CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,413 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-3387 EXP | Directory traversal vulnerability in sources/post.php in Fusion News 1.0, when register_globals is enabled, allows remote attackers to include arbitra… | Patch early | 5.1 medium | 2% | 2006-07-06 |
| CVE-2013-5748 EXP | Cross-site request forgery (CSRF) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001 allows remote attackers to hij… | Patch early | 6.8 medium | 2% | 2014-05-12 |
| CVE-2011-4837 EXP | Cross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to hijack the authentic… | Patch early | 6.8 medium | 2% | 2011-12-15 |
| CVE-2023-4407 EXP | A vulnerability classified as critical was found in Codecanyon Credit Lite 1.5.4. Affected by this vulnerability is an unknown functionality of the fi… | Patch early | 6.3 medium | 2% | 2023-08-18 |
| CVE-2016-9834 EXP | An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices w… | Patch early | 6.1 medium | 2% | 2017-06-07 |
| CVE-2007-6147 EXP | Multiple PHP remote file inclusion vulnerabilities in IAPR COMMENCE 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the (a) php_… | Patch early | 6.8 medium | 2% | 2007-11-27 |
| CVE-2008-0287 EXP | PHP remote file inclusion vulnerability in VisionBurst vcart 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the abs_path par… | Patch early | 6.8 medium | 2% | 2008-01-16 |
| CVE-2007-4068 EXP | Multiple SQL injection vulnerabilities in Webyapar 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the kat_id parameter to the de… | Patch early | 5.8 medium | 2% | 2007-07-30 |
| CVE-2017-16568 EXP | Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. This vulnerability allows att… | Patch early | 5.4 medium | 2% | 2017-11-10 |
| CVE-2006-6356 EXP | Multiple cross-site scripting (XSS) vulnerabilities in templates/link_temp.php in PHPNews 1.3.0 allow remote attackers to inject arbitrary web script… | Patch early | 6.8 medium | 2% | 2006-12-07 |
| CVE-2014-2339 EXP | Multiple SQL injection vulnerabilities in bbs/ajax.autosave.php in GNUboard 5.x and possibly earlier allow remote authenticated users to execute arbit… | Patch early | 6.5 medium | 2% | 2014-03-19 |
| CVE-2006-5056 EXP | Cross-site scripting (XSS) vulnerability in index.php in Opial Audio/Video Download Management 1.0 allows remote attackers to inject arbitrary web scr… | Patch early | 5.1 medium | 2% | 2006-09-28 |
| CVE-2006-5074 EXP | Cross-site scripting (XSS) vulnerability in home.php in PHP Invoice 2.2 allows remote attackers to inject arbitrary web script or HTML via the alert p… | Patch early | 5.1 medium | 2% | 2006-09-29 |
| CVE-2006-1357 EXP | Cross-site scripting (XSS) vulnerability in my.support.php3 in F5 Firepass 4100 SSL VPN 5.4.2 allows remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 2% | 2006-03-22 |
| CVE-2007-1101 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Photostand 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) mess… | Patch early | 4.3 medium | 2% | 2007-02-26 |
| CVE-2008-6658 EXP | Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated admin… | Patch early | 4.0 medium | 2% | 2009-04-07 |
| CVE-2015-6655 EXP | Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for requests… | Patch early | 6.8 medium | 2% | 2015-08-31 |
| CVE-2015-6827 EXP | Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentication of users for requests tha… | Patch early | 6.8 medium | 2% | 2015-09-11 |
| CVE-2006-6819 EXP | AlstraSoft Web Host Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to downl… | Patch early | 6.4 medium | 2% | 2006-12-29 |
| CVE-2020-13260 EXP | A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload a JavaScrip… | Patch early | 6.1 medium | 2% | 2020-09-17 |
| CVE-2008-6074 EXP | Directory traversal vulnerability in frame.php in phpcrs 2.06 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and e… | Patch early | 5.1 medium | 2% | 2009-02-06 |
| CVE-2003-0102 EXP | Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large… | Patch early | 4.6 medium | 2% | 2003-03-18 |
| CVE-2007-1709 EXP | Buffer overflow in the confirm_phpdoc_compiled function in the phpDOC extension (PECL phpDOC) in PHP 5.2.1 allows context-dependent attackers to execu… | Patch early | 4.3 medium | 2% | 2007-03-27 |
| CVE-2006-1916 EXP | Multiple cross-site scripting (XSS) vulnerabilities in profile.php in DbbS 2.0-alpha and earlier allow remote attackers to inject arbitrary web script… | Patch early | 6.8 medium | 2% | 2006-04-20 |
| CVE-2003-1175 EXP | Cross-site scripting (XSS) vulnerability in index.php in Sympoll 1.5 allows remote attackers to inject arbitrary web script or HTML via the vo paramet… | Patch early | 6.8 medium | 2% | 2003-12-31 |
| CVE-2003-1182 EXP | Cross-site scripting (XSS) vulnerability in MPM Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter. | Patch early | 6.8 medium | 2% | 2003-11-03 |
| CVE-2004-1818 EXP | Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary scri… | Patch early | 6.8 medium | 2% | 2004-03-15 |
| CVE-2005-1611 EXP | Cross-site scripting (XSS) vulnerability in WebX in Web Crossing 5.x allows remote attackers to inject arbitrary web script or HTML via a URL with an… | Patch early | 6.8 medium | 2% | 2005-05-16 |
| CVE-2008-1128 EXP | PHP remote file inclusion vulnerability in tourney/index.php in phpMyTourney 2 allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 6.8 medium | 2% | 2008-03-03 |
| CVE-2008-2744 EXP | Cross-site scripting (XSS) vulnerability in vBulletin 3.6.10 and 3.7.1 allows remote attackers to inject arbitrary web script or HTML via unknown vect… | Patch early | 4.3 medium | 2% | 2008-06-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt