CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,941 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
170,622 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-1369 EXP | moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) page[] and (3) cat[] parameter… | Patch early | 5.0 medium | 2.4% | 2009-04-22 |
| CVE-2008-5936 EXP | front-end/edit.php in mini-pub 0.3 and earlier allows remote attackers to read files and obtain PHP source code via a filename in the sFileName parame… | Patch early | 5.0 medium | 2.4% | 2009-01-22 |
| CVE-2008-7118 EXP | WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain S… | Patch early | 5.0 medium | 2.4% | 2009-08-28 |
| CVE-2010-0674 EXP | StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database… | Patch early | 5.0 medium | 2.4% | 2010-02-22 |
| CVE-2010-0765 EXP | fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database v… | Patch early | 5.0 medium | 2.4% | 2010-03-02 |
| CVE-2010-0939 EXP | Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a d… | Patch early | 5.0 medium | 2.4% | 2010-03-08 |
| CVE-2012-6048 EXP | Guitar Pro 6.1.1 r10791 allows remote attackers to cause a denial of service (crash) via a long string in a gpx file. | Patch early | 5.0 medium | 2.4% | 2012-11-27 |
| CVE-2008-1506 EXP | PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpin… | Patch early | 5.0 medium | 2.4% | 2008-03-25 |
| CVE-2008-1782 EXP | phpdemo/viewsource.php in Advanced Software Engineering ChartDirector 4.1 allows remote attackers to read sensitive files via the file parameter. | Patch early | 5.0 medium | 2.4% | 2008-04-15 |
| CVE-2006-2699 EXP | Cross-site scripting (XSS) vulnerability in getimage.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to inject arbitrary HTML or web scrip… | Patch early | 6.8 medium | 2.4% | 2006-05-31 |
| CVE-2006-5731 EXP | Directory traversal vulnerability in classes/index.php in Lithium CMS 4.04c and earlier allows remote attackers to include and execute arbitrary local… | Patch early | 6.4 medium | 2.4% | 2006-11-06 |
| CVE-2018-10311 EXP | A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 6.1 medium | 2.4% | 2018-04-24 |
| CVE-2008-2199 EXP | PHP remote file inclusion vulnerability in kmitaadmin/kmitam/htmlcode.php in Kmita Mail 3.0 and earlier, when register_globals is enabled, allows remo… | Patch early | 6.8 medium | 2.4% | 2008-05-14 |
| CVE-2010-1057 EXP | Multiple directory traversal vulnerabilities in Phpkobo AdFreely (aka Ad Board Script) 1.01, when magic_quotes_gpc is disabled, allow remote attackers… | Patch early | 6.8 medium | 2.4% | 2010-03-23 |
| CVE-2016-6853 EXP | An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can be injected to the names of PG… | Patch early | 6.1 medium | 2.4% | 2016-12-15 |
| CVE-2016-6854 EXP | An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline PGP signature gets executed w… | Patch early | 6.1 medium | 2.4% | 2016-12-15 |
| CVE-2006-1704 EXP | Sire 2.0 nws allows remote attackers to upload arbitrary image files without authentication via a direct request to upload.php. | Patch early | 5.0 medium | 2.4% | 2006-04-11 |
| CVE-2012-4254 EXP | MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information (Notices) via a direct request to (1) learn/cubemail/restore.php or (2) lea… | Patch early | 4.3 medium | 2.4% | 2012-08-13 |
| CVE-2008-0794 EXP | Directory traversal vulnerability in user/header.php in Affiliate Market 0.1 BETA allows remote attackers to include and execute arbitrary local files… | Patch early | 6.4 medium | 2.4% | 2008-02-15 |
| CVE-2007-3638 EXP | Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users, who are listed in an address book, to execute arbitrary code… | Patch early | 6.0 medium | 2.4% | 2007-07-10 |
| CVE-1999-0376 EXP | Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs. | Patch early | 4.6 medium | 2.4% | 1999-02-20 |
| CVE-2004-1958 EXP | Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in… | Patch early | 5.0 medium | 2.4% | 2004-12-31 |
| CVE-2004-1470 EXP | CRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTTP Response Splitting attacks t… | Patch early | 5.0 medium | 2.4% | 2004-12-31 |
| CVE-2004-1687 EXP | CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks to modify exp… | Patch early | 5.0 medium | 2.4% | 2004-09-16 |
| CVE-2005-0795 EXP | HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified v… | Patch early | 5.0 medium | 2.4% | 2005-03-14 |
| CVE-2006-1326 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board 2.0.4 allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 2.4% | 2006-03-21 |
| CVE-2013-1471 EXP | Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (I… | Patch early | 4.3 medium | 2.4% | 2013-02-04 |
| CVE-2008-4662 EXP | Directory traversal vulnerability in admin.php in LokiCMS 0.3.4, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arb… | Patch early | 6.8 medium | 2.4% | 2008-10-22 |
| CVE-2006-2682 EXP | PHP remote file inclusion vulnerability in BE_config.php in Back-End CMS 0.7.2.1 and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 6.4 medium | 2.4% | 2006-05-31 |
| CVE-2006-5703 EXP | Cross-site scripting (XSS) vulnerability in tiki-featured_link.php in Tikiwiki 1.9.5 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 2.4% | 2006-11-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt