CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,373 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
208,326 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-1233 EXP | Cross-site scripting (XSS) vulnerability in index.php in PHP Labs proFile allows remote attackers to inject arbitrary web script or HTML via the (1) d… | Patch early | 4.3 medium | 2.2% | 2005-04-20 |
| CVE-2008-7046 EXP | AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/include/new… | Patch early | 6.4 medium | 2.2% | 2009-08-24 |
| CVE-2006-3611 EXP | Directory traversal vulnerability in pm.php in Phorum 5 allows remote authenticated users to include and execute arbitrary local files via directory t… | Patch early | 5.5 medium | 2.2% | 2006-07-18 |
| CVE-2008-6742 EXP | Foxy P2P software allows remote attackers to cause a denial of service (memory consumption) via a foxy URI with a download action and a large fs value… | Patch early | 4.3 medium | 2.2% | 2009-04-21 |
| CVE-2008-5125 EXP | admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin. | Patch early | 6.8 medium | 2.2% | 2008-11-18 |
| CVE-2006-0217 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary web script or HTML via the (1)… | Patch early | 4.3 medium | 2.2% | 2006-01-16 |
| CVE-2004-1845 EXP | Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1)… | Patch early | 4.3 medium | 2.2% | 2004-12-31 |
| CVE-2006-4654 EXP | Format string vulnerability in Easy Address Book Web Server 1.2 allows remote attackers to cause a denial of service (crash) or "compromise the server… | Patch early | 5.1 medium | 2.2% | 2006-09-09 |
| CVE-2006-5643 EXP | Cross-site scripting (XSS) vulnerability in search_de.html in foresite CMS allows remote attackers to inject arbitrary web script or HTML via the quer… | Patch early | 6.8 medium | 2.2% | 2006-11-01 |
| CVE-2007-1996 EXP | PHP remote file inclusion vulnerability in codebreak.php in CodeBreak, probably 1.1.2 and earlier, allows remote attackers to execute arbitrary PHP co… | Patch early | 6.8 medium | 2.2% | 2007-04-12 |
| CVE-2020-20139 EXP | Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17. | Patch early | 6.1 medium | 2.2% | 2020-12-17 |
| CVE-2020-20140 EXP | Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17. | Patch early | 6.1 medium | 2.2% | 2020-12-17 |
| CVE-2020-20141 EXP | Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17. | Patch early | 6.1 medium | 2.2% | 2020-12-17 |
| CVE-2004-0344 EXP | Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot… | Patch early | 6.4 medium | 2.2% | 2004-11-23 |
| CVE-2008-2018 EXP | The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings delimited by '{' and '}' characte… | Patch early | 4.0 medium | 2.2% | 2008-04-30 |
| CVE-2008-0289 EXP | PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remote attackers to execute arbitr… | Patch early | 6.8 medium | 2.2% | 2008-01-16 |
| CVE-2006-6925 EXP | Multiple cross-site scripting (XSS) vulnerabilities in bitweaver 1.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (… | Patch early | 6.8 medium | 2.2% | 2007-01-13 |
| CVE-2009-0735 EXP | Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled and magic_quotes_gpc is disabled… | Patch early | 5.1 medium | 2.2% | 2009-02-25 |
| CVE-2010-0754 EXP | Cross-site scripting (XSS) vulnerability in index.php/Special/Main/Templates in WikyBlog 1.7.2 and 1.7.3 rc2 allows remote attackers to inject arbitra… | Patch early | 4.3 medium | 2.2% | 2010-02-27 |
| CVE-2010-4874 EXP | Multiple cross-site scripting (XSS) vulnerabilities in users.php in NinkoBB 1.3 RC5 allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 2.2% | 2011-10-07 |
| CVE-2007-6005 EXP | Unspecified vulnerability in the GpcContainer.GpcContainer.1 ActiveX control in WebEx allows remote attackers to cause a denial of service (memory acc… | Patch early | 4.3 medium | 2.2% | 2007-11-15 |
| CVE-2004-2670 EXP | Multiple cross-site scripting (XSS) vulnerabilities in mod.php in eNdonesia 8.3 allow remote attackers to inject arbitrary web script or HTML via (1)… | Patch early | 6.8 medium | 2.2% | 2004-12-31 |
| CVE-2005-3208 EXP | Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execute arbitrary SQL code via (a) t… | Patch early | 6.8 medium | 2.2% | 2005-10-14 |
| CVE-2008-7213 EXP | Cross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php in MOStlyCE before 2.4… | Patch early | 4.3 medium | 2.2% | 2009-09-11 |
| CVE-2018-9238 EXP | proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter. | Patch early | 6.1 medium | 2.2% | 2018-04-04 |
| CVE-2018-9857 EXP | PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" screen). | Patch early | 6.1 medium | 2.2% | 2018-04-09 |
| CVE-2006-4273 EXP | Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML by upload… | Patch early | 6.8 medium | 2.2% | 2006-08-21 |
| CVE-2015-8398 EXP | Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 6.1 medium | 2.2% | 2016-04-11 |
| CVE-2008-5621 EXP | Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unautho… | Patch early | 6.0 medium | 2.2% | 2008-12-17 |
| CVE-2008-7135 EXP | toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the IsChecked… | Patch early | 4.3 medium | 2.2% | 2009-09-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt