CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,708 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-4163 EXP | PHP remote file inclusion vulnerability in cls_fast_template.php in myWebland miniBloggie 1.0 and earlier allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 4.2% | 2006-08-16 |
| CVE-2016-1744 EXP | The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or… | Patch early | 7.8 high | 4.2% | 2016-03-24 |
| CVE-2004-1227 EXP | Directory traversal vulnerability in SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to read arbitrary files and possibly execute arbi… | Patch early | 10.0 high | 4.2% | 2005-01-10 |
| CVE-2007-6652 EXP | cpie.php in XCMS 1.83 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct direct static code i… | Patch early | 7.5 high | 4.2% | 2008-01-04 |
| CVE-2016-6707 EXP | An elevation of privilege vulnerability in System Server in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local malicious app… | Patch early | 7.8 high | 4.2% | 2016-11-25 |
| CVE-2002-2026 EXP | Buffer overflow in BrowseFTP 1.62 client allows remote FTP servers to execute arbitrary code via a long FTP "220" message reply. | Patch early | 7.5 high | 4.2% | 2002-12-31 |
| CVE-2004-0304 EXP | SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitr… | Patch early | 10.0 high | 4.1% | 2004-11-23 |
| CVE-2015-2219 EXP | Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privile… | Patch early | 7.2 high | 4.1% | 2015-05-12 |
| CVE-2003-1245 EXP | index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of a session… | Patch early | 10.0 high | 4.1% | 2003-12-31 |
| CVE-2005-1401 EXP | Format string vulnerability in the client for Mtp-Target 1.2.2 and earlier allows remote attackers to execute arbitrary code via game messages or othe… | Patch early | 7.5 high | 4.1% | 2005-05-03 |
| CVE-2006-6976 EXP | PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.2 and earlier allows remote attackers to execute arbitrary code via a… | Patch early | 7.5 high | 4.1% | 2007-02-08 |
| CVE-2004-2534 EXP | Fastream NETFile Server 7.1.2 does not properly handle keep-alive connection timeouts and does not close the connection after a HEAD request, which al… | Patch early | 7.8 high | 4.1% | 2004-12-31 |
| CVE-2017-11567 EXP | Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for re… | Patch early | 8.8 high | 4.1% | 2017-09-07 |
| CVE-2008-2833 EXP | admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in… | Patch early | 10.0 high | 4.1% | 2008-06-24 |
| CVE-2017-2443 EXP | An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graphics Driver" component. It allo… | Patch early | 7.8 high | 4.1% | 2017-04-02 |
| CVE-2013-3543 EXP | The AXIS Media Control (AMC) ActiveX control (AxisMediaControlEmb.dll) 6.2.10.11 for AXIS network cameras allows remote attackers to create or overwri… | Patch early | 8.8 high | 4.1% | 2013-10-04 |
| CVE-2012-6046 EXP | Static code injection vulnerability in admin/banners.php in PHP Enter allows remote attackers to inject arbitrary PHP code into horad.php via the code… | Patch early | 10.0 high | 4.1% | 2012-11-27 |
| CVE-2007-4715 EXP | Multiple PHP remote file inclusion vulnerabilities in Weblogicnet allow remote attackers to execute arbitrary PHP code via a URL in the files_dir para… | Patch early | 7.5 high | 4.1% | 2007-09-05 |
| CVE-2022-26986 EXP | SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and m… | Patch early | 7.2 high | 4.1% | 2022-04-05 |
| CVE-2008-1242 EXP | The control panel on the Belkin F5D7230-4 router with firmware 9.01.10 maintains authentication state by IP address, which allows remote attackers to… | Patch early | 10.0 high | 4.1% | 2008-03-10 |
| CVE-2008-5677 EXP | Unrestricted file upload vulnerability in Kwalbum 2.0.4, 2.0.2, and earlier, when PICS_PATH is located in the web root, allows remote authenticated us… | Patch early | 7.1 high | 4.1% | 2008-12-19 |
| CVE-2003-0232 EXP | Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that… | Patch early | 7.2 high | 4.1% | 2003-08-27 |
| CVE-2008-6534 EXP | Incomplete blacklist vulnerability in NULL FTP Server Free and Pro 1.1.0.7 allows remote authenticated users to execute arbitrary commands via a custo… | Patch early | 7.1 high | 4.1% | 2009-03-26 |
| CVE-2002-1468 EXP | Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root. | Patch early | 10.0 high | 4.1% | 2003-04-22 |
| CVE-2016-7980 EXP | Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authent… | Patch early | 8.8 high | 4.1% | 2017-01-18 |
| CVE-2002-0525 EXP | Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileg… | Patch early | 10.0 high | 4.1% | 2002-08-12 |
| CVE-2006-5223 EXP | PHP remote file inclusion vulnerability in includes/functions_user_viewed_posts.php in the Nivisec User Viewed Posts Tracker module 1.0 and earlier fo… | Patch early | 7.5 high | 4.1% | 2006-10-10 |
| CVE-2018-4230 EXP | An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "NVIDIA Graphics Drivers" component. It al… | Patch early | 7.0 high | 4.1% | 2018-06-08 |
| CVE-2008-7115 EXP | The web interface to the Belkin Wireless G router and ADSL2 modem F5D7632-4V6 with firmware 6.01.08 allows remote attackers to bypass authentication a… | Patch early | 10.0 high | 4.1% | 2009-08-28 |
| CVE-2004-0621 EXP | admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (ad… | Patch early | 10.0 high | 4.1% | 2004-12-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt