CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,602 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-24963 EXP | An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4. | Patch early | 5.4 medium | 1.9% | 2020-09-04 |
| CVE-2012-6517 EXP | Multiple cross-site scripting (XSS) vulnerabilities in DiY-CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) question… | Patch early | 4.3 medium | 1.9% | 2013-01-24 |
| CVE-2006-6380 EXP | Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary web script or HTML via the keyw… | Patch early | 6.8 medium | 1.9% | 2006-12-07 |
| CVE-2012-6528 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_IN… | Patch early | 4.3 medium | 1.9% | 2013-01-31 |
| CVE-2009-0701 EXP | Multiple PHP remote file inclusion vulnerabilities in index.php in Cybershade CMS 0.2b, when register_globals is enabled, allow remote attackers to ex… | Patch early | 6.8 medium | 1.9% | 2009-02-23 |
| CVE-2006-6708 EXP | Cross-site scripting (XSS) vulnerability in listings.asp in MGinternet Property Site Manager allows remote attackers to inject arbitrary web script or… | Patch early | 6.8 medium | 1.9% | 2006-12-23 |
| CVE-2008-0501 EXP | Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pa… | Patch early | 5.8 medium | 1.9% | 2008-01-30 |
| CVE-2008-6735 EXP | Directory traversal vulnerability in qc/index.php in ThaiQuickCart 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the sLangua… | Patch early | 5.8 medium | 1.9% | 2009-04-21 |
| CVE-2004-2363 EXP | Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allows remote attackers to conduct… | Patch early | 4.3 medium | 1.8% | 2004-12-31 |
| CVE-2007-4862 EXP | Cross-site scripting (XSS) vulnerability in admin/menu.php in SAXON 5.4 allows remote attackers to inject arbitrary web script or HTML via the config[… | Patch early | 4.3 medium | 1.8% | 2007-10-30 |
| CVE-2005-0410 EXP | SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV file. | Patch early | 5.0 medium | 1.8% | 2005-02-14 |
| CVE-2006-6777 EXP | Cross-site scripting (XSS) vulnerability in index.cfm in Future Internet allows remote attackers to inject arbitrary web script or HTML via the catego… | Patch early | 6.8 medium | 1.8% | 2006-12-28 |
| CVE-2008-0478 EXP | Directory traversal vulnerability in index.php in SetCMS 3.6.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot)… | Patch early | 6.8 medium | 1.8% | 2008-01-29 |
| CVE-2008-1553 EXP | Directory traversal vulnerability in mod.php in TopperMod 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot)… | Patch early | 6.8 medium | 1.8% | 2008-03-31 |
| CVE-2008-1962 EXP | Multiple directory traversal vulnerabilities in Aterr 0.9.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in… | Patch early | 6.8 medium | 1.8% | 2008-04-25 |
| CVE-2008-2217 EXP | Directory traversal vulnerability in cm/graphie.php in Content Management System 0.6.1 for Phprojekt allows remote attackers to include and execute ar… | Patch early | 6.8 medium | 1.8% | 2008-05-14 |
| CVE-2008-2976 EXP | Multiple directory traversal vulnerabilities in TinX/cms 1.1, when register_globals is enabled, allow remote attackers to include and execute arbitrar… | Patch early | 6.8 medium | 1.8% | 2008-07-02 |
| CVE-2008-2978 EXP | Directory traversal vulnerability in phpi/rss.php in Ourvideo CMS 9.5, when register_globals is enabled, allows remote attackers to include and execut… | Patch early | 6.8 medium | 1.8% | 2008-07-02 |
| CVE-2008-2985 EXP | Directory traversal vulnerability in load_language.php in CMReams CMS 1.3.1.1 Beta 2, when register_globals is enabled, allows remote attackers to inc… | Patch early | 6.8 medium | 1.8% | 2008-07-02 |
| CVE-2008-4739 EXP | Directory traversal vulnerability in index.php in PlugSpace 0.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arb… | Patch early | 6.8 medium | 1.8% | 2008-10-24 |
| CVE-2008-5204 EXP | Multiple directory traversal vulnerabilities in PowerAward 1.1.0 RC1, when register_globals is enabled, allow remote attackers to include and execute… | Patch early | 6.8 medium | 1.8% | 2008-11-21 |
| CVE-2008-5990 EXP | Directory traversal vulnerability in connect/init.inc in emergecolab 1.0 allows remote attackers to include and execute arbitrary local files via a ..… | Patch early | 6.8 medium | 1.8% | 2009-01-28 |
| CVE-2008-6361 EXP | Directory traversal vulnerability in index.php in InSun Feed CMS 1.7.3 19Beta allows remote attackers to include and execute arbitrary local files via… | Patch early | 6.8 medium | 1.8% | 2009-03-02 |
| CVE-2006-1925 EXP | Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify f… | Patch early | 4.3 medium | 1.8% | 2006-04-20 |
| CVE-2009-4458 EXP | Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow remote attackers to inject arbit… | Patch early | 4.3 medium | 1.8% | 2009-12-30 |
| CVE-2009-4547 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ViArt CMS 3.x allow remote attackers to inject arbitrary web script or HTML via the (1) categor… | Patch early | 4.3 medium | 1.8% | 2010-01-04 |
| CVE-2018-10752 EXP | The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action. | Patch early | 4.8 medium | 1.8% | 2018-05-05 |
| CVE-2018-10321 EXP | Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings. | Patch early | 4.8 medium | 1.8% | 2018-04-24 |
| CVE-2005-1803 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 1.8% | 2005-05-29 |
| CVE-2006-3052 EXP | Cross-site scripting (XSS) vulnerability in Event Registration allows remote attackers to inject arbitrary web script or HTML via the (1) event_id par… | Patch early | 6.8 medium | 1.8% | 2006-06-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt