CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,707 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
170,932 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-3660 EXP | PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remote attacke… | Patch early | 6.8 medium | 1.9% | 2009-10-11 |
| CVE-2017-14956 EXP | AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php"… | Patch early | 5.7 medium | 1.9% | 2017-10-18 |
| CVE-2013-6166 EXP | Google Chrome before 29 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote… | Patch early | 6.8 medium | 1.9% | 2014-02-15 |
| CVE-2010-0760 EXP | Multiple directory traversal vulnerabilities in the Core Design Scriptegrator plugin 1.4.1 for Joomla! allow remote attackers to include and execute a… | Patch early | 6.8 medium | 1.9% | 2010-02-27 |
| CVE-2010-0958 EXP | Directory traversal vulnerability in modules/hayoo/index.php in Tribisur 2.1, 2.0, and earlier, when magic_quotes_gpc is disabled, allows remote attac… | Patch early | 6.8 medium | 1.9% | 2010-03-10 |
| CVE-2008-5962 EXP | Directory traversal vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remote attackers to include a… | Patch early | 6.8 medium | 1.9% | 2009-01-23 |
| CVE-2008-6177 EXP | Multiple directory traversal vulnerabilities in LightBlog 9.8, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitr… | Patch early | 6.8 medium | 1.9% | 2009-02-19 |
| CVE-2008-6265 EXP | Directory traversal vulnerability in portfolio/css.php in Cyberfolio 7.12.2 and earlier allows remote attackers to include and execute arbitrary local… | Patch early | 6.8 medium | 1.9% | 2009-02-24 |
| CVE-2008-6271 EXP | Directory traversal vulnerability in index.php in TBmnetCMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files vi… | Patch early | 6.8 medium | 1.9% | 2009-02-25 |
| CVE-2008-6842 EXP | Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to include and execute arbitrary l… | Patch early | 6.8 medium | 1.9% | 2009-07-02 |
| CVE-2008-7254 EXP | Directory traversal vulnerability in includes/template-loader.php in Irmin CMS (formerly Pepsi CMS) 0.5 and 0.6 BETA2, when register_globals is enable… | Patch early | 6.8 medium | 1.9% | 2010-04-07 |
| CVE-2010-1060 EXP | Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allows remote attackers to… | Patch early | 6.8 medium | 1.9% | 2010-03-23 |
| CVE-2010-1062 EXP | Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allo… | Patch early | 6.8 medium | 1.9% | 2010-03-23 |
| CVE-2010-1077 EXP | Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers to include and execute arbitra… | Patch early | 6.8 medium | 1.9% | 2010-03-23 |
| CVE-2008-2813 EXP | Directory traversal vulnerability in index.php in WallCity-Server Shoutcast Admin Panel 2.0, when magic_quotes_gpc is disabled, allows remote attacker… | Patch early | 6.8 medium | 1.9% | 2008-06-23 |
| CVE-2008-2913 EXP | Directory traversal vulnerability in func.php in Devalcms 1.4a, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbi… | Patch early | 6.8 medium | 1.9% | 2008-06-30 |
| CVE-2008-4483 EXP | Directory traversal vulnerability in index.php in Crux Gallery 1.32 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include… | Patch early | 6.8 medium | 1.9% | 2008-10-08 |
| CVE-2008-4712 EXP | Directory traversal vulnerability in pages/showblog.php in LnBlog 0.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to inc… | Patch early | 6.8 medium | 1.9% | 2008-10-23 |
| CVE-2008-6199 EXP | 2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via a direct request to backup.ph… | Patch early | 4.0 medium | 1.9% | 2009-02-20 |
| CVE-2009-5095 EXP | PHP remote file inclusion vulnerability in index_inc.php in ea gBook 0.1 and 0.1.4 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 6.8 medium | 1.9% | 2011-09-12 |
| CVE-2008-2227 EXP | Multiple directory traversal vulnerabilities in PHP-Fusion Forum Rank System 6 allow remote attackers to include and execute arbitrary local files via… | Patch early | 6.8 medium | 1.9% | 2008-05-14 |
| CVE-2005-2065 EXP | HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web content and poison web caches via C… | Patch early | 5.0 medium | 1.9% | 2005-06-29 |
| CVE-2007-0950 EXP | Cross-site scripting (XSS) vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to inject arbitrary web script or HTM… | Patch early | 6.8 medium | 1.9% | 2007-02-15 |
| CVE-2020-24963 EXP | An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4. | Patch early | 5.4 medium | 1.9% | 2020-09-04 |
| CVE-2012-6517 EXP | Multiple cross-site scripting (XSS) vulnerabilities in DiY-CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) question… | Patch early | 4.3 medium | 1.9% | 2013-01-24 |
| CVE-2006-6380 EXP | Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary web script or HTML via the keyw… | Patch early | 6.8 medium | 1.9% | 2006-12-07 |
| CVE-2012-6528 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_IN… | Patch early | 4.3 medium | 1.9% | 2013-01-31 |
| CVE-2009-0701 EXP | Multiple PHP remote file inclusion vulnerabilities in index.php in Cybershade CMS 0.2b, when register_globals is enabled, allow remote attackers to ex… | Patch early | 6.8 medium | 1.9% | 2009-02-23 |
| CVE-2006-6708 EXP | Cross-site scripting (XSS) vulnerability in listings.asp in MGinternet Property Site Manager allows remote attackers to inject arbitrary web script or… | Patch early | 6.8 medium | 1.9% | 2006-12-23 |
| CVE-2008-6735 EXP | Directory traversal vulnerability in qc/index.php in ThaiQuickCart 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the sLangua… | Patch early | 5.8 medium | 1.9% | 2009-04-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt