CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,851 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
170,577 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-2557 EXP | Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 2.6% | 2005-09-28 |
| CVE-2006-1258 EXP | Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows remote attackers to inject arbitrary web script or HTML via the set_theme parame… | Patch early | 4.3 medium | 2.6% | 2006-03-19 |
| CVE-2006-6660 EXP | The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote attackers to cause a denial of… | Patch early | 4.3 medium | 2.6% | 2006-12-20 |
| CVE-2008-4484 EXP | main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to "users," as demonstra… | Patch early | 6.8 medium | 2.6% | 2008-10-08 |
| CVE-2007-1726 EXP | Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitrary files via the avatar functi… | Patch early | 6.5 medium | 2.6% | 2007-03-28 |
| CVE-2008-5792 EXP | PHP remote file inclusion vulnerability in show_joined.php in Indiscripts Enthusiast 3.1.4, and possibly earlier, allows remote attackers to execute a… | Patch early | 6.8 medium | 2.6% | 2008-12-31 |
| CVE-2004-1824 EXP | Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.0 allows remote attackers to inject arbitrary web script or HTML via the what p… | Patch early | 4.3 medium | 2.6% | 2004-12-31 |
| CVE-2012-4036 EXP | Unrestricted file upload vulnerability in admin.php in PBBoard 2.1.4 allows remote administrators to execute arbitrary PHP code by uploading a file wi… | Patch early | 6.8 medium | 2.6% | 2012-08-27 |
| CVE-2012-1671 EXP | Directory traversal vulnerability in index.php in phpPaleo 4.8b155 and earlier allows remote attackers to include and execute arbitrary local files vi… | Patch early | 6.8 medium | 2.6% | 2012-10-08 |
| CVE-2010-1890 EXP | The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate ACLs on kernel obje… | Patch early | 4.6 medium | 2.6% | 2010-08-11 |
| CVE-2010-3023 EXP | Multiple cross-site scripting (XSS) vulnerabilities in DiamondList 0.1.6, and possibly earlier, allow remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 2.6% | 2010-08-16 |
| CVE-2006-3076 EXP | PHP remote file inclusion vulnerability in software_upload/public_includes/pub_templates/vphptree/template.php in PhpBlueDragon CMS 2.9.1 allows remot… | Patch early | 6.4 medium | 2.6% | 2006-06-19 |
| CVE-2017-11830 EXP | Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to make an unsig… | Patch early | 5.3 medium | 2.6% | 2017-11-15 |
| CVE-2009-3422 EXP | login.php in Zenas PaoLiber 1.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by… | Patch early | 6.8 medium | 2.6% | 2009-09-25 |
| CVE-2009-3423 EXP | login.php in Zenas PaoLink 1.0, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by s… | Patch early | 6.8 medium | 2.6% | 2009-09-25 |
| CVE-2005-1884 EXP | Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to crea… | Patch early | 6.4 medium | 2.6% | 2005-06-09 |
| CVE-2019-12745 EXP | out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field. | Patch early | 5.4 medium | 2.6% | 2019-06-20 |
| CVE-2002-2247 EXP | The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full web root pat… | Patch early | 5.0 medium | 2.6% | 2002-12-31 |
| CVE-2007-2943 EXP | PHP remote file inclusion vulnerability in class/class.php in Webavis 0.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the roo… | Patch early | 6.8 medium | 2.6% | 2007-05-31 |
| CVE-2006-5262 EXP | CRLF injection vulnerability in lib/session.php in Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary IMAP… | Patch early | 6.5 medium | 2.6% | 2006-10-12 |
| CVE-2006-0734 EXP | The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remote authenticated users to cause… | Patch early | 4.0 medium | 2.6% | 2006-02-16 |
| CVE-2007-5573 EXP | PHP remote file inclusion vulnerability in classes/core/language.php in LimeSurvey 1.5.2 and earlier allows remote attackers to execute arbitrary PHP… | Patch early | 6.8 medium | 2.6% | 2007-10-18 |
| CVE-2024-44762 EXP | A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts. | Patch early | 5.3 medium | 2.6% | 2024-10-16 |
| CVE-2010-5322 EXP | Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search par… | Patch early | 4.3 medium | 2.6% | 2015-03-11 |
| CVE-2009-0325 EXP | Directory traversal vulnerability in entries/index.php in Ninja Blog 4.8, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary… | Patch early | 4.3 medium | 2.6% | 2009-01-29 |
| CVE-2006-4206 EXP | Cross-site scripting (XSS) vulnerability in calendar.asp in ASPPlayground.NET Forum Advanced Edition 2.4.5 Unicode, and possibly other versions before… | Patch early | 4.3 medium | 2.6% | 2006-08-17 |
| CVE-2011-5075 EXP | translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to obtain sensitive information via a direct request us… | Patch early | 5.0 medium | 2.6% | 2012-01-29 |
| CVE-2014-4163 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the Featured Comments plugin 1.2.1 for WordPress allow remote attackers to hijack the au… | Patch early | 6.8 medium | 2.6% | 2014-06-16 |
| CVE-2014-2088 EXP | Unrestricted file upload vulnerability in ilias.php in ILIAS 4.4.1 allows remote authenticated users to execute arbitrary PHP code by using a .php fil… | Patch early | 6.5 medium | 2.6% | 2014-03-02 |
| CVE-2021-31673 EXP | A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitra… | Patch early | 6.1 medium | 2.6% | 2022-05-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt