CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,226 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-6103 EXP | PHP remote file inclusion vulnerability in index.php in A4Desk Event Calendar, when magic_quotes_gpc is disabled, allows remote attackers to execute a… | Patch early | 6.8 medium | 2% | 2009-02-10 |
| CVE-2006-3603 EXP | Cross-site scripting (XSS) vulnerability in index.php in FlexWATCH Network Camera 3.0 and earlier allows remote attackers to inject arbitrary web scri… | Patch early | 5.8 medium | 2% | 2006-07-18 |
| CVE-2008-7025 EXP | TrueVector in Check Point ZoneAlarm 8.0.020.000, with vsmon.exe running, allows remote HTTP proxies to cause a denial of service (crash) and disable t… | Patch early | 4.3 medium | 2% | 2009-08-21 |
| CVE-2009-1408 EXP | Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to… | Patch early | 4.3 medium | 2% | 2009-04-24 |
| CVE-2009-4435 EXP | Multiple directory traversal vulnerabilities in F3Site 2009 allow remote attackers to include and execute arbitrary local files via directory traversa… | Patch early | 6.8 medium | 2% | 2009-12-28 |
| CVE-2004-0672 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition 5.6 allows re… | Patch early | 6.8 medium | 2% | 2004-08-06 |
| CVE-2002-2288 EXP | Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.php with a parameter that does… | Patch early | 5.0 medium | 2% | 2002-12-31 |
| CVE-2001-1524 EXP | Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) unam… | Patch early | 4.3 medium | 2% | 2001-12-31 |
| CVE-2006-4020 EXP | scanf.c in PHP 5.1.4 and earlier, and 4.4.3 and earlier, allows context-dependent attackers to execute arbitrary code via a sscanf PHP function call t… | Patch early | 4.6 medium | 2% | 2006-08-08 |
| CVE-2007-4630 EXP | Cross-site scripting (XSS) vulnerability in xlaapmview.asp in Absolute Poll Manager XE 4.1 allows remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 2% | 2007-08-31 |
| CVE-2004-1563 EXP | Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via the (1) threa… | Patch early | 4.3 medium | 2% | 2004-12-31 |
| CVE-2005-1075 EXP | Multiple cross-site scripting (XSS) vulnerabilities in RadScripts RadBids Gold 2 allow remote attackers to inject arbitrary web script or HTML via (1)… | Patch early | 4.3 medium | 2% | 2005-05-02 |
| CVE-2008-0178 EXP | Cross-site scripting (XSS) vulnerability in the Enterprise Admin Session Monitoring component in Liferay Portal 4.3.6 allows remote authenticated user… | Patch early | 4.3 medium | 2% | 2008-02-05 |
| CVE-2020-23522 EXP | Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter. | Patch early | 6.8 medium | 2% | 2021-01-19 |
| CVE-2014-9302 EXP | Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Communit… | Patch early | 5.0 medium | 2% | 2014-12-07 |
| CVE-2007-2002 EXP | InoutMailingListManager 3.1 and earlier allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code,… | Patch early | 6.8 medium | 2% | 2007-04-12 |
| CVE-2007-2003 EXP | InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check fails, which allows remote att… | Patch early | 6.8 medium | 2% | 2007-04-12 |
| CVE-2003-1347 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web script or HTML via the (1) cid par… | Patch early | 4.3 medium | 2% | 2003-12-31 |
| CVE-2012-4901 EXP | Cross-site scripting (XSS) vulnerability in Template CMS 2.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the them… | Patch early | 4.3 medium | 2% | 2015-05-20 |
| CVE-2008-6911 EXP | SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.0.1, when magic_quotes_gpc is… | Patch early | 6.8 medium | 2% | 2009-08-06 |
| CVE-2012-1503 EXP | Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary w… | Patch early | 4.3 medium | 2% | 2014-08-29 |
| CVE-2012-2591 EXP | Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 2% | 2014-06-20 |
| CVE-2010-5040 EXP | PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute… | Patch early | 6.8 medium | 2% | 2011-11-02 |
| CVE-2008-0461 EXP | SQL injection vulnerability in index.php in the Search module in PHP-Nuke 8.0 FINAL and earlier, when magic_quotes_gpc is disabled, allows remote atta… | Patch early | 6.8 medium | 2% | 2008-01-25 |
| CVE-2012-4870 EXP | Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (… | Patch early | 4.3 medium | 2% | 2012-09-06 |
| CVE-2007-2634 EXP | PHP remote file inclusion vulnerability in common/errormsg.php in aForum 1.32 and possibly earlier, when register_globals is enabled, allows remote at… | Patch early | 6.8 medium | 2% | 2007-05-13 |
| CVE-2010-2003 EXP | Cross-site scripting (XSS) vulnerability in misc/get_admin.php in Advanced Poll 2.08 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 2% | 2010-05-20 |
| CVE-2008-1495 EXP | Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote authenticated administrators to up… | Patch early | 6.5 medium | 2% | 2008-03-25 |
| CVE-2018-13832 EXP | Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow re… | Patch early | 4.8 medium | 2% | 2018-07-16 |
| CVE-2008-7098 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Qsoft K-Rate Premium allow remote attackers to inject arbitrary web script or HTML via the blog… | Patch early | 4.3 medium | 2% | 2009-08-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt