CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,696 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
170,928 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-1071 EXP | Cross-site scripting (XSS) vulnerability in index.php in DVguestbook 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the page… | Patch early | 4.3 medium | 1.9% | 2006-03-08 |
| CVE-2006-1080 EXP | Cross-site scripting (XSS) vulnerability in login.php in Game-Panel 2.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 1.9% | 2006-03-09 |
| CVE-2006-1414 EXP | Multiple cross-site scripting (XSS) vulnerabilities in toast.asp in Toast Forums 1.6 and earlier allow remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.9% | 2006-03-28 |
| CVE-2006-1496 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1)… | Patch early | 4.3 medium | 1.9% | 2006-03-30 |
| CVE-2002-1929 EXP | Cross-site scripting (XSS) vulnerability in pafiledb.php in PHP Arena paFileDB 1.1.3 through 3.0 allows remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 1.9% | 2002-12-31 |
| CVE-2007-6233 EXP | Directory traversal vulnerability in index.php in FTP Admin 0.1.0 allows remote authenticated users to include and execute arbitrary local files via a… | Patch early | 4.9 medium | 1.9% | 2007-12-04 |
| CVE-2005-4374 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Allinta 2.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.9% | 2005-12-20 |
| CVE-2006-5528 EXP | Directory traversal vulnerability in mod.php in SchoolAlumni Portal 2.26 allows remote attackers to include and execute arbitrary local files via a ..… | Patch early | 5.0 medium | 1.9% | 2006-10-26 |
| CVE-2008-0207 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PRO-Search 0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.9% | 2008-01-10 |
| CVE-2010-1712 EXP | Multiple cross-site scripting (XSS) vulnerabilities in base/Comments.php in Webmobo WB News 2.3.3 allow remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 1.9% | 2010-05-04 |
| CVE-2008-7156 EXP | EkinBoard 1.1.0 and earlier, when register_globals is enabled, allows remote attackers to bypass authorization and gain administrator privileges by se… | Patch early | 6.8 medium | 1.9% | 2009-09-02 |
| CVE-2002-1802 EXP | Cross-site scripting (XSS) vulnerability in Xoops 1.0 RC3 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag… | Patch early | 4.3 medium | 1.9% | 2002-12-31 |
| CVE-2008-6025 EXP | Directory traversal vulnerability in scr/form.php in openElec 3.01 and earlier allows remote attackers to include and execute arbitrary local files vi… | Patch early | 6.8 medium | 1.9% | 2009-02-03 |
| CVE-2008-4075 EXP | Directory traversal vulnerability in index.php in D-iscussion Board 3.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the top… | Patch early | 6.8 medium | 1.9% | 2008-09-15 |
| CVE-2008-4780 EXP | Directory traversal vulnerability in admin/centre.php in MyForum 1.3, when register_globals is enabled, allows remote attackers to include and execute… | Patch early | 6.8 medium | 1.9% | 2008-10-29 |
| CVE-2008-2415 EXP | Directory traversal vulnerability in template/purpletech/base_include.php in DigitalHive (aka hive) 2.0 RC2 allows remote attackers to include and exe… | Patch early | 6.8 medium | 1.9% | 2008-05-22 |
| CVE-2008-3312 EXP | Directory traversal vulnerability in lemon_includes/FCKeditor/editor/filemanager/browser/browser.php in Lemon CMS 1.10 allows remote attackers to incl… | Patch early | 6.8 medium | 1.9% | 2008-07-25 |
| CVE-2008-6522 EXP | Multiple directory traversal vulnerabilities in the RenderFile function in ContentRender.class.php in Terracotta (aka OpenTerracotta) 0.6.1, and possi… | Patch early | 6.8 medium | 1.9% | 2009-03-25 |
| CVE-2010-0953 EXP | Directory traversal vulnerability in mod.php in phpCOIN 1.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter. | Patch early | 6.8 medium | 1.9% | 2010-03-10 |
| CVE-2012-4259 EXP | Cross-site scripting (XSS) vulnerability in the contacts in (1) XPhone UC Web and the (2) web frontend for XPhone Virtual Directory in C4B XPhone Unif… | Patch early | 4.3 medium | 1.9% | 2012-08-13 |
| CVE-2006-6197 EXP | Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTM… | Patch early | 6.8 medium | 1.9% | 2006-12-01 |
| CVE-2006-6211 EXP | Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) msg pa… | Patch early | 6.8 medium | 1.9% | 2006-12-01 |
| CVE-2006-6389 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via the (1) Taaa para… | Patch early | 6.8 medium | 1.9% | 2006-12-08 |
| CVE-2006-6517 EXP | Multiple cross-site scripting (XSS) vulnerabilities in KDPics 1.16 and earlier allow remote attackers to inject arbitrary web script or HTML via the (… | Patch early | 6.8 medium | 1.9% | 2006-12-14 |
| CVE-2018-9034 EXP | Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote attackers to inject arbitrary… | Patch early | 5.4 medium | 1.9% | 2018-04-04 |
| CVE-2008-1649 EXP | Cross-site scripting (XSS) vulnerability in staticpages/easypublish/index.php in EasyNews 4.0 allows remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 1.9% | 2008-04-02 |
| CVE-2007-2098 EXP | Multiple cross-site scripting (XSS) vulnerabilities in showpic.php in Wabbit PHP Gallery 0.9 allow remote attackers to inject arbitrary web script or… | Patch early | 6.8 medium | 1.9% | 2007-04-18 |
| CVE-2008-3682 EXP | SQL injection vulnerability in dpage.php in YPN PHP Realty allows remote attackers to execute arbitrary SQL commands via the docID parameter. | Patch early | 6.8 medium | 1.9% | 2008-08-14 |
| CVE-2020-15600 EXP | An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password. | Patch early | 6.5 medium | 1.9% | 2020-07-07 |
| CVE-2012-4926 EXP | approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via th… | Patch early | 6.4 medium | 1.9% | 2012-09-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt