CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,557 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
170,889 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-3141 EXP | PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 allows remote attackers to execute arbitrary PHP code via a URL in th… | Patch early | 6.8 medium | 2% | 2007-06-11 |
| CVE-2007-0605 EXP | Cross-site scripting (XSS) vulnerability in picture.php in Advanced Guestbook 2.4.2 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 2% | 2007-05-09 |
| CVE-2007-0694 EXP | Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1 allows remote attackers to inject arbitrary web script or HTML via the copyright… | Patch early | 4.3 medium | 2% | 2007-05-30 |
| CVE-2009-5090 EXP | SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbit… | Patch early | 6.8 medium | 2% | 2011-09-12 |
| CVE-2010-1737 EXP | PHP remote file inclusion vulnerability in core/includes/gfw_smarty.php in Gallo 0.1.0, when magic_quotes_gpc is disabled, allows remote attackers to… | Patch early | 6.8 medium | 2% | 2010-05-06 |
| CVE-2008-3308 EXP | PHP remote file inclusion vulnerability in cuenta/cuerpo.php in C. Desseno YouTube Blog (ytb) 0.1, when register_globals is enabled, allows remote att… | Patch early | 6.8 medium | 2% | 2008-07-25 |
| CVE-2008-1785 EXP | delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary users via a modified s parameter. | Patch early | 5.5 medium | 2% | 2008-04-15 |
| CVE-2009-0597 EXP | SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disabled, allows remote attackers… | Patch early | 6.8 medium | 2% | 2009-02-16 |
| CVE-2014-10014 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attackers to hijack the authenticatio… | Patch early | 6.8 medium | 2% | 2015-01-13 |
| CVE-2001-1142 EXP | ArGoSoft FTP Server 1.2.2.2 uses weak encryption for user passwords, which allows an attacker with access to the password file to gain privileges. | Patch early | 5.0 medium | 2% | 2001-07-12 |
| CVE-2011-5161 EXP | Unrestricted file upload vulnerability in the patient photograph functionality in OpenEMR 4 allows remote attackers to execute arbitrary PHP code by u… | Patch early | 6.8 medium | 2% | 2012-09-09 |
| CVE-2007-1872 EXP | Cross-site scripting (XSS) vulnerability in toendaCMS 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the searchword paramete… | Patch early | 4.3 medium | 2% | 2007-04-13 |
| CVE-2005-2453 EXP | Cross-site scripting (XSS) vulnerability in NetworkActiv Web Server 1.0, 2.0.0.6, 3.0.1.1, and 3.5.13, and possibly other versions, allows remote atta… | Patch early | 4.3 medium | 2% | 2005-08-04 |
| CVE-2006-0341 EXP | Cross-site scripting (XSS) vulnerability in WCONSOLE.DLL in Rockliffe MailSite 5.x and 6.1.22 and earlier allows remote attackers to inject arbitrary… | Patch early | 4.3 medium | 2% | 2006-01-06 |
| CVE-2006-1417 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Caloris Planitia Online Quiz System (aka Web Quiz pro), possibly 1.0, allow remote attackers to… | Patch early | 4.3 medium | 2% | 2006-03-28 |
| CVE-2009-0301 EXP | Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.6.9 allow remote attackers to… | Patch early | 6.8 medium | 2% | 2009-01-27 |
| CVE-2009-1659 EXP | Unrestricted file upload vulnerability in admin/uploadimage.php in eLitius 1.0 allows remote attackers to bypass intended access restrictions and uplo… | Patch early | 6.8 medium | 2% | 2009-05-18 |
| CVE-2010-1528 EXP | PHP remote file inclusion vulnerability in include/template.php in Uiga Proxy, when register_globals is enabled, allows remote attackers to execute ar… | Patch early | 6.8 medium | 2% | 2010-04-26 |
| CVE-2005-4489 EXP | Cross-site scripting (XSS) vulnerability in Scoop 1.1 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) type… | Patch early | 4.3 medium | 2% | 2005-12-22 |
| CVE-2006-0509 EXP | Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 2% | 2006-02-01 |
| CVE-2005-0606 EXP | Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows remote attackers… | Patch early | 4.3 medium | 2% | 2005-05-02 |
| CVE-2008-0497 EXP | Cross-site scripting (XSS) vulnerability in action.php in Nucleus CMS 3.31 allows remote attackers to inject arbitrary web script or HTML via the PATH… | Patch early | 4.3 medium | 2% | 2008-01-30 |
| CVE-2007-5720 EXP | Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and execute arbitrary PHP code via u… | Patch early | 6.8 medium | 2% | 2007-10-30 |
| CVE-2002-2298 EXP | PHP remote file inclusion vulnerability in config.php in Thatware 0.3 through 0.5.3 allows remote attackers to execute arbitrary PHP code via the root… | Patch early | 6.8 medium | 2% | 2002-12-31 |
| CVE-2009-0570 EXP | Directory traversal vulnerability in send.php in Ninja Designs Mailist 3.0, when register_globals is enabled and magic_quotes_gpc is disabled, allows… | Patch early | 5.1 medium | 2% | 2009-02-13 |
| CVE-2008-6650 EXP | del.php in miniBloggie 1.0 allows remote attackers to delete arbitrary posts via a direct request with a modified post_id parameter, a different vulne… | Patch early | 5.0 medium | 2% | 2009-04-07 |
| CVE-2007-6560 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1)… | Patch early | 4.3 medium | 2% | 2007-12-28 |
| CVE-2014-10034 EXP | Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execute arbitrary SQL commands via t… | Patch early | 6.5 medium | 2% | 2015-01-13 |
| CVE-2019-7440 EXP | JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcma… | Patch early | 6.5 medium | 2% | 2019-03-21 |
| CVE-2010-1887 EXP | The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server… | Patch early | 4.4 medium | 2% | 2010-08-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt