CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,674 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-1621 EXP | PHP remote file inclusion vulnerability in templates/head.php in Active PHP Bookmark Notes (APB) 0.2.5 and earlier allows remote attackers to execute… | Patch early | 10.0 high | 4.2% | 2007-03-23 |
| CVE-2007-1778 EXP | PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remote attackers to execute arbitra… | Patch early | 10.0 high | 4.2% | 2007-03-30 |
| CVE-1999-0944 EXP | IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections. | Patch early | 10.0 high | 4.2% | 1999-10-24 |
| CVE-2021-27946 EXP | SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3). | Patch early | 8.8 high | 4.2% | 2021-03-15 |
| CVE-2006-4974 EXP | Buffer overflow in Ipswitch WS_FTP Limited Edition (LE) 5.08 allows remote FTP servers to execute arbitrary code via a long response to a PASV command… | Patch early | 7.5 high | 4.2% | 2006-09-25 |
| CVE-2010-2744 EXP | The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2… | Patch early | 7.2 high | 4.2% | 2010-10-13 |
| CVE-2006-2487 EXP | Multiple PHP remote file inclusion vulnerabilities in ScozNews 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 4.2% | 2006-05-19 |
| CVE-2017-2360 EXP | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. wa… | Patch early | 7.8 high | 4.2% | 2017-02-20 |
| CVE-2007-5187 EXP | SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remote attack… | Patch early | 7.5 high | 4.2% | 2007-10-03 |
| CVE-2017-2501 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… | Patch early | 7.0 high | 4.2% | 2017-05-22 |
| CVE-2006-2507 EXP | Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing 0.2.0 through 0.7.0, as used with phpBB, allow remote attackers to execute arb… | Patch early | 7.5 high | 4.2% | 2006-05-22 |
| CVE-2015-1318 EXP | The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport fi… | Patch early | 7.2 high | 4.2% | 2015-04-17 |
| CVE-2002-2417 EXP | acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or mi… | Patch early | 10.0 high | 4.2% | 2002-12-31 |
| CVE-2005-4216 EXP | The Administration Service (FMSAdmin.exe) in Macromedia Flash Media Server 2.0 r1145 allows remote attackers to cause a denial of service (application… | Patch early | 7.8 high | 4.2% | 2005-12-14 |
| CVE-2010-0552 EXP | Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via mu… | Patch early | 7.5 high | 4.2% | 2010-02-04 |
| CVE-2010-4232 EXP | The web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allo… | Patch early | 10.0 high | 4.2% | 2010-11-17 |
| CVE-2015-8284 EXP | SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions. | Patch early | 8.8 high | 4.2% | 2017-04-13 |
| CVE-2007-1076 EXP | Multiple directory traversal vulnerabilities in phpTrafficA 1.4.1, and possibly earlier, allow remote attackers to include arbitrary local files via a… | Patch early | 7.5 high | 4.2% | 2007-02-22 |
| CVE-2006-6376 EXP | Multiple directory traversal vulnerabilities in fm.php in Simple File Manager (SFM) 0.24a allow remote attackers to use ".." sequences to (1) read arb… | Patch early | 7.5 high | 4.2% | 2006-12-07 |
| CVE-2014-1204 EXP | SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated users to execute arbitrary SQL com… | Patch early | 7.5 high | 4.2% | 2014-01-31 |
| CVE-2015-2878 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of admini… | Patch early | 8.8 high | 4.2% | 2017-10-23 |
| CVE-2005-0185 EXP | Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap packet that con… | Patch early | 7.5 high | 4.2% | 2005-05-02 |
| CVE-2010-0702 EXP | SQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 4.2% | 2010-02-23 |
| CVE-2015-7068 EXP | IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privi… | Patch early | 7.8 high | 4.2% | 2015-12-11 |
| CVE-2007-4446 EXP | Format string vulnerability in the server in Toribash 2.71 and earlier allows remote attackers to execute arbitrary code via format string specifiers… | Patch early | 7.5 high | 4.2% | 2007-08-21 |
| CVE-2007-2985 EXP | Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to… | Patch early | 10.0 high | 4.2% | 2007-06-01 |
| CVE-2008-6490 EXP | function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the target filename in the target… | Patch early | 7.5 high | 4.2% | 2009-03-19 |
| CVE-2007-3270 EXP | PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to execute arbitrary PHP code via a U… | Patch early | 10.0 high | 4.2% | 2007-06-19 |
| CVE-2020-7949 EXP | schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and i… | Patch early | 7.8 high | 4.2% | 2020-01-27 |
| CVE-2007-3011 EXP | The DBAsciiAccess CGI Script in the web interface in Fujitsu-Siemens Computers ServerView before 4.50.09 allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 4.2% | 2007-07-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt