CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,573 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
170,178 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-2211 EXP | Absolute path traversal vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to browse arbitrary directories via the path par… | Patch early | 5.0 medium | 3.2% | 2006-05-05 |
| CVE-2007-1906 EXP | Directory traversal vulnerability in richedit/keyboard.php in eCardMAX HotEditor (Hot Editor) 4.0, and the HotEditor plugin for MyBB, allows remote at… | Patch early | 6.8 medium | 3.2% | 2007-04-10 |
| CVE-2010-1921 EXP | Multiple PHP remote file inclusion vulnerabilities in OpenMairie openAnnuaire 2.00, when register_globals is enabled, allow remote attackers to execut… | Patch early | 6.8 medium | 3.2% | 2010-05-12 |
| CVE-2010-1927 EXP | Multiple PHP remote file inclusion vulnerabilities in openMairie openCourrier 2.02 and 2.03 beta, when register_globals is enabled, allow remote attac… | Patch early | 6.8 medium | 3.2% | 2010-05-12 |
| CVE-2007-6129 EXP | Directory traversal vulnerability in scripts/include/show_content.php in Amber Script 1.0 allows remote attackers to include and execute arbitrary loc… | Patch early | 5.8 medium | 3.2% | 2007-11-26 |
| CVE-2007-2166 EXP | PHP remote file inclusion vulnerability in administration/user/lib/group.inc.php in OpenSurveyPilot (osp) 1.2.1 and earlier allows remote attackers to… | Patch early | 6.8 medium | 3.2% | 2007-04-22 |
| CVE-2008-4136 EXP | Michael Roth Software Personal FTP Server (PFT) 6.0f allows remote attackers to cause a denial of service (service crash) via multiple RETR commands,… | Patch early | 5.0 medium | 3.2% | 2008-09-24 |
| CVE-2002-1021 EXP | BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte. | Patch early | 5.0 medium | 3.2% | 2002-10-04 |
| CVE-2004-0303 EXP | OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filena… | Patch early | 5.0 medium | 3.2% | 2004-11-23 |
| CVE-2009-4497 EXP | Cross-site scripting (XSS) vulnerability in LXR Cross Referencer 0.9.5 and 0.9.6 allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 3.2% | 2010-01-07 |
| CVE-2012-6312 EXP | Cross-site scripting (XSS) vulnerability in the Video Lead Form plugin for WordPress allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 3.2% | 2012-12-11 |
| CVE-2018-8813 EXP | Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbit… | Patch early | 4.8 medium | 3.2% | 2018-04-04 |
| CVE-2013-2750 EXP | Cross-site scripting (XSS) vulnerability in e107_plugins/content/handlers/content_preset.php in e107 before 1.0.3 allows remote attackers to inject ar… | Patch early | 4.3 medium | 3.2% | 2014-01-22 |
| CVE-2013-3639 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Xaraya 2.4.0-b1 and earlier allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 3.2% | 2014-02-05 |
| CVE-2013-5312 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 3.2% | 2013-08-19 |
| CVE-2014-9580 EXP | Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) r561 allows remote attackers to inject arbitrary web script or HTML via the De… | Patch early | 4.3 medium | 3.2% | 2015-01-08 |
| CVE-2015-1478 EXP | Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to inject arbitrary web s… | Patch early | 4.3 medium | 3.2% | 2015-02-04 |
| CVE-2013-6793 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allow remote attackers to inject arbitrary w… | Patch early | 4.3 medium | 3.2% | 2013-11-14 |
| CVE-2013-6923 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to inj… | Patch early | 4.3 medium | 3.2% | 2014-01-09 |
| CVE-2014-100017 EXP | Cross-site scripting (XSS) vulnerability in canned_opr.php in PhpOnlineChat 3.0 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 3.2% | 2015-01-13 |
| CVE-2014-1603 EXP | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) p… | Patch early | 4.3 medium | 3.2% | 2014-05-14 |
| CVE-2014-6619 EXP | Multiple cross-site scripting (XSS) vulnerabilities in register-exec.php in Restaurant Script (PizzaInn_Project) 1.0.0 allow remote attackers to injec… | Patch early | 4.3 medium | 3.2% | 2014-09-30 |
| CVE-2014-8469 EXP | Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 3.2% | 2014-11-21 |
| CVE-2014-8954 EXP | Multiple cross-site scripting (XSS) vulnerabilities in phpSound 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Title… | Patch early | 4.3 medium | 3.2% | 2014-11-17 |
| CVE-2014-9142 EXP | Cross-site scripting (XSS) vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 3.2% | 2014-12-05 |
| CVE-2014-9349 EXP | Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 3.2% | 2014-12-08 |
| CVE-2014-2586 EXP | Cross-site scripting (XSS) vulnerability in the login audit form in McAfee Cloud Single Sign On (SSO) allows remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 3.2% | 2014-03-24 |
| CVE-2014-3974 EXP | Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3.2% | 2014-06-05 |
| CVE-2014-4166 EXP | Cross-site scripting (XSS) vulnerability in the song history in SHOUTcast DNAS 2.2.1 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 3.2% | 2014-06-16 |
| CVE-2014-4710 EXP | Cross-site scripting (XSS) vulnerability in zero_user_account.php in ZeroCMS 1.0 allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 3.2% | 2014-07-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt