CVE-2009-2352 EXP | Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cr… | Patch early | 4.3 medium | 2% | 2009-07-07 |
| CVE-2006-5853 EXP | Cross-site scripting (XSS) vulnerability in logon.aspx in Immediacy CMS (Immediacy .NET CMS) 5.2 allows remote attackers to inject arbitrary web scrip… | Patch early | 6.8 medium | 2% | 2006-11-10 |
| CVE-2009-3181 EXP | Directory traversal vulnerability in Anantasoft Gazelle CMS 1.0 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the customi… | Patch early | 5.0 medium | 2% | 2009-09-11 |
| CVE-2008-0613 EXP | Open redirect vulnerability in htdocs/user.php in XOOPS 2.0.18 allows remote attackers to redirect users to arbitrary web sites and conduct phishing a… | Patch early | 5.0 medium | 2% | 2008-02-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt