CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,999 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
170,624 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-1424 EXP | Cross-site request forgery (CSRF) vulnerability in Gecko CMS 2.2 and 2.3 allows remote attackers to hijack the authentication of administrators for re… | Patch early | 6.8 medium | 2.3% | 2015-01-29 |
| CVE-2008-6473 EXP | _blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary users via a modified "a" parame… | Patch early | 6.4 medium | 2.3% | 2009-03-16 |
| CVE-2021-24444 EXP | The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allow… | Patch early | 4.8 medium | 2.3% | 2021-08-02 |
| CVE-2009-4739 EXP | PHP remote file inclusion vulnerability in index.php in SkaDate Dating allows remote attackers to execute arbitrary PHP code via a URL in the language… | Patch early | 6.8 medium | 2.3% | 2010-03-26 |
| CVE-2006-2681 EXP | PHP remote file inclusion vulnerability in SocketMail Lite and Pro 2.2.6 and earlier, when register_globals and magic_quotes are enabled, allows remot… | Patch early | 6.8 medium | 2.3% | 2006-05-31 |
| CVE-2007-2248 EXP | Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Phorum before 5.1.22 allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 2.3% | 2007-04-25 |
| CVE-2006-3295 EXP | Cross-site scripting (XSS) vulnerability in header.php in Open Guestbook 0.5 allows remote attackers to inject arbitrary web script or HTML via the ti… | Patch early | 4.3 medium | 2.3% | 2006-06-29 |
| CVE-2006-0706 EXP | Cross-site scripting vulnerability in eintrag.php in Gästebuch (Gastebuch) before 1.3.3 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 2.3% | 2006-02-15 |
| CVE-2017-2489 EXP | An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graphics Driver" component. It allo… | Patch early | 5.5 medium | 2.3% | 2017-04-02 |
| CVE-2005-3064 EXP | MultiTheftAuto 0.5 patch 1 and earlier does not properly verify client privileges when running command 40, which allows remote attackers to change or… | Patch early | 5.0 medium | 2.3% | 2005-09-27 |
| CVE-2007-4318 EXP | Cross-site scripting (XSS) vulnerability in Forms/General_1 in the management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allo… | Patch early | 4.3 medium | 2.3% | 2007-08-13 |
| CVE-2007-6173 EXP | Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Enterprise Portal 4.3.1 allows remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 2.3% | 2007-11-30 |
| CVE-2006-1324 EXP | Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrar… | Patch early | 6.8 medium | 2.3% | 2006-03-21 |
| CVE-2012-6493 EXP | Cross-site request forgery (CSRF) vulnerability in Rapid7 Nexpose Security Console before 5.5.4 allows remote attackers to hijack the authentication o… | Patch early | 6.8 medium | 2.3% | 2014-02-04 |
| CVE-2014-5180 EXP | SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 for WordPress allows remote auth… | Patch early | 6.5 medium | 2.3% | 2014-08-06 |
| CVE-2008-4612 EXP | Cross-site scripting (XSS) vulnerability in PortalApp 4.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter to… | Patch early | 4.3 medium | 2.3% | 2008-10-20 |
| CVE-2014-4718 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Lunar CMS before 3.3-3 allow remote attackers to hijack the authentication of administra… | Patch early | 6.8 medium | 2.3% | 2014-07-03 |
| CVE-2011-4452 EXP | Cross-site request forgery (CSRF) vulnerability in the AdminUsers component in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to hijack the authent… | Patch early | 6.8 medium | 2.3% | 2012-09-05 |
| CVE-2008-4319 EXP | fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary… | Patch early | 6.4 medium | 2.3% | 2008-09-29 |
| CVE-2023-3320 EXP | The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing… | Patch early | 6.1 medium | 2.3% | 2023-06-20 |
| CVE-2006-0185 EXP | Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web script or… | Patch early | 5.0 medium | 2.3% | 2006-01-12 |
| CVE-2004-2451 EXP | Roger Wilco 1.4.1.6 and earlier, or Roger Wilco Base Station 0.30a or earlier, allows remote attackers to send audio to arbitrary channels, aka the "V… | Patch early | 5.0 medium | 2.3% | 2004-12-31 |
| CVE-2013-3320 EXP | Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 6.1 medium | 2.3% | 2020-01-29 |
| CVE-2007-5092 EXP | Directory traversal vulnerability in index.php in the Dance Music module for phpNuke, when register_globals is enabled, allows remote attackers to inc… | Patch early | 6.8 medium | 2.3% | 2007-09-26 |
| CVE-2008-1170 EXP | Multiple PHP remote file inclusion vulnerabilities in KCWiki 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the page parameter… | Patch early | 6.8 medium | 2.3% | 2008-03-05 |
| CVE-2017-14126 EXP | The Participants Database plugin before 1.7.5.10 for WordPress has XSS. | Patch early | 6.1 medium | 2.3% | 2017-09-04 |
| CVE-2008-3926 EXP | Multiple directory traversal vulnerabilities in Content Management Made Easy (CMME) 1.12 allow remote attackers to (1) read arbitrary files via a .. (… | Patch early | 5.8 medium | 2.3% | 2008-09-04 |
| CVE-2019-6588 EXP | In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" par… | Patch early | 4.7 medium | 2.3% | 2019-06-03 |
| CVE-2007-5697 EXP | Multiple PHP remote file inclusion vulnerabilities in PHP Image 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the xarg paramet… | Patch early | 6.8 medium | 2.3% | 2007-10-29 |
| CVE-2007-2319 EXP | PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to execute arbitrary PHP code via… | Patch early | 6.8 medium | 2.3% | 2007-04-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt