CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,522 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-2314 EXP | SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang param… | Patch early | 7.5 high | 7.1% | 2015-03-17 |
| CVE-2006-3162 EXP | PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 7.1% | 2006-06-22 |
| CVE-2016-2203 EXP | The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by… | Patch early | 7.8 high | 7.1% | 2016-04-22 |
| CVE-2003-0625 EXP | Off-by-one error in certain versions of xfstt allows remote attackers to read potentially sensitive memory via a malformed client request in the conne… | Patch early | 7.5 high | 7.1% | 2003-08-27 |
| CVE-2019-14267 EXP | PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled. | Patch early | 7.8 high | 7.1% | 2019-07-29 |
| CVE-2022-47876 EXP | The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code via Groovy-scripts. | Patch early | 8.8 high | 7% | 2023-05-02 |
| CVE-2008-6583 EXP | Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a lon… | Patch early | 9.3 high | 7% | 2009-04-03 |
| CVE-2007-5070 EXP | Heap-based buffer overflow in the EasyMailMessagePrinter ActiveX control in emprint.DLL 6.0.1.0 in the Quiksoft EasyMail MessagePrinter Object allows… | Patch early | 10.0 high | 7% | 2007-09-24 |
| CVE-2009-3691 EXP | Multiple integer overflows in setnet32.exe 3.50.0.13752 in IBM Informix Client SDK 3.0 and 3.50 and Informix Connect Runtime 3.x allow remote attacker… | Patch early | 9.3 high | 7% | 2009-10-13 |
| CVE-2007-2588 EXP | Multiple buffer overflows in the Office Viewer OCX ActiveX control (oa.ocx) 3.2 allow remote attackers to cause a denial of service (crash) or possibl… | Patch early | 9.3 high | 7% | 2007-05-10 |
| CVE-2006-0163 EXP | SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attackers to execute arbitrary SQL com… | Patch early | 7.5 high | 7% | 2006-01-11 |
| CVE-2009-0291 EXP | Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the MA… | Patch early | 7.5 high | 7% | 2009-01-27 |
| CVE-2023-33177 EXP | Xibo is a content management system (CMS). A path traversal vulnerability exists in the Xibo CMS whereby a specially crafted zip file can be uploaded… | Patch early | 8.8 high | 7% | 2023-05-30 |
| CVE-2000-0590 EXP | Poll It 2.0 CGI script allows remote attackers to read arbitrary files by specifying the file name in the data_dir parameter. | Patch early | 7.5 high | 7% | 2000-07-04 |
| CVE-2017-5594 EXP | An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when… | Patch early | 7.5 high | 7% | 2017-01-25 |
| CVE-1999-0068 EXP | CGI PHP mylog script allows an attacker to read any file on the target server. | Patch early | 7.5 high | 7% | 1997-10-19 |
| CVE-2008-4428 EXP | Unrestricted file upload vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier allows remote attackers to exe… | Patch early | 10.0 high | 7% | 2008-10-03 |
| CVE-2018-9107 EXP | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla!… | Patch early | 8.8 high | 7% | 2018-03-28 |
| CVE-2014-1947 EXP | Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial o… | Patch early | 7.8 high | 7% | 2020-02-17 |
| CVE-2001-0626 EXP | O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request contain… | Patch early | 7.5 high | 7% | 2001-08-22 |
| CVE-2001-0839 EXP | ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers to modify ac… | Patch early | 7.5 high | 7% | 2001-12-06 |
| CVE-2002-0413 EXP | Cross-site scripting vulnerability in ReBB allows remote attackers to execute arbitrary Javascript and steal cookies via an IMG tag whose URL includes… | Patch early | 7.5 high | 7% | 2002-08-12 |
| CVE-2002-1009 EXP | Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web scri… | Patch early | 7.5 high | 7% | 2002-10-04 |
| CVE-2014-3008 EXP | Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm parameter to re… | Patch early | 10.0 high | 7% | 2014-04-28 |
| CVE-2005-0436 EXP | Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode p… | Patch early | 7.5 high | 7% | 2005-05-02 |
| CVE-2002-0207 EXP | Buffer overflow in Real Networks RealPlayer 8.0 and earlier allows remote attackers to execute arbitrary code via a header length value that exceeds t… | Patch early | 7.5 high | 7% | 2002-05-16 |
| CVE-2007-4905 EXP | Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute arbitrary PHP files via the imag… | Patch early | 7.5 high | 7% | 2007-09-17 |
| CVE-2008-1647 EXP | The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0, and earlier in ChilkatHttp Ac… | Patch early | 9.3 high | 7% | 2008-04-02 |
| CVE-2007-2936 EXP | Multiple PHP remote file inclusion vulnerabilities in Frequency Clock 0.1b (Beta 0.1) allow remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 7% | 2007-05-31 |
| CVE-2007-2941 EXP | Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 for vBulletin allow remote atta… | Patch early | 7.5 high | 7% | 2007-05-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt