CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,557 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-1915 EXP | EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks. | Patch early | 6.1 medium | 1.9% | 2020-01-09 |
| CVE-2012-4246 EXP | Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 1.9% | 2012-08-12 |
| CVE-2013-5020 EXP | Multiple cross-site scripting (XSS) vulnerabilities in bb_admin.php in MiniBB before 3.0.1 allow remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.9% | 2013-07-31 |
| CVE-2008-6988 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Easy Photo Gallery (aka Ezphotogallery) 2.1 allow remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 1.9% | 2009-08-19 |
| CVE-2009-0530 EXP | Multiple PHP remote file inclusion vulnerabilities in SnippetMaster 2.2.2, when register_globals is enabled, allow remote attackers to execute arbitra… | Patch early | 6.8 medium | 1.9% | 2009-02-11 |
| CVE-2009-1946 EXP | PHP remote file inclusion vulnerability in latestposts.php in AdaptBB 1.0, when register_globals is enabled, allows remote attackers to execute arbitr… | Patch early | 6.8 medium | 1.9% | 2009-06-05 |
| CVE-2007-3281 EXP | Cross-site scripting (XSS) vulnerability in index.php in Php Hosting Biller 1.0 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.9% | 2007-06-19 |
| CVE-2009-3660 EXP | PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remote attacke… | Patch early | 6.8 medium | 1.9% | 2009-10-11 |
| CVE-2017-14956 EXP | AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php"… | Patch early | 5.7 medium | 1.9% | 2017-10-18 |
| CVE-2013-6166 EXP | Google Chrome before 29 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote… | Patch early | 6.8 medium | 1.9% | 2014-02-15 |
| CVE-2010-0760 EXP | Multiple directory traversal vulnerabilities in the Core Design Scriptegrator plugin 1.4.1 for Joomla! allow remote attackers to include and execute a… | Patch early | 6.8 medium | 1.9% | 2010-02-27 |
| CVE-2010-0958 EXP | Directory traversal vulnerability in modules/hayoo/index.php in Tribisur 2.1, 2.0, and earlier, when magic_quotes_gpc is disabled, allows remote attac… | Patch early | 6.8 medium | 1.9% | 2010-03-10 |
| CVE-2010-1060 EXP | Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allows remote attackers to… | Patch early | 6.8 medium | 1.9% | 2010-03-23 |
| CVE-2010-1062 EXP | Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allo… | Patch early | 6.8 medium | 1.9% | 2010-03-23 |
| CVE-2010-1077 EXP | Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers to include and execute arbitra… | Patch early | 6.8 medium | 1.9% | 2010-03-23 |
| CVE-2008-2813 EXP | Directory traversal vulnerability in index.php in WallCity-Server Shoutcast Admin Panel 2.0, when magic_quotes_gpc is disabled, allows remote attacker… | Patch early | 6.8 medium | 1.9% | 2008-06-23 |
| CVE-2008-2913 EXP | Directory traversal vulnerability in func.php in Devalcms 1.4a, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbi… | Patch early | 6.8 medium | 1.9% | 2008-06-30 |
| CVE-2008-4483 EXP | Directory traversal vulnerability in index.php in Crux Gallery 1.32 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include… | Patch early | 6.8 medium | 1.9% | 2008-10-08 |
| CVE-2008-4712 EXP | Directory traversal vulnerability in pages/showblog.php in LnBlog 0.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to inc… | Patch early | 6.8 medium | 1.9% | 2008-10-23 |
| CVE-2008-5962 EXP | Directory traversal vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remote attackers to include a… | Patch early | 6.8 medium | 1.9% | 2009-01-23 |
| CVE-2008-6177 EXP | Multiple directory traversal vulnerabilities in LightBlog 9.8, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitr… | Patch early | 6.8 medium | 1.9% | 2009-02-19 |
| CVE-2008-6265 EXP | Directory traversal vulnerability in portfolio/css.php in Cyberfolio 7.12.2 and earlier allows remote attackers to include and execute arbitrary local… | Patch early | 6.8 medium | 1.9% | 2009-02-24 |
| CVE-2008-6271 EXP | Directory traversal vulnerability in index.php in TBmnetCMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files vi… | Patch early | 6.8 medium | 1.9% | 2009-02-25 |
| CVE-2008-6842 EXP | Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to include and execute arbitrary l… | Patch early | 6.8 medium | 1.9% | 2009-07-02 |
| CVE-2008-7254 EXP | Directory traversal vulnerability in includes/template-loader.php in Irmin CMS (formerly Pepsi CMS) 0.5 and 0.6 BETA2, when register_globals is enable… | Patch early | 6.8 medium | 1.9% | 2010-04-07 |
| CVE-2008-6199 EXP | 2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via a direct request to backup.ph… | Patch early | 4.0 medium | 1.9% | 2009-02-20 |
| CVE-2009-5095 EXP | PHP remote file inclusion vulnerability in index_inc.php in ea gBook 0.1 and 0.1.4 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 6.8 medium | 1.9% | 2011-09-12 |
| CVE-2008-2227 EXP | Multiple directory traversal vulnerabilities in PHP-Fusion Forum Rank System 6 allow remote attackers to include and execute arbitrary local files via… | Patch early | 6.8 medium | 1.9% | 2008-05-14 |
| CVE-2005-2065 EXP | HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web content and poison web caches via C… | Patch early | 5.0 medium | 1.9% | 2005-06-29 |
| CVE-2007-0950 EXP | Cross-site scripting (XSS) vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to inject arbitrary web script or HTM… | Patch early | 6.8 medium | 1.9% | 2007-02-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt