CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,941 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-2325 EXP | The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to c… | Patch early | 7.8 high | 3.5% | 2002-12-31 |
| CVE-2003-0243 EXP | Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) no… | Patch early | 7.5 high | 3.5% | 2003-05-27 |
| CVE-2006-5124 EXP | Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 3.5% | 2006-10-03 |
| CVE-2007-5089 EXP | PHP remote file inclusion vulnerability in php-inc/log.inc.php in sk.log 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 3.5% | 2007-09-26 |
| CVE-2017-0214 EXP | Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 G… | Patch early | 7.0 high | 3.5% | 2017-05-12 |
| CVE-2008-4526 EXP | Multiple directory traversal vulnerabilities in CCMS 3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the… | Patch early | 10.0 high | 3.5% | 2008-10-09 |
| CVE-2013-4948 EXP | SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the element_2 parameter. | Patch early | 7.5 high | 3.5% | 2013-07-29 |
| CVE-2005-1487 EXP | Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt… | Patch early | 7.5 high | 3.5% | 2005-05-11 |
| CVE-2006-2008 EXP | PHP remote file inclusion vulnerability in movie_cls.php in Built2Go PHP Movie Review 2B and earlier allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 3.5% | 2006-04-25 |
| CVE-2006-3177 EXP | PHP remote file inclusion vulnerability in Admin/rtf_parser.php in The Bible Portal Project 2.12 and earlier allows remote attackers to execute arbitr… | Patch early | 7.5 high | 3.5% | 2006-06-23 |
| CVE-2006-3300 EXP | PHP remote file inclusion vulnerability in sms_config/gateway.php in PhpMySms 2.0 and earlier allows remote attackers to execute arbitrary PHP code vi… | Patch early | 7.5 high | 3.5% | 2006-06-29 |
| CVE-2006-4040 EXP | PHP remote file inclusion vulnerability in myevent.php in myWebland myEvent 1.3 and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 3.5% | 2006-08-09 |
| CVE-2006-4045 EXP | PHP remote file inclusion vulnerability in news.php in Torbstoff News 4 allows remote attackers to execute arbitrary PHP code via a URL in the pfad pa… | Patch early | 7.5 high | 3.5% | 2006-08-09 |
| CVE-2006-4209 EXP | PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to execute arbitrary PHP code vi… | Patch early | 7.5 high | 3.5% | 2006-08-17 |
| CVE-2006-4296 EXP | PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers to include… | Patch early | 7.5 high | 3.5% | 2006-08-23 |
| CVE-2006-4629 EXP | PHP remote file inclusion vulnerability in affichage/commentaires.php in C-News.fr C-News 1.0.1 and earlier allows remote attackers to execute arbitra… | Patch early | 7.5 high | 3.5% | 2006-09-08 |
| CVE-2006-4630 EXP | PHP remote file inclusion vulnerability in jscript.php in Sky GUNNING MySpeach 3.0.2 and earlier, when register_globals is enabled, allows remote atta… | Patch early | 7.5 high | 3.5% | 2006-09-08 |
| CVE-2006-0887 EXP | Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib distribution is available on th… | Patch early | 7.5 high | 3.5% | 2006-02-25 |
| CVE-2000-0342 EXP | Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers… | Patch early | 7.5 high | 3.5% | 2000-04-28 |
| CVE-2000-0592 EXP | Buffer overflows in POP3 service in WinProxy 2.0 and 2.0.1 allow remote attackers to execute arbitrary commands via long USER, PASS, LIST, RETR, or DE… | Patch early | 7.5 high | 3.5% | 2000-06-27 |
| CVE-2007-2556 EXP | SQL injection vulnerability in Nuked-klaN 1.7.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For (X_FORWARDED_FOR) HT… | Patch early | 7.5 high | 3.5% | 2007-05-09 |
| CVE-2007-1795 EXP | JCcorp URLshrink 1.3.1 allows remote attackers to execute arbitrary PHP code via the email address field in an HTML link. NOTE: the provenance of thi… | Patch early | 10.0 high | 3.4% | 2007-04-02 |
| CVE-2006-6869 EXP | Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and reg… | Patch early | 9.3 high | 3.4% | 2006-12-31 |
| CVE-2009-4194 EXP | Directory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions allows remote authenticated users… | Patch early | 8.1 high | 3.4% | 2009-12-03 |
| CVE-2016-0728 EXP | The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error cas… | Patch early | 7.8 high | 3.4% | 2016-02-08 |
| CVE-2007-6231 EXP | Multiple PHP remote file inclusion vulnerabilities in tellmatic 1.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the tm_include… | Patch early | 7.5 high | 3.4% | 2007-12-04 |
| CVE-2005-3859 EXP | PHP remote file inclusion vulnerability in q-news.php in Q-News 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the id paramete… | Patch early | 7.5 high | 3.4% | 2005-11-29 |
| CVE-2007-5926 EXP | OpenBase 10.0.5 and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in arguments to the (1) AsciiBack… | Patch early | 9.0 high | 3.4% | 2007-11-10 |
| CVE-2005-4168 EXP | Multiple SQL injection vulnerabilities in eFiction 1.0, 1.1, and 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the let paramete… | Patch early | 7.5 high | 3.4% | 2005-12-11 |
| CVE-2013-6164 EXP | SQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execute arbitrary SQL commands via the objectI… | Patch early | 7.5 high | 3.4% | 2013-11-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt