CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,429 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-2783 EXP | Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) op parame… | Patch early | 4.3 medium | 1.9% | 2009-08-17 |
| CVE-2008-6840 EXP | Multiple PHP remote file inclusion vulnerabilities in V-webmail 1.6.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG… | Patch early | 6.8 medium | 1.9% | 2009-07-01 |
| CVE-2008-5320 EXP | SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the… | Patch early | 6.5 medium | 1.9% | 2008-12-03 |
| CVE-2010-3267 EXP | Multiple SQL injection vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the q… | Patch early | 6.5 medium | 1.9% | 2010-12-02 |
| CVE-2021-36654 EXP | CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while updating the theme. | Patch early | 5.4 medium | 1.9% | 2021-08-03 |
| CVE-2006-0469 EXP | Cross-site scripting (XSS) vulnerability in UebiMiau 2.7.9, and possibly earlier versions, allows remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 1.9% | 2006-01-30 |
| CVE-2006-0758 EXP | Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via a UR… | Patch early | 4.3 medium | 1.9% | 2006-02-18 |
| CVE-2006-1202 EXP | Multiple cross-site scripting (XSS) vulnerabilities in textfileBB 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 1.9% | 2006-03-14 |
| CVE-2006-1802 EXP | Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.9% | 2006-04-18 |
| CVE-2006-0211 EXP | Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbit… | Patch early | 4.3 medium | 1.9% | 2006-01-14 |
| CVE-2006-2821 EXP | Multiple cross-site scripting (XSS) vulnerabilities in DeltaScripts Pro Publish allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 6.8 medium | 1.9% | 2006-06-05 |
| CVE-2006-7184 EXP | Multiple PHP remote file inclusion vulnerabilities in Exhibit Engine (EE) 1.22, and possibly earlier, allow remote attackers to execute arbitrary PHP… | Patch early | 6.8 medium | 1.9% | 2007-03-30 |
| CVE-2008-3163 EXP | Directory traversal vulnerability in dodosmail.php in DodosMail 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot… | Patch early | 6.8 medium | 1.9% | 2008-07-14 |
| CVE-2007-3426 EXP | Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.9% | 2007-06-27 |
| CVE-2006-5146 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in… | Patch early | 6.8 medium | 1.9% | 2006-10-05 |
| CVE-2005-0429 EXP | Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to exe… | Patch early | 5.0 medium | 1.9% | 2005-05-02 |
| CVE-2009-4800 EXP | Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrary files via a ..// (dot dot sl… | Patch early | 4.0 medium | 1.9% | 2010-04-22 |
| CVE-2008-0393 EXP | Directory traversal vulnerability in info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a… | Patch early | 5.8 medium | 1.9% | 2008-01-23 |
| CVE-2021-28420 EXP | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time" parameter. | Patch early | 4.8 medium | 1.9% | 2021-03-18 |
| CVE-2007-3249 EXP | Cross-site scripting (XSS) vulnerability in mod_lettermansubscribe.php in the Letterman Subscriber (mod_letterman) before 1.2.5 module for Joomla! all… | Patch early | 4.3 medium | 1.9% | 2007-06-18 |
| CVE-2006-4708 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1b allow remote attackers to inject arbitrary web script or HTML via the (1) act… | Patch early | 6.8 medium | 1.9% | 2006-09-12 |
| CVE-2006-5090 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Phoenix Evolution CMS (PECMS) allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 6.8 medium | 1.9% | 2006-09-29 |
| CVE-2008-4455 EXP | Directory traversal vulnerability in index.php in EKINdesigns MySQL Quick Admin 1.5.5 and earlier, when magic_quotes_gpc is disabled, allows remote at… | Patch early | 6.8 medium | 1.9% | 2008-10-06 |
| CVE-2008-5819 EXP | Directory traversal vulnerability in eDNews_archive.php in eDreamers eDNews 2, when magic_quotes_gpc is disabled, allows remote attackers to include a… | Patch early | 6.8 medium | 1.9% | 2009-01-02 |
| CVE-2008-4245 EXP | The Admin Control Panel in Rianxosencabos CMS 0.9 does not require administrator privileges, which allows remote authenticated users to (1) change a u… | Patch early | 6.5 medium | 1.9% | 2008-09-25 |
| CVE-2008-0633 EXP | Buffer overflow in Anon Proxy Server 0.102 and earlier, when user authentication is enabled, allows remote attackers to cause a denial of service (exc… | Patch early | 6.0 medium | 1.9% | 2008-02-06 |
| CVE-2005-3996 EXP | SQL injection vulnerability in admin/password_forgotten.php in Zen Cart 1.2.6d and earlier allows remote attackers to execute arbitrary SQL commands v… | Patch early | 5.1 medium | 1.9% | 2005-12-05 |
| CVE-2009-4939 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdPeeps 8.5d1 allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 1.9% | 2010-07-22 |
| CVE-2006-1569 EXP | Multiple SQL injection vulnerabilities in RedCMS 0.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password par… | Patch early | 5.1 medium | 1.9% | 2006-04-01 |
| CVE-2006-2143 EXP | Multiple cross-site scripting (XSS) vulnerabilities in TextFileBB 1.0.16 allow remote attackers to inject arbitrary web script or HTML via Javascript… | Patch early | 4.3 medium | 1.9% | 2006-05-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt