CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,829 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
170,557 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-4874 EXP | TalkBack 2.3.14 does not properly restrict access to the edit comment feature (comments.php), which allows remote attackers to modify comments. | Patch early | 6.4 medium | 2.6% | 2010-05-26 |
| CVE-2008-5794 EXP | Directory traversal vulnerability in system/admin/images.php in LoveCMS 1.6.2 Final allows remote attackers to delete arbitrary files via a .. (dot do… | Patch early | 5.0 medium | 2.6% | 2008-12-31 |
| CVE-2015-6517 EXP | Cross-site request forgery (CSRF) vulnerability in phpLiteAdmin 1.1 allows remote attackers to hijack the authentication of users for requests that dr… | Patch early | 6.8 medium | 2.6% | 2015-08-18 |
| CVE-2008-7142 EXP | Absolute path traversal vulnerability in the Disk Usage module (frontend/x/diskusage/index.html) in cPanel 11.18.3 allows remote attackers to list arb… | Patch early | 5.0 medium | 2.6% | 2009-09-01 |
| CVE-2018-1002009 EXP | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileg… | Patch early | 4.8 medium | 2.6% | 2018-12-03 |
| CVE-2007-5774 EXP | index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invalid argumentname parameter in a… | Patch early | 5.0 medium | 2.6% | 2007-11-01 |
| CVE-2007-6702 EXP | goform/QuickStart_c0 on the GoAhead Web Server on the FS4104-AW (aka rooter) VDSL device contains a password in the typepassword field, which allows r… | Patch early | 5.0 medium | 2.6% | 2008-03-04 |
| CVE-2006-1040 EXP | Cross-site scripting (XSS) vulnerability in vBulletin 3.0.12 and 3.5.3 allows remote attackers to inject arbitrary web script or HTML via the email fi… | Patch early | 4.3 medium | 2.6% | 2006-03-07 |
| CVE-2008-7045 EXP | AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct request to… | Patch early | 6.4 medium | 2.6% | 2009-08-24 |
| CVE-2018-16736 EXP | In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters section of the settings). | Patch early | 5.4 medium | 2.6% | 2018-09-09 |
| CVE-2010-1055 EXP | Multiple PHP remote file inclusion vulnerabilities in osDate 2.1.9 and 2.5.4, when magic_quotes_gpc is disabled and register_globals is enabled, allow… | Patch early | 5.1 medium | 2.6% | 2010-03-23 |
| CVE-2006-1803 EXP | Cross-site scripting (XSS) vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to inject arbitrary web script or HTML via the sql… | Patch early | 4.3 medium | 2.6% | 2006-04-18 |
| CVE-2006-5480 EXP | PHP remote file inclusion vulnerability in lib/rs.php in 2le.net Castor PHP Web Builder 1.1.1 allows remote attackers to execute arbitrary PHP code vi… | Patch early | 5.1 medium | 2.6% | 2006-10-24 |
| CVE-2007-5979 EXP | Cross-site scripting (XSS) vulnerability in download_plugin.php3 in F5 Firepass 4100 SSL VPN 5.4 through 5.5.2 and 6.0 through 6.0.1 allows remote att… | Patch early | 4.3 medium | 2.6% | 2007-11-15 |
| CVE-2005-0320 EXP | Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web sc… | Patch early | 5.0 medium | 2.6% | 2005-01-28 |
| CVE-2008-0636 EXP | Level Platforms, Inc. (LPI) Managed Workplace Service Center 4.x, 5.x and 6.x allows remote attackers to obtain sensitive information via a direct req… | Patch early | 5.0 medium | 2.6% | 2008-02-12 |
| CVE-2022-27308 EXP | A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a pr… | Patch early | 5.4 medium | 2.6% | 2022-05-09 |
| CVE-2018-7707 EXP | Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via an… | Patch early | 6.1 medium | 2.6% | 2018-03-15 |
| CVE-2004-2625 EXP | Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTML via Javascript in an attribu… | Patch early | 5.1 medium | 2.6% | 2004-12-31 |
| CVE-2009-3802 EXP | Amiro.CMS 5.4.0.0 and earlier allows remote attackers to obtain sensitive information via an invalid loginname ("%%%") to _admin/index.php, which reve… | Patch early | 5.0 medium | 2.6% | 2009-10-27 |
| CVE-2009-4585 EXP | UranyumSoft Listing Service stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa… | Patch early | 5.0 medium | 2.6% | 2010-01-06 |
| CVE-2008-5229 EXP | Stack-based buffer overflow in Microsoft Device IO Control in iphlpapi.dll in Microsoft Windows Vista Gold and SP1 allows local users in the Network C… | Patch early | 6.9 medium | 2.6% | 2008-11-25 |
| CVE-2020-12261 EXP | Open-AudIT 3.3.0 allows an XSS attack after login. | Patch early | 5.4 medium | 2.6% | 2020-04-28 |
| CVE-2008-5596 EXP | Ikon AdManager 2.1 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to down… | Patch early | 5.0 medium | 2.6% | 2008-12-16 |
| CVE-2008-5597 EXP | Cold BBS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file… | Patch early | 5.0 medium | 2.6% | 2008-12-16 |
| CVE-2008-5602 EXP | Natterchat 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the databa… | Patch early | 5.0 medium | 2.6% | 2008-12-16 |
| CVE-2008-5773 EXP | Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database… | Patch early | 5.0 medium | 2.6% | 2008-12-30 |
| CVE-2008-5780 EXP | Forest Blog 1.3.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the data… | Patch early | 5.0 medium | 2.6% | 2008-12-30 |
| CVE-2008-5886 EXP | TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa… | Patch early | 5.0 medium | 2.6% | 2009-01-12 |
| CVE-2008-5929 EXP | VP-ASP Shopping Cart 6.50 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download… | Patch early | 5.0 medium | 2.6% | 2009-01-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt