CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,941 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-5117 EXP | Multiple PHP remote file inclusion vulnerabilities in FrontAccounting (FA) 1.13, when register_globals is enabled, allow remote attackers to execute a… | Patch early | 9.3 high | 3.6% | 2007-09-27 |
| CVE-2006-6341 EXP | Multiple PHP remote file inclusion vulnerabilities in mg.applanix 1.3.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 3.6% | 2006-12-07 |
| CVE-2009-0120 EXP | The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by se… | Patch early | 7.8 high | 3.6% | 2009-01-15 |
| CVE-2008-7001 EXP | Unrestricted file upload vulnerability in the file manager in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary code via unkn… | Patch early | 7.5 high | 3.6% | 2009-08-19 |
| CVE-2002-2425 EXP | Sun AnswerBook2 1.2 through 1.4.2 allows remote attackers to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a dir… | Patch early | 10.0 high | 3.5% | 2002-12-31 |
| CVE-2008-3455 EXP | PHP remote file inclusion vulnerability in include/admin.php in JnSHosts PHP Hosting Directory 2.0 allows remote attackers to execute arbitrary PHP co… | Patch early | 10.0 high | 3.5% | 2008-08-04 |
| CVE-2008-4704 EXP | PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 10.0 high | 3.5% | 2008-10-23 |
| CVE-2008-5066 EXP | PHP remote file inclusion vulnerability in upload/admin/frontpage_right.php in Agares Media ThemeSiteScript 1.0 allows remote attackers to execute arb… | Patch early | 10.0 high | 3.5% | 2008-11-13 |
| CVE-2006-4720 EXP | PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary PHP code via a URL in the pat… | Patch early | 7.5 high | 3.5% | 2006-09-12 |
| CVE-2006-5256 EXP | PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 3.5% | 2006-10-12 |
| CVE-2006-5527 EXP | PHP remote file inclusion vulnerability in lib.editor.inc.php in Intelimen InteliEditor 1.2.x allows remote attackers to execute arbitrary PHP code vi… | Patch early | 7.5 high | 3.5% | 2006-10-26 |
| CVE-2006-5796 EXP | Multiple PHP remote file inclusion vulnerabilities in Soholaunch Pro Edition 4.9 r46 and earlier, when register_globals is enabled, allow remote attac… | Patch early | 7.5 high | 3.5% | 2006-11-08 |
| CVE-2001-0490 EXP | Buffer overflow in WINAMP 2.6x and 2.7x allows attackers to execute arbitrary code via a long string in an AIP file. | Patch early | 7.5 high | 3.5% | 2001-06-27 |
| CVE-2003-0315 EXP | Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP request, whi… | Patch early | 7.5 high | 3.5% | 2003-06-16 |
| CVE-2008-0600 EXP | The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows l… | Patch early | 7.2 high | 3.5% | 2008-02-12 |
| CVE-2008-3371 EXP | Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remote attackers to include and exe… | Patch early | 7.5 high | 3.5% | 2008-07-30 |
| CVE-2008-0251 EXP | Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown v… | Patch early | 10.0 high | 3.5% | 2008-01-12 |
| CVE-2006-5243 EXP | Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Doc 1.4 and earlier, when register_globals is enabled, allow remote attackers to e… | Patch early | 7.5 high | 3.5% | 2006-10-12 |
| CVE-2013-2580 EXP | Unrestricted file upload vulnerability in cgi-bin/uploadfile in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other mo… | Patch early | 7.1 high | 3.5% | 2013-10-11 |
| CVE-2019-0959 EXP | An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker… | Patch early | 7.0 high | 3.5% | 2019-06-12 |
| CVE-2008-2672 EXP | Multiple directory traversal vulnerabilities in ErfurtWiki R1.02b and earlier, when register_globals is enabled, allow remote attackers to include and… | Patch early | 7.5 high | 3.5% | 2008-06-12 |
| CVE-2010-3081 EXP | The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly all… | Patch early | 7.8 high | 3.5% | 2010-09-24 |
| CVE-2007-1930 EXP | Directory traversal vulnerability in download2.php in cattaDoc 2.21, and possibly other versions including 3.0, allows remote attackers to read arbitr… | Patch early | 7.8 high | 3.5% | 2007-04-10 |
| CVE-2015-2183 EXP | Multiple SQL injection vulnerabilities in the administrative backend in ZeusCart 4 allow remote administrators to execute arbitrary SQL commands via t… | Patch early | 7.5 high | 3.5% | 2015-03-10 |
| CVE-2015-2512 EXP | The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Serv… | Patch early | 7.2 high | 3.5% | 2015-09-09 |
| CVE-2008-0246 EXP | admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain… | Patch early | 10.0 high | 3.5% | 2008-01-12 |
| CVE-2007-4956 EXP | Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to login.ph… | Patch early | 7.5 high | 3.5% | 2007-09-18 |
| CVE-2006-5930 EXP | Multiple PHP remote file inclusion vulnerabilities in Aigaion Web based bibliography management system 1.2.1 and earlier allow remote attackers to exe… | Patch early | 7.5 high | 3.5% | 2006-11-16 |
| CVE-2008-1989 EXP | PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows remo… | Patch early | 10.0 high | 3.5% | 2008-04-27 |
| CVE-1999-1007 EXP | Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file. | Patch early | 7.6 high | 3.5% | 1999-12-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt