CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,413 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-4709 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Hotaru.php in the Search plugin 1.3 for Hotaru CMS allow remote attackers to inject arbitrary w… | Patch early | 4.3 medium | 2% | 2011-12-08 |
| CVE-2009-3715 EXP | Multiple SQL injection vulnerabilities in scr_login.php in MCshoutbox 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitr… | Patch early | 6.8 medium | 2% | 2009-10-16 |
| CVE-2008-1094 EXP | SQL injection vulnerability in index.cgi in the Account View page in Barracuda Spam Firewall (BSF) before 3.5.12.007 allows remote authenticated admin… | Patch early | 6.5 medium | 2% | 2008-12-19 |
| CVE-2008-2974 EXP | Directory traversal vulnerability in chatconfig.php in MM Chat 1.5, when register_globals is enabled, allows remote attackers to include and execute a… | Patch early | 6.8 medium | 2% | 2008-07-02 |
| CVE-2008-2982 EXP | Multiple directory traversal vulnerabilities in HomePH Design 2.10 RC2, when register_globals is enabled, allow remote attackers to include and execut… | Patch early | 6.8 medium | 2% | 2008-07-02 |
| CVE-2008-4158 EXP | Multiple directory traversal vulnerabilities in index.php in Zanfi CMS lite 1.2 allow remote attackers to include and execute arbitrary local files vi… | Patch early | 6.8 medium | 2% | 2008-09-22 |
| CVE-2009-0515 EXP | Directory traversal vulnerability in check_lang.php in Yet Another NOCC (YANOCC) 0.1.0 and earlier allows remote attackers to include and execute arbi… | Patch early | 6.8 medium | 2% | 2009-02-11 |
| CVE-2009-2338 EXP | Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is enabled, allows remote attack… | Patch early | 6.8 medium | 2% | 2009-07-07 |
| CVE-2009-2552 EXP | Multiple directory traversal vulnerabilities in comments.php in Super Simple Blog Script 2.5.4 allow remote attackers to overwrite, include, and execu… | Patch early | 6.8 medium | 2% | 2009-07-20 |
| CVE-2008-6790 EXP | The admin module in MindDezign Photo Gallery 2.2 allows remote attackers to add administrative users and gain privileges via a modified username param… | Patch early | 5.1 medium | 2% | 2009-05-04 |
| CVE-2003-0404 EXP | Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitr… | Patch early | 4.3 medium | 2% | 2003-06-30 |
| CVE-2009-3857 EXP | Buffer overflow in Softonic International SciTE 1.72 allows user-assisted remote attackers to cause a denial of service (application crash) via a Ruby… | Patch early | 4.3 medium | 2% | 2009-11-04 |
| CVE-2008-4161 EXP | SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands and conduct session fixation… | Patch early | 6.8 medium | 2% | 2008-09-22 |
| CVE-2004-0617 EXP | Cross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows remote attackers to inject arbitrary script or HTML via the rawURL parameter. | Patch early | 6.8 medium | 2% | 2004-12-06 |
| CVE-2004-0673 EXP | Cross-site scripting (XSS) vulnerability in SCI Photo Chat Server 3.4.9 allows remote attackers to execute arbitrary web script as other users via an… | Patch early | 6.8 medium | 2% | 2004-08-06 |
| CVE-2005-4477 EXP | Cross-site scripting (XSS) vulnerability in papaya CMS 4.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the bab[se… | Patch early | 6.8 medium | 2% | 2005-12-22 |
| CVE-2010-0712 EXP | Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote authenticate… | Patch early | 6.5 medium | 2% | 2010-02-26 |
| CVE-2010-5284 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Collabtive 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) User… | Patch early | 4.3 medium | 2% | 2012-11-26 |
| CVE-2009-2605 EXP | Multiple SQL injection vulnerabilities in adminquery.php in Traidnt Up 2.0 allow remote attackers to execute arbitrary SQL commands via (1) trupuser a… | Patch early | 6.8 medium | 2% | 2009-07-27 |
| CVE-2008-6730 EXP | Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPLink Pro 0.0.6 and 0.0.7, when magic_quotes_gpc is disabled, allow remote atta… | Patch early | 6.8 medium | 2% | 2009-04-20 |
| CVE-2006-2140 EXP | Multiple cross-site scripting (XSS) vulnerabilities in OrbitHYIP 2.0 and earlier allow remote attackers to inject arbitrary web script via the (1) ref… | Patch early | 5.8 medium | 2% | 2006-05-02 |
| CVE-2006-0194 EXP | Cross-site scripting (XSS) vulnerability in default.asp in FogBugz 4.029, and other versions before 4.0.33, allows remote attackers to inject arbitrar… | Patch early | 4.3 medium | 2% | 2006-01-13 |
| CVE-2011-5197 EXP | Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Harvester Systems 2.3.1 and earlier allow… | Patch early | 6.8 medium | 2% | 2012-09-23 |
| CVE-2006-0350 EXP | Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.p… | Patch early | 4.3 medium | 2% | 2006-01-21 |
| CVE-2006-0409 EXP | Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 2% | 2006-01-25 |
| CVE-2006-0676 EXP | Cross-site scripting (XSS) vulnerability in header.php in PHP-Nuke 6.0 to 7.8 allows remote attackers to inject arbitrary web script or HTML via the p… | Patch early | 4.3 medium | 2% | 2006-02-13 |
| CVE-2006-1216 EXP | Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms 1.x allows remote attackers to inject arbitrary web script or HTML via the id parame… | Patch early | 4.3 medium | 2% | 2006-03-14 |
| CVE-2006-1348 EXP | Cross-site scripting (XSS) vulnerability in index.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 2% | 2006-03-22 |
| CVE-2004-1871 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 2% | 2004-03-29 |
| CVE-2005-2855 EXP | Cross-site scripting (XSS) vulnerability in Unclassified NewsBoard 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the descri… | Patch early | 4.3 medium | 2% | 2005-09-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt