CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,708 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2000-0638 EXP | bb-hostsvc.sh in Big Brother 1.4h1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the HOSTSVC parameter. | Patch early | 10.0 high | 4.1% | 2000-07-11 |
| CVE-2007-1372 EXP | PHP remote file inclusion vulnerability in styles/internal/header.php in the PostGuestbook 0.6.1 module for PHP-Nuke allows remote attackers to execut… | Patch early | 10.0 high | 4.1% | 2007-03-10 |
| CVE-2000-1074 EXP | csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to ga… | Patch early | 10.0 high | 4.1% | 2000-12-11 |
| CVE-2004-2158 EXP | SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter to (1) exit.… | Patch early | 7.5 high | 4.1% | 2004-12-31 |
| CVE-2000-0675 EXP | Buffer overflow in Infopulse Gatekeeper 3.5 and earlier allows remote attackers to execute arbitrary commands via a long string. | Patch early | 7.5 high | 4.1% | 2000-07-13 |
| CVE-2002-1242 EXP | SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain privileges via the "bio" argument… | Patch early | 7.5 high | 4.1% | 2002-11-12 |
| CVE-2007-2201 EXP | Multiple PHP remote file inclusion vulnerabilities in Post Revolution 6.6 and 7.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 4.1% | 2007-04-24 |
| CVE-2007-2657 EXP | Unspecified vulnerability in the PrecisionID Barcode 1.3 ActiveX control in PrecisionID_DataMatrix.DLL allows remote attackers to cause a denial of se… | Patch early | 7.8 high | 4.1% | 2007-05-14 |
| CVE-2006-4632 EXP | Multiple SQL injection vulnerabilities in SoftBB 0.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) group… | Patch early | 7.5 high | 4.1% | 2006-09-08 |
| CVE-2019-10716 EXP | An Information Disclosure issue in Verodin Director 3.5.3.1 and earlier reveals usernames and passwords of integrated security technologies via a /int… | Patch early | 7.7 high | 4.1% | 2019-10-21 |
| CVE-2006-3819 EXP | Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via an HTTP P… | Patch early | 7.5 high | 4.1% | 2006-07-27 |
| CVE-2016-1914 EXP | Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service befor… | Patch early | 8.8 high | 4.1% | 2017-04-13 |
| CVE-2008-5197 EXP | SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter in a deta… | Patch early | 7.5 high | 4.1% | 2008-11-21 |
| CVE-2007-2736 EXP | PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_at… | Patch early | 10.0 high | 4.1% | 2007-05-17 |
| CVE-2006-2400 EXP | The leetnet functions (leetnet/rudp.cpp) in Outgun 1.0.3 bot 2 and earlier allow remote attackers to cause a denial of service (game interruption) via… | Patch early | 7.8 high | 4.1% | 2006-05-16 |
| CVE-2006-2401 EXP | The leetnet functions (leetnet/rudp.cpp) in Outgun 1.0.3 bot 2 and earlier allow remote attackers to cause a denial of service (application crash) via… | Patch early | 7.8 high | 4.1% | 2006-05-16 |
| CVE-2000-0757 EXP | The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the serv… | Patch early | 10.0 high | 4.1% | 2000-10-20 |
| CVE-2008-4502 EXP | Multiple PHP remote file inclusion vulnerabilities in DataFeedFile (DFF) PHP Framework API allow remote attackers to execute arbitrary PHP code via a… | Patch early | 10.0 high | 4.1% | 2008-10-09 |
| CVE-2005-3817 EXP | Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands v… | Patch early | 7.5 high | 4.1% | 2005-11-26 |
| CVE-2021-24581 EXP | The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored… | Patch early | 8.8 high | 4.1% | 2021-08-30 |
| CVE-2006-0681 EXP | Format string vulnerability in powerd.c in Power Daemon (powerd) 2.0.2 and earlier allows remote attackers to execute arbitrary code via format string… | Patch early | 7.5 high | 4.1% | 2006-02-15 |
| CVE-2007-3340 EXP | BugHunter HTTP SERVER (httpsv.exe) 1.6.2 allows remote attackers to cause a denial of service (application crash) via a large number of requests for n… | Patch early | 7.8 high | 4.1% | 2007-06-21 |
| CVE-2004-1552 EXP | SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page… | Patch early | 7.5 high | 4.1% | 2004-12-31 |
| CVE-2008-3156 EXP | The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CA… | Patch early | 9.3 high | 4.1% | 2008-07-11 |
| CVE-2005-3879 EXP | Multiple SQL injection vulnerabilities in Softbiz Resource Repository Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 4.1% | 2005-11-29 |
| CVE-2005-0737 EXP | Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode. | Patch early | 7.5 high | 4.1% | 2005-05-02 |
| CVE-2019-6205 EXP | A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A mal… | Patch early | 7.8 high | 4.1% | 2019-03-05 |
| CVE-2007-1483 EXP | Multiple PHP remote file inclusion vulnerabilities in WebCalendar 0.9.45 allow remote attackers to execute arbitrary PHP code via a URL in the include… | Patch early | 7.5 high | 4.1% | 2007-03-16 |
| CVE-2006-2731 EXP | Multiple SQL injection vulnerabilities in Enigma Haber 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id paramet… | Patch early | 7.5 high | 4.1% | 2006-06-01 |
| CVE-2002-2309 EXP | php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via… | Patch early | 7.8 high | 4.1% | 2002-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt