CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,069 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
169,942 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-3261 EXP | Open redirect vulnerability in claroline/redirector.php in Claroline before 1.8.10 allows remote attackers to redirect users to arbitrary web sites an… | Patch early | 4.3 medium | 4.8% | 2008-07-22 |
| CVE-2010-2680 EXP | Directory traversal vulnerability in the JExtensions JE Section/Property Finder (jesectionfinder) component for Joomla! allows remote attackers to inc… | Patch early | 6.8 medium | 4.8% | 2010-07-12 |
| CVE-2010-2857 EXP | Directory traversal vulnerability in the Music Manager component for Joomla! allows remote attackers to read arbitrary files and possibly have unspeci… | Patch early | 6.8 medium | 4.8% | 2010-07-25 |
| CVE-2013-3242 EXP | plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializin… | Patch early | 5.5 medium | 4.8% | 2013-05-03 |
| CVE-2011-5214 EXP | Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 4.8% | 2012-10-25 |
| CVE-2014-2879 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to in… | Patch early | 4.3 medium | 4.8% | 2014-04-17 |
| CVE-2016-10258 EXP | Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administra… | Patch early | 6.8 medium | 4.8% | 2018-04-11 |
| CVE-2017-18256 EXP | Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert() argument in JavaScript code… | Patch early | 6.5 medium | 4.8% | 2018-04-04 |
| CVE-2012-0904 EXP | VLC media player 1.1.11 allows remote attackers to cause a denial of service (crash) via a long string in an amr file. | Patch early | 4.3 medium | 4.8% | 2012-01-20 |
| CVE-2005-0443 EXP | index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks v… | Patch early | 4.3 medium | 4.8% | 2005-05-02 |
| CVE-2007-4528 EXP | The Foreign Function Interface (ffi) extension in PHP 5.0.5 does not follow safe_mode restrictions, which allows context-dependent attackers to execut… | Patch early | 4.3 medium | 4.8% | 2007-08-25 |
| CVE-2011-5148 EXP | Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote attack… | Patch early | 6.8 medium | 4.8% | 2012-08-31 |
| CVE-2017-11333 EXP | The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted… | Patch early | 5.5 medium | 4.8% | 2017-07-31 |
| CVE-2006-0971 EXP | Directory traversal vulnerability in Lionel Reyero DirectContact 0.3b allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | Patch early | 5.0 medium | 4.8% | 2006-03-03 |
| CVE-2007-2144 EXP | PHP remote file inclusion vulnerability in includes/CAltInstaller.php in the JoomlaPack (com_jpack) 1.0.4a2 RE component for Joomla! allows remote att… | Patch early | 6.8 medium | 4.8% | 2007-04-19 |
| CVE-2010-3449 EXP | Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1… | Patch early | 6.8 medium | 4.8% | 2010-12-06 |
| CVE-2009-0442 EXP | Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute arbitrary local files via a .… | Patch early | 6.8 medium | 4.8% | 2009-02-10 |
| CVE-2003-1256 EXP | aff_liste_langue.php in E-theni allows remote attackers to execute arbitrary PHP code by modifying the rep_include parameter to reference a URL on a r… | Patch early | 6.8 medium | 4.8% | 2003-12-31 |
| CVE-2004-0322 EXP | Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1)… | Patch early | 4.3 medium | 4.8% | 2004-02-23 |
| CVE-2009-3535 EXP | Directory traversal vulnerability in image.php in Clear Content 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the url para… | Patch early | 4.3 medium | 4.8% | 2009-10-02 |
| CVE-2009-3701 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in Horde Application Framework before 3.3.6, Horde Groupware befor… | Patch early | 4.3 medium | 4.8% | 2009-12-21 |
| CVE-2018-20326 EXP | ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage=html/index.html var:subpage p… | Patch early | 6.1 medium | 4.8% | 2019-01-02 |
| CVE-2006-4881 EXP | Multiple cross-site scripting (XSS) vulnerabilities in David Bennett PHP-Post (PHPp) 1.0 and earlier allow remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 4.8% | 2006-09-19 |
| CVE-2009-2736 EXP | Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators to inject arbitrary PHP code in… | Patch early | 6.5 medium | 4.8% | 2009-08-11 |
| CVE-2006-5653 EXP | Cross-site scripting (XSS) vulnerability in the errorHTML function in the index script in Sun Java System Messenger Express 6 allows remote attackers… | Patch early | 4.3 medium | 4.8% | 2006-11-03 |
| CVE-2017-15646 EXP | Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote URL' option t… | Patch early | 6.1 medium | 4.8% | 2017-10-19 |
| CVE-2017-15374 EXP | Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management system backend modules. Remot… | Patch early | 6.1 medium | 4.8% | 2017-10-16 |
| CVE-2008-2751 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Glassfish webadmin interface in Sun Java System Application Server 9.1_01 allow remote atta… | Patch early | 4.3 medium | 4.8% | 2008-06-18 |
| CVE-2009-0643 EXP | Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary PHP code into news.txt via th… | Patch early | 5.1 medium | 4.8% | 2009-02-20 |
| CVE-2008-6956 EXP | Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code int… | Patch early | 6.5 medium | 4.8% | 2009-08-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt