CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,769 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
170,545 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-4330 EXP | Directory traversal vulnerability in includes/controller.php in Pulse CMS Basic before 1.2.9 allows remote attackers to include and execute arbitrary… | Patch early | 6.8 medium | 2.6% | 2010-12-07 |
| CVE-2011-4831 EXP | Directory traversal vulnerability in webFileBrowser.php in Web File Browser 0.4b14 allows remote authenticated users to read arbitrary files via a ..%… | Patch early | 4.0 medium | 2.6% | 2011-12-15 |
| CVE-2023-23286 EXP | Cross Site Scripting (XSS) vulnerability in Provide server 14.4 allows attackers to execute arbitrary code through the server-log via username field f… | Patch early | 6.1 medium | 2.6% | 2023-02-10 |
| CVE-2018-11443 EXP | The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0. | Patch early | 6.1 medium | 2.6% | 2018-05-25 |
| CVE-2006-4723 EXP | PHP remote file inclusion vulnerability in raidenhttpd-admin/slice/check.php in RaidenHTTPD 1.1.49, when register_globals and WebAdmin is enabled, all… | Patch early | 5.1 medium | 2.6% | 2006-09-12 |
| CVE-2006-4945 EXP | Multiple PHP remote file inclusion vulnerabilities in Cardway (aka Frederic Boudaud) DigitalWebShop 1.128 and earlier allow remote attackers to execut… | Patch early | 5.1 medium | 2.6% | 2006-09-23 |
| CVE-2006-4946 EXP | PHP remote file inclusion vulnerability in include/startup.inc.php in CMSDevelopment Business Card Web Builder (BCWB) 0.99, and possibly 2.5 Beta and… | Patch early | 5.1 medium | 2.6% | 2006-09-23 |
| CVE-2006-5165 EXP | PHP remote file inclusion vulnerability in inc/functions.inc.php in Skrypty PPA Gallery 1.0 and earlier allows remote attackers to execute arbitrary P… | Patch early | 5.1 medium | 2.6% | 2006-10-05 |
| CVE-2006-5284 EXP | PHP remote file inclusion vulnerability in auth/phpbb.inc.php in Shen Cheng-Da PHP News Reader (aka pnews) 2.6.4 and earlier allows remote attackers t… | Patch early | 5.1 medium | 2.6% | 2006-10-13 |
| CVE-2005-2085 EXP | Buffer overflow in Inframail Advantage Server Edition 6.0 through 6.7 allows remote attackers to cause a denial of service (process crash) via a long… | Patch early | 5.0 medium | 2.6% | 2005-07-05 |
| CVE-2002-0333 EXP | Directory traversal vulnerability in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to read files with short names, an… | Patch early | 5.0 medium | 2.6% | 2002-06-25 |
| CVE-2010-4099 EXP | ess.pm in NitroSecurity NitroView ESM 8.4.0a, when ESSPMDebug is enabled, allows remote attackers to execute arbitrary commands via shell metacharacte… | Patch early | 6.8 medium | 2.6% | 2010-10-27 |
| CVE-2018-18760 EXP | RhinOS 3.0 build 1190 allows CSRF. | Patch early | 6.5 medium | 2.6% | 2018-11-16 |
| CVE-2019-11564 EXP | A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HTML via a /protected/vendor/cod… | Patch early | 6.1 medium | 2.6% | 2019-05-08 |
| CVE-2017-8382 EXP | admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user accounts. | Patch early | 4.5 medium | 2.6% | 2017-05-16 |
| CVE-2006-6597 EXP | Argument injection vulnerability in HyperAccess 8.4 allows user-assisted remote attackers to execute arbitrary vbscript and commands via the /r option… | Patch early | 6.8 medium | 2.6% | 2006-12-15 |
| CVE-2003-1381 EXP | Format string vulnerability in AMX 0.9.2 and earlier, a plugin for Valve Software's Half-Life Server, allows remote attackers to execute arbitrary com… | Patch early | 6.8 medium | 2.6% | 2003-12-31 |
| CVE-2005-3200 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 2.6% | 2005-10-14 |
| CVE-2017-9813 EXP | In Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312), the scriptName parameter of the licenseKey… | Patch early | 6.1 medium | 2.6% | 2017-07-17 |
| CVE-2005-0632 EXP | PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the… | Patch early | 5.0 medium | 2.6% | 2005-03-01 |
| CVE-2006-0473 EXP | Cross-site scripting (XSS) vulnerability in the bbcode function in weblog.php in my little homepage my little weblog, as last modified in April 2004,… | Patch early | 4.3 medium | 2.6% | 2006-01-31 |
| CVE-2010-1544 EXP | micro_httpd on the RCA DCM425 cable modem allows remote attackers to cause a denial of service (device reboot) via a long string to TCP port 80. | Patch early | 5.0 medium | 2.6% | 2010-04-26 |
| CVE-2008-1713 EXP | MailServer.exe in NoticeWare Email Server 4.6.1.0 allows remote attackers to cause a denial of service (application crash) via a long string to IMAP p… | Patch early | 5.0 medium | 2.6% | 2008-04-09 |
| CVE-2015-2084 EXP | Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote attackers to hijack the authe… | Patch early | 6.8 medium | 2.6% | 2015-02-25 |
| CVE-2020-8778 EXP | Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write ac… | Patch early | 5.4 medium | 2.6% | 2020-03-02 |
| CVE-2006-2066 EXP | Multiple cross-site scripting (XSS) vulnerabilities pm_popup.php in MKPortal 1.1 Rc1 and earlier, as used with vBulletin 3.5.4 and earlier, allow remo… | Patch early | 4.3 medium | 2.6% | 2006-04-27 |
| CVE-2008-0473 EXP | RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors. | Patch early | 6.4 medium | 2.6% | 2008-01-29 |
| CVE-2006-0407 EXP | Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 2.6% | 2006-01-25 |
| CVE-2008-5931 EXP | The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download… | Patch early | 5.0 medium | 2.6% | 2009-01-21 |
| CVE-2009-0453 EXP | Online Grades 3.2.4 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. | Patch early | 5.0 medium | 2.6% | 2009-02-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt