CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,659 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
170,909 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-5894 EXP | Directory traversal vulnerability in index.php in Mediatheka 4.2 allows remote attackers to include and execute arbitrary local files via a .. (dot do… | Patch early | 6.8 medium | 1.9% | 2009-01-12 |
| CVE-2018-11502 EXP | An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. An… | Patch early | 6.5 medium | 1.9% | 2018-08-24 |
| CVE-2018-19829 EXP | Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is kno… | Patch early | 6.5 medium | 1.9% | 2018-12-18 |
| CVE-2005-4363 EXP | Cross-site scripting (XSS) vulnerability in the search engine in Komodo CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via uns… | Patch early | 5.8 medium | 1.9% | 2005-12-20 |
| CVE-2005-1817 EXP | Invision Power Board (IPB) 1.0 through 1.3 allows remote attackers to edit arbitrary forum posts via a direct request to index.php with modified param… | Patch early | 5.0 medium | 1.9% | 2005-06-01 |
| CVE-2009-3426 EXP | PHP remote file inclusion vulnerability in includes/file_manager/special.php in MaxCMS 3.11.20b allows remote attackers to execute arbitrary PHP code… | Patch early | 6.8 medium | 1.9% | 2009-09-25 |
| CVE-2009-4543 EXP | PHP remote file inclusion vulnerability in index.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to execute arbitrary PH… | Patch early | 6.8 medium | 1.9% | 2010-01-04 |
| CVE-2009-4039 EXP | Cross-site scripting (XSS) vulnerability in Piwigo before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors… | Patch early | 4.3 medium | 1.9% | 2009-11-20 |
| CVE-2005-3522 EXP | Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.9% | 2005-11-06 |
| CVE-2006-1110 EXP | Cross-site scripting (XSS) vulnerability in Aztek Forum 4.0 allows remote attackers to inject arbitrary web script or HTML via the message body in a n… | Patch early | 4.3 medium | 1.9% | 2006-03-09 |
| CVE-2007-5993 EXP | Cross-site scripting (XSS) vulnerability in Visionary Technology in Library Solutions (VTLS) vtls.web.gateway before 48.1.1 allows remote attackers to… | Patch early | 4.3 medium | 1.9% | 2007-11-15 |
| CVE-2008-3399 EXP | PHP remote file inclusion vulnerability in activities/workflow-activities.php in XRMS CRM 1.99.2, when register_globals is enabled, allows remote atta… | Patch early | 6.8 medium | 1.9% | 2008-07-31 |
| CVE-2008-4490 EXP | Directory traversal vulnerability in config.inc.php in phpAbook 0.8.8b and earlier, when magic_quotes_gpc is disabled, allows remote attackers to incl… | Patch early | 5.1 medium | 1.9% | 2008-10-08 |
| CVE-2008-5217 EXP | Directory traversal vulnerability in index.php in txtCMS 0.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attacke… | Patch early | 5.1 medium | 1.9% | 2008-11-24 |
| CVE-2008-5418 EXP | Directory traversal vulnerability in login.php in the PunPortal module before 2.0 for PunBB allows remote attackers to include and execute arbitrary l… | Patch early | 5.1 medium | 1.9% | 2008-12-10 |
| CVE-2008-6551 EXP | Multiple directory traversal vulnerabilities in e-Vision CMS 2.0.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include a… | Patch early | 5.1 medium | 1.9% | 2009-03-30 |
| CVE-2004-1790 EXP | Cross-site scripting (XSS) vulnerability in the web management interface in Edimax AR-6004 ADSL Routers allows remote attackers to inject arbitrary we… | Patch early | 4.3 medium | 1.9% | 2004-12-31 |
| CVE-2004-1954 EXP | Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jco… | Patch early | 4.3 medium | 1.9% | 2004-04-21 |
| CVE-2004-2494 EXP | Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.9% | 2004-12-31 |
| CVE-2004-2514 EXP | Cross-site scripting (XSS) vulnerability in modules/private_messages/index.php in PowerPortal 1.x allows remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 1.9% | 2004-12-31 |
| CVE-2005-0650 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ProjectBB 0.4.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) the pag… | Patch early | 4.3 medium | 1.9% | 2005-05-02 |
| CVE-2005-0802 EXP | Cross-site scripting (XSS) vulnerability in search.asp in ACS Blog 0.8 through 1.1b allows remote attackers to execute arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.9% | 2005-05-02 |
| CVE-2005-1095 EXP | Cross-site scripting (XSS) vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.9% | 2005-05-02 |
| CVE-2005-1886 EXP | Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.9% | 2005-06-09 |
| CVE-2005-3685 EXP | Cross-site scripting (XSS) vulnerability in shopadmin.asp in VP-ASP Shopping Cart 5.50 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.9% | 2005-11-19 |
| CVE-2005-4627 EXP | Cross-site scripting (XSS) vulnerability in index.php in (1) GmailSite 1.0 through 1.0.4 and (2) GFHost 0.1.1 through 0.4.2 allows remote attackers to… | Patch early | 4.3 medium | 1.9% | 2005-12-31 |
| CVE-2006-0251 EXP | Cross-site scripting (XSS) vulnerability in fom.cgi in Faq-O-Matic 2.711 allows remote attackers to inject arbitrary web script or HTML via the (1) _d… | Patch early | 4.3 medium | 1.9% | 2006-01-18 |
| CVE-2006-0880 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 allow remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.9% | 2006-02-24 |
| CVE-2006-0974 EXP | Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.9% | 2006-03-03 |
| CVE-2006-1070 EXP | Cross-site scripting (XSS) vulnerability in dv_gbook.php in DVguestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the f p… | Patch early | 4.3 medium | 1.9% | 2006-03-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt