CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,729 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
170,949 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-0501 EXP | Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pa… | Patch early | 5.8 medium | 1.9% | 2008-01-30 |
| CVE-2004-2363 EXP | Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allows remote attackers to conduct… | Patch early | 4.3 medium | 1.8% | 2004-12-31 |
| CVE-2007-4862 EXP | Cross-site scripting (XSS) vulnerability in admin/menu.php in SAXON 5.4 allows remote attackers to inject arbitrary web script or HTML via the config[… | Patch early | 4.3 medium | 1.8% | 2007-10-30 |
| CVE-2005-0410 EXP | SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV file. | Patch early | 5.0 medium | 1.8% | 2005-02-14 |
| CVE-2006-6777 EXP | Cross-site scripting (XSS) vulnerability in index.cfm in Future Internet allows remote attackers to inject arbitrary web script or HTML via the catego… | Patch early | 6.8 medium | 1.8% | 2006-12-28 |
| CVE-2008-0478 EXP | Directory traversal vulnerability in index.php in SetCMS 3.6.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot)… | Patch early | 6.8 medium | 1.8% | 2008-01-29 |
| CVE-2008-1553 EXP | Directory traversal vulnerability in mod.php in TopperMod 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot)… | Patch early | 6.8 medium | 1.8% | 2008-03-31 |
| CVE-2008-1962 EXP | Multiple directory traversal vulnerabilities in Aterr 0.9.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in… | Patch early | 6.8 medium | 1.8% | 2008-04-25 |
| CVE-2008-2217 EXP | Directory traversal vulnerability in cm/graphie.php in Content Management System 0.6.1 for Phprojekt allows remote attackers to include and execute ar… | Patch early | 6.8 medium | 1.8% | 2008-05-14 |
| CVE-2008-2976 EXP | Multiple directory traversal vulnerabilities in TinX/cms 1.1, when register_globals is enabled, allow remote attackers to include and execute arbitrar… | Patch early | 6.8 medium | 1.8% | 2008-07-02 |
| CVE-2008-2978 EXP | Directory traversal vulnerability in phpi/rss.php in Ourvideo CMS 9.5, when register_globals is enabled, allows remote attackers to include and execut… | Patch early | 6.8 medium | 1.8% | 2008-07-02 |
| CVE-2008-2985 EXP | Directory traversal vulnerability in load_language.php in CMReams CMS 1.3.1.1 Beta 2, when register_globals is enabled, allows remote attackers to inc… | Patch early | 6.8 medium | 1.8% | 2008-07-02 |
| CVE-2008-4739 EXP | Directory traversal vulnerability in index.php in PlugSpace 0.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arb… | Patch early | 6.8 medium | 1.8% | 2008-10-24 |
| CVE-2008-5204 EXP | Multiple directory traversal vulnerabilities in PowerAward 1.1.0 RC1, when register_globals is enabled, allow remote attackers to include and execute… | Patch early | 6.8 medium | 1.8% | 2008-11-21 |
| CVE-2008-5990 EXP | Directory traversal vulnerability in connect/init.inc in emergecolab 1.0 allows remote attackers to include and execute arbitrary local files via a ..… | Patch early | 6.8 medium | 1.8% | 2009-01-28 |
| CVE-2008-6361 EXP | Directory traversal vulnerability in index.php in InSun Feed CMS 1.7.3 19Beta allows remote attackers to include and execute arbitrary local files via… | Patch early | 6.8 medium | 1.8% | 2009-03-02 |
| CVE-2009-4458 EXP | Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow remote attackers to inject arbit… | Patch early | 4.3 medium | 1.8% | 2009-12-30 |
| CVE-2009-4547 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ViArt CMS 3.x allow remote attackers to inject arbitrary web script or HTML via the (1) categor… | Patch early | 4.3 medium | 1.8% | 2010-01-04 |
| CVE-2006-1925 EXP | Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify f… | Patch early | 4.3 medium | 1.8% | 2006-04-20 |
| CVE-2018-10752 EXP | The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action. | Patch early | 4.8 medium | 1.8% | 2018-05-05 |
| CVE-2018-10321 EXP | Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings. | Patch early | 4.8 medium | 1.8% | 2018-04-24 |
| CVE-2005-1803 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 1.8% | 2005-05-29 |
| CVE-2006-3052 EXP | Cross-site scripting (XSS) vulnerability in Event Registration allows remote attackers to inject arbitrary web script or HTML via the (1) event_id par… | Patch early | 6.8 medium | 1.8% | 2006-06-16 |
| CVE-2008-1068 EXP | Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a U… | Patch early | 6.8 medium | 1.8% | 2008-02-28 |
| CVE-2008-1123 EXP | Multiple PHP remote file inclusion vulnerabilities in SiteBuilder Elite 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the Carp… | Patch early | 6.8 medium | 1.8% | 2008-03-03 |
| CVE-2006-6087 EXP | Cross-site scripting (XSS) vulnerability in weblog.php in my little weblog allows remote attackers to inject arbitrary web script or HTML via the acti… | Patch early | 4.3 medium | 1.8% | 2006-11-24 |
| CVE-2006-6746 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script or HTML via the id_news param… | Patch early | 4.3 medium | 1.8% | 2006-12-27 |
| CVE-2006-1825 EXP | Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 6.8 medium | 1.8% | 2006-04-18 |
| CVE-2004-0032 EXP | Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script via the firs… | Patch early | 6.8 medium | 1.8% | 2004-01-20 |
| CVE-2007-0836 EXP | admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to include arbitrary local and possibly remote f… | Patch early | 4.0 medium | 1.8% | 2007-02-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt