CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,534 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
170,877 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-2552 EXP | Multiple directory traversal vulnerabilities in comments.php in Super Simple Blog Script 2.5.4 allow remote attackers to overwrite, include, and execu… | Patch early | 6.8 medium | 2% | 2009-07-20 |
| CVE-2009-0515 EXP | Directory traversal vulnerability in check_lang.php in Yet Another NOCC (YANOCC) 0.1.0 and earlier allows remote attackers to include and execute arbi… | Patch early | 6.8 medium | 2% | 2009-02-11 |
| CVE-2008-6790 EXP | The admin module in MindDezign Photo Gallery 2.2 allows remote attackers to add administrative users and gain privileges via a modified username param… | Patch early | 5.1 medium | 2% | 2009-05-04 |
| CVE-2009-3857 EXP | Buffer overflow in Softonic International SciTE 1.72 allows user-assisted remote attackers to cause a denial of service (application crash) via a Ruby… | Patch early | 4.3 medium | 2% | 2009-11-04 |
| CVE-2003-0404 EXP | Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitr… | Patch early | 4.3 medium | 2% | 2003-06-30 |
| CVE-2004-0617 EXP | Cross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows remote attackers to inject arbitrary script or HTML via the rawURL parameter. | Patch early | 6.8 medium | 2% | 2004-12-06 |
| CVE-2004-0673 EXP | Cross-site scripting (XSS) vulnerability in SCI Photo Chat Server 3.4.9 allows remote attackers to execute arbitrary web script as other users via an… | Patch early | 6.8 medium | 2% | 2004-08-06 |
| CVE-2005-4477 EXP | Cross-site scripting (XSS) vulnerability in papaya CMS 4.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the bab[se… | Patch early | 6.8 medium | 2% | 2005-12-22 |
| CVE-2008-4161 EXP | SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands and conduct session fixation… | Patch early | 6.8 medium | 2% | 2008-09-22 |
| CVE-2010-0712 EXP | Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote authenticate… | Patch early | 6.5 medium | 2% | 2010-02-26 |
| CVE-2010-5284 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Collabtive 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) User… | Patch early | 4.3 medium | 2% | 2012-11-26 |
| CVE-2009-2605 EXP | Multiple SQL injection vulnerabilities in adminquery.php in Traidnt Up 2.0 allow remote attackers to execute arbitrary SQL commands via (1) trupuser a… | Patch early | 6.8 medium | 2% | 2009-07-27 |
| CVE-2008-6730 EXP | Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPLink Pro 0.0.6 and 0.0.7, when magic_quotes_gpc is disabled, allow remote atta… | Patch early | 6.8 medium | 2% | 2009-04-20 |
| CVE-2006-2140 EXP | Multiple cross-site scripting (XSS) vulnerabilities in OrbitHYIP 2.0 and earlier allow remote attackers to inject arbitrary web script via the (1) ref… | Patch early | 5.8 medium | 2% | 2006-05-02 |
| CVE-2006-0194 EXP | Cross-site scripting (XSS) vulnerability in default.asp in FogBugz 4.029, and other versions before 4.0.33, allows remote attackers to inject arbitrar… | Patch early | 4.3 medium | 2% | 2006-01-13 |
| CVE-2011-5197 EXP | Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Harvester Systems 2.3.1 and earlier allow… | Patch early | 6.8 medium | 2% | 2012-09-23 |
| CVE-2005-2855 EXP | Cross-site scripting (XSS) vulnerability in Unclassified NewsBoard 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the descri… | Patch early | 4.3 medium | 2% | 2005-09-08 |
| CVE-2005-3237 EXP | Cross-site scripting (XSS) vulnerability in Cyphor 0.19 allows remote attackers to inject arbitrary web script or HTML via the t_login parameter of fo… | Patch early | 4.3 medium | 2% | 2005-10-14 |
| CVE-2006-0110 EXP | Cross-site scripting (XSS) vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to inject arbitrary web script via the email param… | Patch early | 4.3 medium | 2% | 2006-01-07 |
| CVE-2006-0350 EXP | Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.p… | Patch early | 4.3 medium | 2% | 2006-01-21 |
| CVE-2006-0409 EXP | Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 2% | 2006-01-25 |
| CVE-2006-0676 EXP | Cross-site scripting (XSS) vulnerability in header.php in PHP-Nuke 6.0 to 7.8 allows remote attackers to inject arbitrary web script or HTML via the p… | Patch early | 4.3 medium | 2% | 2006-02-13 |
| CVE-2006-1216 EXP | Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms 1.x allows remote attackers to inject arbitrary web script or HTML via the id parame… | Patch early | 4.3 medium | 2% | 2006-03-14 |
| CVE-2006-1348 EXP | Cross-site scripting (XSS) vulnerability in index.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 2% | 2006-03-22 |
| CVE-2004-1871 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 2% | 2004-03-29 |
| CVE-2007-5175 EXP | PHP remote file inclusion vulnerability lib/base.php in actSite 1.991 Beta allows remote attackers to execute arbitrary PHP code via a URL in the Base… | Patch early | 6.8 medium | 2% | 2007-10-03 |
| CVE-2008-6749 EXP | Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPDirectory 0.0.1, when magic_quotes_gpc is disabled, allow remote attackers to… | Patch early | 6.8 medium | 2% | 2009-04-24 |
| CVE-2009-3218 EXP | SQL injection vulnerability in control/login.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to e… | Patch early | 6.8 medium | 2% | 2009-09-16 |
| CVE-2008-0804 EXP | PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to execute arbitrary PHP code via a U… | Patch early | 6.8 medium | 2% | 2008-02-19 |
| CVE-2008-1038 EXP | PHP remote file inclusion vulnerability in mod/mod.extmanager.php in DBHcms 1.1.4 and earlier allows remote attackers to execute arbitrary PHP code vi… | Patch early | 6.8 medium | 2% | 2008-02-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt