CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,851 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
170,577 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-6356 EXP | evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a da… | Patch early | 5.0 medium | 2.6% | 2009-03-02 |
| CVE-2008-6357 EXP | MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to down… | Patch early | 5.0 medium | 2.6% | 2009-03-02 |
| CVE-2008-6374 EXP | CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access control, which allows remote at… | Patch early | 5.0 medium | 2.6% | 2009-03-02 |
| CVE-2008-6387 EXP | Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download t… | Patch early | 5.0 medium | 2.6% | 2009-03-02 |
| CVE-2009-3544 EXP | Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HT… | Patch early | 5.0 medium | 2.6% | 2009-10-05 |
| CVE-2009-4760 EXP | Winn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo… | Patch early | 5.0 medium | 2.6% | 2010-03-29 |
| CVE-2009-4799 EXP | Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database… | Patch early | 5.0 medium | 2.6% | 2010-04-22 |
| CVE-2008-2873 EXP | sHibby sHop 2.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa… | Patch early | 5.0 medium | 2.6% | 2008-06-26 |
| CVE-2008-4115 EXP | TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function. | Patch early | 5.0 medium | 2.6% | 2008-09-16 |
| CVE-2008-0249 EXP | PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the creden… | Patch early | 5.0 medium | 2.6% | 2008-01-12 |
| CVE-2023-31698 EXP | Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trus… | Patch early | 5.4 medium | 2.6% | 2023-05-17 |
| CVE-2006-6328 EXP | Directory traversal vulnerability in index.php for TorrentFlux 2.2 allows remote attackers to create or overwrite arbitrary files via sequences in the… | Patch early | 4.9 medium | 2.6% | 2006-12-06 |
| CVE-2006-6329 EXP | index.php for TorrentFlux 2.2 allows remote attackers to delete files by specifying the target filename in the delfile parameter. | Patch early | 4.9 medium | 2.6% | 2006-12-06 |
| CVE-2005-2412 EXP | PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP code via the Include parameter. | Patch early | 5.0 medium | 2.6% | 2005-08-03 |
| CVE-2006-1230 EXP | Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (… | Patch early | 4.3 medium | 2.6% | 2006-03-14 |
| CVE-2018-6671 EXP | Application Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows remote authenticat… | Patch early | 4.7 medium | 2.6% | 2018-06-15 |
| CVE-2015-2199 EXP | Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote authenticated users to execut… | Patch early | 6.5 medium | 2.6% | 2015-03-03 |
| CVE-1999-0811 EXP | Buffer overflow in Samba smbd program via a malformed message command. | Patch early | 5.0 medium | 2.6% | 1999-07-21 |
| CVE-2018-1002006 EXP | These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:14: via POST re… | Patch early | 4.8 medium | 2.6% | 2018-12-03 |
| CVE-2018-1002007 EXP | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileg… | Patch early | 4.8 medium | 2.6% | 2018-12-03 |
| CVE-2018-1002008 EXP | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileg… | Patch early | 4.8 medium | 2.6% | 2018-12-03 |
| CVE-2006-6824 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbi… | Patch early | 4.3 medium | 2.6% | 2006-12-29 |
| CVE-2008-3763 EXP | Variable overwrite vulnerability in libsecure.php in Turnkey PHP Live Helper 2.0.1 and earlier, when register_globals is enabled, allows remote attack… | Patch early | 6.8 medium | 2.6% | 2008-08-21 |
| CVE-2007-1192 EXP | Thomas R. Pasawicz HyperBook Guestbook 1.30 stores sensitive information under the web root with insufficient access control, which allows remote atta… | Patch early | 5.0 medium | 2.6% | 2007-03-02 |
| CVE-2007-4937 EXP | CS Guestbook stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin name… | Patch early | 5.0 medium | 2.6% | 2007-09-18 |
| CVE-2007-0173 EXP | Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled… | Patch early | 6.8 medium | 2.6% | 2007-01-11 |
| CVE-2012-3351 EXP | Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers to inject arbitrary web scrip… | Patch early | 6.1 medium | 2.6% | 2020-02-20 |
| CVE-2001-1472 EXP | SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain adminis… | Patch early | 4.6 medium | 2.6% | 2001-08-03 |
| CVE-2005-3878 EXP | Directory traversal vulnerability in index.php in PHP Doc System 1.5.1 and earlier allows remote attackers to access or include arbitrary files via a… | Patch early | 6.4 medium | 2.6% | 2005-11-29 |
| CVE-2005-4646 EXP | Unspecified vulnerability in index.php in PEARLINGER Pearl Forums 2.4 allows remote attackers to include arbitrary files via the mode parameter, possi… | Patch early | 5.0 medium | 2.6% | 2005-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt