CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,908 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-14266 EXP | tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related issue to CVE-2016-6160. | Patch early | 7.8 high | 3.6% | 2017-09-12 |
| CVE-2006-7134 EXP | Unrestricted file upload vulnerability in main_user.php in Upload Tool for PHP 1.0 allows remote attackers to upload and execute arbitrary files with… | Patch early | 10.0 high | 3.6% | 2007-03-06 |
| CVE-2009-0968 EXP | SQL injection vulnerability in fmoblog.php in the fMoblog plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the i… | Patch early | 7.5 high | 3.6% | 2009-03-19 |
| CVE-2012-3435 EXP | SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and earlier, and 2.x before 2.0.2rc1, allows remote attackers to exec… | Patch early | 7.5 high | 3.6% | 2012-08-15 |
| CVE-2007-0576 EXP | PHP remote file inclusion vulnerability in xt_counter.php in Xt-Stats 2.3.x up to 2.4.0.b3 allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 3.6% | 2007-01-30 |
| CVE-2006-5093 EXP | PHP remote file inclusion vulnerability in index.php in Tagmin Control Center in TagIt! Tagboard 2.1.B Build 2 allows remote attackers to execute arbi… | Patch early | 7.5 high | 3.6% | 2006-09-29 |
| CVE-2006-4607 EXP | admin/index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to bypass authentication controls by setting the ID_ADMIN and SUPER_ADMIN… | Patch early | 7.5 high | 3.6% | 2006-09-07 |
| CVE-2015-0004 EXP | The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win… | Patch early | 7.2 high | 3.6% | 2015-01-13 |
| CVE-2006-4026 EXP | PHP remote file inclusion vulnerability in SAPID CMS 123 rc3 allows remote attackers to execute arbitrary PHP code via a URL in the (1) root_path para… | Patch early | 7.5 high | 3.6% | 2006-08-09 |
| CVE-2006-1799 EXP | censtore.cgi in Censtore 7.3.002 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter. | Patch early | 7.5 high | 3.6% | 2006-04-18 |
| CVE-2008-6824 EXP | The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin account, which makes it easier for… | Patch early | 10.0 high | 3.6% | 2009-06-04 |
| CVE-2006-6581 EXP | PHP remote file inclusion vulnerability in tests/debug_test.php in Vernet Loic PHP_Debug 1.1.0 allows remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 3.6% | 2006-12-15 |
| CVE-2012-0699 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the a… | Patch early | 8.8 high | 3.6% | 2018-01-11 |
| CVE-2006-1032 EXP | Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other progr… | Patch early | 7.5 high | 3.6% | 2006-03-07 |
| CVE-2006-2982 EXP | Multiple PHP remote file inclusion vulnerabilities in Enterprise Timesheet and Payroll Systems (EPS) 1.1 and earlier allow remote attackers to execute… | Patch early | 7.5 high | 3.6% | 2006-06-13 |
| CVE-2006-3922 EXP | PHP remote file inclusion vulnerability in mod_membre/inscription.php in PortailPHP 1.7 allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 3.6% | 2006-07-28 |
| CVE-2006-6041 EXP | Multiple PHP remote file inclusion vulnerabilities in Laurent Van den Reysen WORK system e-commerce 3.0.2, and other versions before 3.0.4, allow remo… | Patch early | 7.5 high | 3.6% | 2006-11-22 |
| CVE-2006-2666 EXP | PHP remote file inclusion vulnerability in includes/mailaccess/pop3.php in V-Webmail 1.5 through 1.6.4 allows remote attackers to execute arbitrary PH… | Patch early | 7.5 high | 3.6% | 2006-05-30 |
| CVE-2006-3028 EXP | PHP remote file inclusion vulnerability in stat_modules/users_age/module.php in Minerva 2.0.8a Build 237 and earlier allows remote attackers to execut… | Patch early | 7.5 high | 3.6% | 2006-06-15 |
| CVE-2016-6253 EXP | mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary file… | Patch early | 7.8 high | 3.6% | 2017-01-20 |
| CVE-2013-3365 EXP | TRENDnet TEW-812DRU router allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) wan network prefix to i… | Patch early | 8.5 high | 3.6% | 2014-02-04 |
| CVE-2006-5087 EXP | Multiple PHP remote file inclusion vulnerabilities in evoBB 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path… | Patch early | 7.5 high | 3.6% | 2006-09-29 |
| CVE-2013-6041 EXP | index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cooki… | Patch early | 7.5 high | 3.6% | 2014-12-27 |
| CVE-2008-3375 EXP | The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrativ… | Patch early | 7.5 high | 3.6% | 2008-07-30 |
| CVE-2007-0677 EXP | PHP remote file inclusion vulnerability in fw/class.Quick_Config_Browser.php in Cadre PHP Framework 20020724 allows remote attackers to execute arbitr… | Patch early | 7.5 high | 3.6% | 2007-02-03 |
| CVE-2007-3192 EXP | admin/setup.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to read and modify configuration settings via a direc… | Patch early | 9.4 high | 3.6% | 2007-06-12 |
| CVE-2008-4624 EXP | PHP remote file inclusion vulnerability in init.php in Fast Click SQL Lite 1.1.7, when register_globals is enabled, allows remote attackers to execute… | Patch early | 9.3 high | 3.6% | 2008-10-21 |
| CVE-2017-5473 EXP | Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demo… | Patch early | 8.8 high | 3.6% | 2017-01-14 |
| CVE-2005-0959 EXP | Buffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a long path. | Patch early | 7.5 high | 3.6% | 2005-05-02 |
| CVE-2015-2554 EXP | The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain pr… | Patch early | 7.2 high | 3.6% | 2015-10-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt