CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,984 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-6528 EXP | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/spool/.pfile file). | Patch early | 8.1 high | 3.4% | 2017-03-09 |
| CVE-2007-6587 EXP | SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Patch early | 7.5 high | 3.4% | 2007-12-28 |
| CVE-2015-1727 EXP | Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win… | Patch early | 7.2 high | 3.4% | 2015-06-10 |
| CVE-2008-0785 EXP | Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote authenticated users to execute arbitrary SQL… | Patch early | 7.5 high | 3.4% | 2008-02-14 |
| CVE-2006-1994 EXP | PHP remote file inclusion vulnerability in dForum 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DFORUM_PATH p… | Patch early | 7.5 high | 3.4% | 2006-04-25 |
| CVE-2006-3185 EXP | PHP remote file inclusion vulnerability in data/header.php in CMS Faethon 1.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 3.4% | 2006-06-23 |
| CVE-2006-4622 EXP | PHP remote file inclusion vulnerability in annonce.php in AnnonceV (aka annoncesV) 1.1 allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 3.4% | 2006-09-07 |
| CVE-2003-1131 EXP | PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary P… | Patch early | 7.5 high | 3.4% | 2003-12-31 |
| CVE-2005-1881 EXP | upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to up… | Patch early | 7.5 high | 3.4% | 2005-06-06 |
| CVE-2012-5049 EXP | APIFTP Server in Optimalog Optima PLC 1.5.2 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed packet. | Patch early | 7.8 high | 3.4% | 2012-09-28 |
| CVE-2008-3509 EXP | LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows r… | Patch early | 7.5 high | 3.4% | 2008-08-07 |
| CVE-2010-1897 EXP | The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server… | Patch early | 7.2 high | 3.4% | 2010-08-11 |
| CVE-2003-1407 EXP | Buffer overflow in cmd.exe in Windows NT 4.0 may allow local users to execute arbitrary code via a long pathname argument to the cd command. | Patch early | 7.2 high | 3.4% | 2003-12-31 |
| CVE-2008-0743 EXP | PHP remote file inclusion vulnerability in members_help.php in Joovili 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 10.0 high | 3.4% | 2008-02-13 |
| CVE-2006-4648 EXP | PHP remote file inclusion vulnerability in bp_ncom.php in BinGo News (BP News) 3.01 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 3.4% | 2006-09-08 |
| CVE-2011-5212 EXP | SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via the (1) user name or… | Patch early | 7.5 high | 3.4% | 2012-10-22 |
| CVE-2007-2147 EXP | admin/options.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier does not check for administrative credentials, which allows remote attac… | Patch early | 10.0 high | 3.4% | 2007-04-19 |
| CVE-2015-5452 EXP | SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitrary SQL commands via the sid c… | Patch early | 7.5 high | 3.4% | 2015-07-08 |
| CVE-2014-5329 EXP | GIGAPOD file servers (Appliance model and Software model) provide two web interfaces, 80/tcp and 443/tcp for user operation, and 8001/tcp for administ… | Patch early | 7.5 high | 3.4% | 2023-09-08 |
| CVE-2006-2871 EXP | PHP remote file inclusion vulnerability in include/common.php in CyBoards PHP Lite 1.25 allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 3.4% | 2006-06-06 |
| CVE-2006-3997 EXP | PHP remote file inclusion vulnerability in hsList.php in WoWRoster (aka World of Warcraft Roster) 1.5.x and earlier allows remote attackers to execute… | Patch early | 7.5 high | 3.4% | 2006-08-05 |
| CVE-2004-0894 EXP | LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, w… | Patch early | 7.2 high | 3.4% | 2005-01-10 |
| CVE-2018-18773 EXP | CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root… | Patch early | 8.8 high | 3.4% | 2018-11-20 |
| CVE-2014-5109 EXP | SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute arbitrary SQL com… | Patch early | 7.5 high | 3.4% | 2014-07-28 |
| CVE-2007-2615 EXP | Multiple PHP remote file inclusion vulnerabilities in Crie seu PHPLojaFacil 0.1.5 allow remote attackers to execute arbitrary PHP code via a URL in th… | Patch early | 7.5 high | 3.4% | 2007-05-11 |
| CVE-2012-0181 EXP | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, an… | Patch early | 7.2 high | 3.4% | 2012-05-09 |
| CVE-2005-2155 EXP | PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath para… | Patch early | 7.5 high | 3.4% | 2005-07-06 |
| CVE-2006-5637 EXP | PHP remote file inclusion vulnerability in faq_reply.php in Faq Administrator 2.1b allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 3.4% | 2006-11-01 |
| CVE-2008-5963 EXP | Eval injection vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remote attackers to execute arbitr… | Patch early | 10.0 high | 3.4% | 2009-01-23 |
| CVE-2016-0093 EXP | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2… | Patch early | 7.8 high | 3.4% | 2016-03-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt