CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,829 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
170,557 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-0826 EXP | BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to download the database file conta… | Patch early | 5.0 medium | 2.6% | 2009-03-05 |
| CVE-2009-1821 EXP | DMXReady Registration Manager 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to d… | Patch early | 5.0 medium | 2.6% | 2009-05-29 |
| CVE-2015-6545 EXP | Cross-site request forgery (CSRF) vulnerability in ajax.php in Cerb before 7.0.4 allows remote attackers to hijack the authentication of administrator… | Patch early | 6.8 medium | 2.6% | 2015-09-03 |
| CVE-2006-5516 EXP | Multiple cross-site scripting (XSS) vulnerabilities in actions/usersettings.php in WikiNi before 0.4.4 allow remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 2.6% | 2006-10-26 |
| CVE-2019-11375 EXP | Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI. | Patch early | 6.5 medium | 2.6% | 2019-04-20 |
| CVE-2003-1571 EXP | Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… | Patch early | 5.0 medium | 2.6% | 2009-04-02 |
| CVE-2008-5592 EXP | Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo… | Patch early | 5.0 medium | 2.6% | 2008-12-16 |
| CVE-2008-5600 EXP | Merlix Teamworx Server stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… | Patch early | 5.0 medium | 2.6% | 2008-12-16 |
| CVE-2008-5601 EXP | User Engine Lite ASP stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the d… | Patch early | 5.0 medium | 2.6% | 2008-12-16 |
| CVE-2008-5603 EXP | ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database… | Patch early | 5.0 medium | 2.6% | 2008-12-16 |
| CVE-2008-5606 EXP | Gazatem QMail Mailing List Manager 1.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers… | Patch early | 5.0 medium | 2.6% | 2008-12-16 |
| CVE-2008-5762 EXP | Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access control, which allows remote a… | Patch early | 5.0 medium | 2.6% | 2008-12-30 |
| CVE-2008-5852 EXP | Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the da… | Patch early | 5.0 medium | 2.6% | 2009-01-06 |
| CVE-2008-5855 EXP | myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to disc… | Patch early | 5.0 medium | 2.6% | 2009-01-06 |
| CVE-2008-0425 EXP | Absolute path traversal vulnerability in explorerdir.php in Frimousse 0.0.2 allows remote attackers to read arbitrary files and list arbitrary directo… | Patch early | 5.0 medium | 2.6% | 2008-01-23 |
| CVE-2008-2681 EXP | Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.asp, which reveals the database… | Patch early | 5.0 medium | 2.6% | 2008-06-12 |
| CVE-2008-3859 EXP | Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a direct request to conf/admins.php. | Patch early | 5.0 medium | 2.6% | 2008-08-29 |
| CVE-2006-4420 EXP | Directory traversal vulnerability in include_lang.php in Phaos 0.9.2 allows remote attackers to include arbitrary local files via ".." sequences in th… | Patch early | 5.0 medium | 2.6% | 2006-08-28 |
| CVE-2004-1855 EXP | Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers to gain sensitive information… | Patch early | 5.0 medium | 2.6% | 2004-03-23 |
| CVE-2011-0886 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the SMC SMCD3G-CCR (aka Comcast Business Gateway) with firmware bef… | Patch early | 6.8 medium | 2.6% | 2011-02-08 |
| CVE-2009-1584 EXP | Multiple SQL injection vulnerabilities in TemaTres 1.0.3 and 1.031, when magic_quotes_gpc is disabled, allow remote attackers or remote authenticated… | Patch early | 6.0 medium | 2.6% | 2009-05-07 |
| CVE-2011-1714 EXP | Cross-site scripting (XSS) vulnerability in framework/source/resource/qx/test/jsonp_primitive.php in QooxDoo 1.3 and possibly other versions, as used… | Patch early | 4.3 medium | 2.6% | 2011-04-18 |
| CVE-2018-12650 EXP | Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSearch page via 'prntDDLCntrlNam… | Patch early | 6.1 medium | 2.6% | 2018-10-24 |
| CVE-2018-12653 EXP | A Reflected Cross Site Scripting (XSS) vulnerability exists in Adrenalin HRMS 5.4.0. An attacker can input malicious JavaScript code in /RPT/SSRSDynam… | Patch early | 6.1 medium | 2.6% | 2019-03-25 |
| CVE-2008-7014 EXP | fhttpd 0.4.2 allows remote attackers to cause a denial of service (crash) via an Authorization HTTP header with an invalid character after the Basic v… | Patch early | 5.0 medium | 2.6% | 2009-08-19 |
| CVE-2008-7203 EXP | Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets. | Patch early | 5.0 medium | 2.6% | 2009-09-11 |
| CVE-2008-4167 EXP | useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add… | Patch early | 6.4 medium | 2.6% | 2008-09-22 |
| CVE-2018-15533 EXP | A reflected cross-site scripting vulnerability exists in Geutebrueck re_porter 16 before 7.8.974.20 by appending a query string to /modifychannel/exec… | Patch early | 6.1 medium | 2.6% | 2018-08-21 |
| CVE-2004-0275 EXP | SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain acce… | Patch early | 5.0 medium | 2.6% | 2004-11-23 |
| CVE-2008-3254 EXP | SQL injection vulnerability in index.php in preCMS 1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a UserProfil ac… | Patch early | 6.8 medium | 2.6% | 2008-07-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt