CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,108 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
170,687 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-2337 EXP | SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when magic_quotes_gpc is disabled, all… | Patch early | 6.8 medium | 2.2% | 2009-07-07 |
| CVE-2005-3152 EXP | Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the redir para… | Patch early | 4.3 medium | 2.2% | 2005-10-05 |
| CVE-2004-1823 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 allows remote attackers to inject arbitrary web s… | Patch early | 4.3 medium | 2.2% | 2004-12-31 |
| CVE-2004-2509 EXP | Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads 6.2.3 and 6.5 allow remote at… | Patch early | 4.3 medium | 2.2% | 2004-12-31 |
| CVE-2008-2028 EXP | miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via a direct request to the glang… | Patch early | 4.3 medium | 2.2% | 2008-04-30 |
| CVE-2007-3009 EXP | Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration d… | Patch early | 4.3 medium | 2.2% | 2007-06-04 |
| CVE-2013-3299 EXP | RealNetworks RealPlayer 16.0.2.32 and earlier allows remote attackers to cause a denial of service (resource consumption or application crash) via an… | Patch early | 4.3 medium | 2.2% | 2013-07-06 |
| CVE-2006-4754 EXP | Cross-site scripting (XSS) vulnerability in index.php in PHProg before 1.1 allows remote attackers to inject arbitrary web script or HTML via the albu… | Patch early | 6.8 medium | 2.2% | 2006-09-13 |
| CVE-2008-6084 EXP | Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code… | Patch early | 6.8 medium | 2.2% | 2009-02-06 |
| CVE-2022-47870 EXP | A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows remote attackers to inject arbi… | Patch early | 6.1 medium | 2.2% | 2023-04-04 |
| CVE-2008-5951 EXP | ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… | Patch early | 5.0 medium | 2.2% | 2009-01-23 |
| CVE-2008-6057 EXP | Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, which allows remote attackers to o… | Patch early | 5.0 medium | 2.2% | 2009-02-04 |
| CVE-2008-6147 EXP | ForumApp 3.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database vi… | Patch early | 5.0 medium | 2.2% | 2009-02-16 |
| CVE-2008-6321 EXP | CF Shopkart 5.2.2 stores cfshopkart52.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive infor… | Patch early | 5.0 medium | 2.2% | 2009-02-27 |
| CVE-2008-6388 EXP | Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downl… | Patch early | 5.0 medium | 2.2% | 2009-03-02 |
| CVE-2008-6493 EXP | Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, which allows remote attackers to… | Patch early | 5.0 medium | 2.2% | 2009-03-20 |
| CVE-2008-6494 EXP | ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a data… | Patch early | 5.0 medium | 2.2% | 2009-03-20 |
| CVE-2008-6580 EXP | The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access control, which allows remote attac… | Patch early | 5.0 medium | 2.2% | 2009-04-02 |
| CVE-2008-7063 EXP | Ocean12 FAQ Manager Pro stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a databas… | Patch early | 5.0 medium | 2.2% | 2009-08-25 |
| CVE-2008-1680 EXP | PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain configuration information via a direct request to maintenance/index.php, which reveals set… | Patch early | 5.0 medium | 2.2% | 2008-04-04 |
| CVE-2009-2602 EXP | R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to… | Patch early | 5.0 medium | 2.2% | 2009-07-27 |
| CVE-2009-2606 EXP | ASP Football Pool 2.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… | Patch early | 5.0 medium | 2.2% | 2009-07-27 |
| CVE-2009-3199 EXP | Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download… | Patch early | 5.0 medium | 2.2% | 2009-09-15 |
| CVE-2009-4545 EXP | Logoshows BBS 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a databa… | Patch early | 5.0 medium | 2.2% | 2010-01-04 |
| CVE-2007-0302 EXP | Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Sess… | Patch early | 6.8 medium | 2.2% | 2007-01-18 |
| CVE-2009-1595 EXP | The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passw… | Patch early | 4.0 medium | 2.2% | 2009-05-11 |
| CVE-2010-1999 EXP | Directory traversal vulnerability in scr/soustab.php in OpenMairie Opencatalogue 1.024, when register_globals is enabled, allows remote attackers to i… | Patch early | 6.8 medium | 2.2% | 2010-05-20 |
| CVE-2009-0611 EXP | Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterprise Server 1.x allow remote a… | Patch early | 4.3 medium | 2.2% | 2009-02-17 |
| CVE-2012-3835 EXP | Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow remote attackers to in… | Patch early | 4.3 medium | 2.2% | 2012-07-03 |
| CVE-2012-1261 EXP | Cross-site scripting (XSS) vulnerability in cgi-bin/scrut_fa_exclusions.cgi in Plixer International Scrutinizer NetFlow and sFlow Analyzer 8.6.2.16204… | Patch early | 6.1 medium | 2.2% | 2020-01-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt