CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,145 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
208,173 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-1230 EXP | Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (… | Patch early | 4.3 medium | 2.6% | 2006-03-14 |
| CVE-2018-6671 EXP | Application Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows remote authenticat… | Patch early | 4.7 medium | 2.6% | 2018-06-15 |
| CVE-2015-2199 EXP | Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote authenticated users to execut… | Patch early | 6.5 medium | 2.6% | 2015-03-03 |
| CVE-1999-0811 EXP | Buffer overflow in Samba smbd program via a malformed message command. | Patch early | 5.0 medium | 2.6% | 1999-07-21 |
| CVE-2018-1002006 EXP | These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:14: via POST re… | Patch early | 4.8 medium | 2.6% | 2018-12-03 |
| CVE-2018-1002007 EXP | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileg… | Patch early | 4.8 medium | 2.6% | 2018-12-03 |
| CVE-2018-1002008 EXP | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileg… | Patch early | 4.8 medium | 2.6% | 2018-12-03 |
| CVE-2006-6824 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbi… | Patch early | 4.3 medium | 2.6% | 2006-12-29 |
| CVE-2008-3763 EXP | Variable overwrite vulnerability in libsecure.php in Turnkey PHP Live Helper 2.0.1 and earlier, when register_globals is enabled, allows remote attack… | Patch early | 6.8 medium | 2.6% | 2008-08-21 |
| CVE-2007-1192 EXP | Thomas R. Pasawicz HyperBook Guestbook 1.30 stores sensitive information under the web root with insufficient access control, which allows remote atta… | Patch early | 5.0 medium | 2.6% | 2007-03-02 |
| CVE-2007-4937 EXP | CS Guestbook stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin name… | Patch early | 5.0 medium | 2.6% | 2007-09-18 |
| CVE-2012-3351 EXP | Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers to inject arbitrary web scrip… | Patch early | 6.1 medium | 2.6% | 2020-02-20 |
| CVE-2001-1472 EXP | SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain adminis… | Patch early | 4.6 medium | 2.6% | 2001-08-03 |
| CVE-2005-3878 EXP | Directory traversal vulnerability in index.php in PHP Doc System 1.5.1 and earlier allows remote attackers to access or include arbitrary files via a… | Patch early | 6.4 medium | 2.6% | 2005-11-29 |
| CVE-2005-4646 EXP | Unspecified vulnerability in index.php in PEARLINGER Pearl Forums 2.4 allows remote attackers to include arbitrary files via the mode parameter, possi… | Patch early | 5.0 medium | 2.6% | 2005-12-31 |
| CVE-2024-44541 EXP | evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin." | Patch early | 9.8 critical | 2.6% | 2024-09-11 |
| CVE-2005-2557 EXP | Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 2.6% | 2005-09-28 |
| CVE-2006-1258 EXP | Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows remote attackers to inject arbitrary web script or HTML via the set_theme parame… | Patch early | 4.3 medium | 2.6% | 2006-03-19 |
| CVE-2006-6660 EXP | The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote attackers to cause a denial of… | Patch early | 4.3 medium | 2.6% | 2006-12-20 |
| CVE-2008-4484 EXP | main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to "users," as demonstra… | Patch early | 6.8 medium | 2.6% | 2008-10-08 |
| CVE-2007-1726 EXP | Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitrary files via the avatar functi… | Patch early | 6.5 medium | 2.6% | 2007-03-28 |
| CVE-2008-5792 EXP | PHP remote file inclusion vulnerability in show_joined.php in Indiscripts Enthusiast 3.1.4, and possibly earlier, allows remote attackers to execute a… | Patch early | 6.8 medium | 2.6% | 2008-12-31 |
| CVE-2004-1824 EXP | Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.0 allows remote attackers to inject arbitrary web script or HTML via the what p… | Patch early | 4.3 medium | 2.6% | 2004-12-31 |
| CVE-2012-1671 EXP | Directory traversal vulnerability in index.php in phpPaleo 4.8b155 and earlier allows remote attackers to include and execute arbitrary local files vi… | Patch early | 6.8 medium | 2.6% | 2012-10-08 |
| CVE-2012-4036 EXP | Unrestricted file upload vulnerability in admin.php in PBBoard 2.1.4 allows remote administrators to execute arbitrary PHP code by uploading a file wi… | Patch early | 6.8 medium | 2.6% | 2012-08-27 |
| CVE-2010-1890 EXP | The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate ACLs on kernel obje… | Patch early | 4.6 medium | 2.6% | 2010-08-11 |
| CVE-2010-3023 EXP | Multiple cross-site scripting (XSS) vulnerabilities in DiamondList 0.1.6, and possibly earlier, allow remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 2.6% | 2010-08-16 |
| CVE-2006-3076 EXP | PHP remote file inclusion vulnerability in software_upload/public_includes/pub_templates/vphptree/template.php in PhpBlueDragon CMS 2.9.1 allows remot… | Patch early | 6.4 medium | 2.6% | 2006-06-19 |
| CVE-2017-11830 EXP | Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to make an unsig… | Patch early | 5.3 medium | 2.6% | 2017-11-15 |
| CVE-2009-3422 EXP | login.php in Zenas PaoLiber 1.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by… | Patch early | 6.8 medium | 2.6% | 2009-09-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt