CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,145 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
208,173 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-5989 EXP | SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber action, a related issue to CVE-2011… | Patch early | 9.8 critical | 2.6% | 2018-02-17 |
| CVE-2017-15981 EXP | Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. | Patch early | 9.8 critical | 2.6% | 2017-10-31 |
| CVE-2017-15982 EXP | Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. | Patch early | 9.8 critical | 2.6% | 2017-10-31 |
| CVE-2018-7707 EXP | Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via an… | Patch early | 6.1 medium | 2.6% | 2018-03-15 |
| CVE-2004-2625 EXP | Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTML via Javascript in an attribu… | Patch early | 5.1 medium | 2.6% | 2004-12-31 |
| CVE-2009-3802 EXP | Amiro.CMS 5.4.0.0 and earlier allows remote attackers to obtain sensitive information via an invalid loginname ("%%%") to _admin/index.php, which reve… | Patch early | 5.0 medium | 2.6% | 2009-10-27 |
| CVE-2009-4585 EXP | UranyumSoft Listing Service stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa… | Patch early | 5.0 medium | 2.6% | 2010-01-06 |
| CVE-2008-5229 EXP | Stack-based buffer overflow in Microsoft Device IO Control in iphlpapi.dll in Microsoft Windows Vista Gold and SP1 allows local users in the Network C… | Patch early | 6.9 medium | 2.6% | 2008-11-25 |
| CVE-2020-12261 EXP | Open-AudIT 3.3.0 allows an XSS attack after login. | Patch early | 5.4 medium | 2.6% | 2020-04-28 |
| CVE-2008-5596 EXP | Ikon AdManager 2.1 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to down… | Patch early | 5.0 medium | 2.6% | 2008-12-16 |
| CVE-2008-5597 EXP | Cold BBS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file… | Patch early | 5.0 medium | 2.6% | 2008-12-16 |
| CVE-2008-5602 EXP | Natterchat 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the databa… | Patch early | 5.0 medium | 2.6% | 2008-12-16 |
| CVE-2008-5773 EXP | Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database… | Patch early | 5.0 medium | 2.6% | 2008-12-30 |
| CVE-2008-5780 EXP | Forest Blog 1.3.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the data… | Patch early | 5.0 medium | 2.6% | 2008-12-30 |
| CVE-2008-5886 EXP | TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa… | Patch early | 5.0 medium | 2.6% | 2009-01-12 |
| CVE-2008-5929 EXP | VP-ASP Shopping Cart 6.50 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download… | Patch early | 5.0 medium | 2.6% | 2009-01-21 |
| CVE-2008-6356 EXP | evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a da… | Patch early | 5.0 medium | 2.6% | 2009-03-02 |
| CVE-2008-6357 EXP | MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to down… | Patch early | 5.0 medium | 2.6% | 2009-03-02 |
| CVE-2008-6374 EXP | CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access control, which allows remote at… | Patch early | 5.0 medium | 2.6% | 2009-03-02 |
| CVE-2008-6387 EXP | Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download t… | Patch early | 5.0 medium | 2.6% | 2009-03-02 |
| CVE-2009-3544 EXP | Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HT… | Patch early | 5.0 medium | 2.6% | 2009-10-05 |
| CVE-2009-4760 EXP | Winn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo… | Patch early | 5.0 medium | 2.6% | 2010-03-29 |
| CVE-2009-4799 EXP | Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database… | Patch early | 5.0 medium | 2.6% | 2010-04-22 |
| CVE-2008-0249 EXP | PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the creden… | Patch early | 5.0 medium | 2.6% | 2008-01-12 |
| CVE-2008-2873 EXP | sHibby sHop 2.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa… | Patch early | 5.0 medium | 2.6% | 2008-06-26 |
| CVE-2008-4115 EXP | TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function. | Patch early | 5.0 medium | 2.6% | 2008-09-16 |
| CVE-2023-31698 EXP | Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trus… | Patch early | 5.4 medium | 2.6% | 2023-05-17 |
| CVE-2006-6328 EXP | Directory traversal vulnerability in index.php for TorrentFlux 2.2 allows remote attackers to create or overwrite arbitrary files via sequences in the… | Patch early | 4.9 medium | 2.6% | 2006-12-06 |
| CVE-2006-6329 EXP | index.php for TorrentFlux 2.2 allows remote attackers to delete files by specifying the target filename in the delfile parameter. | Patch early | 4.9 medium | 2.6% | 2006-12-06 |
| CVE-2005-2412 EXP | PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP code via the Include parameter. | Patch early | 5.0 medium | 2.6% | 2005-08-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt