CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,999 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-0612 EXP | FileSeek.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) head or (2) foot parameters. | Patch early | 7.5 high | 3.4% | 2002-06-18 |
| CVE-2003-1286 EXP | HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy HTTP request… | Patch early | 7.5 high | 3.4% | 2003-12-31 |
| CVE-2007-4283 EXP | PHP remote file inclusion vulnerability in bridge/yabbse.inc.php in Coppermine Photo Gallery (CPG) 1.3.1 allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 3.4% | 2007-08-09 |
| CVE-2008-5783 EXP | admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative access by setting the admin coo… | Patch early | 7.5 high | 3.4% | 2008-12-31 |
| CVE-2006-5154 EXP | PHP remote file inclusion vulnerability in cp/sig.php in DeluxeBB 1.09 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 3.4% | 2006-10-05 |
| CVE-2012-2109 EXP | SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attackers to execute arbitrary SQL c… | Patch early | 7.5 high | 3.4% | 2012-09-04 |
| CVE-2015-1726 EXP | Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 an… | Patch early | 7.2 high | 3.4% | 2015-06-10 |
| CVE-2011-1516 EXP | The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all creat… | Patch early | 7.6 high | 3.4% | 2011-11-15 |
| CVE-2006-5547 EXP | PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.0.0 through 1.0.3 allows remote… | Patch early | 7.5 high | 3.4% | 2006-10-26 |
| CVE-2006-5548 EXP | PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 2.0.0 through 2.1.3 allows remote… | Patch early | 7.5 high | 3.4% | 2006-10-26 |
| CVE-2020-14930 EXP | An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verif… | Patch early | 8.1 high | 3.4% | 2020-06-19 |
| CVE-2007-0682 EXP | PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allows remote attackers to execute… | Patch early | 7.5 high | 3.4% | 2007-02-03 |
| CVE-2007-1011 EXP | PHP remote file inclusion vulnerability in functions_inc.php in VS-Gastebuch 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 3.4% | 2007-02-21 |
| CVE-2006-1662 EXP | The frontpage option in Limbo CMS 1.0.4.2 and 1.0.4.1 allows remote attackers to execute arbitrary PHP commands via the Itemid parameter in index.php. | Patch early | 7.5 high | 3.4% | 2006-04-07 |
| CVE-2006-6417 EXP | PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers to execute a… | Patch early | 7.5 high | 3.4% | 2006-12-10 |
| CVE-2019-5797 EXP | Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p… | Patch early | 7.5 high | 3.4% | 2022-09-29 |
| CVE-2015-4593 EXP | eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserService.jsp which allows remote at… | Patch early | 8.8 high | 3.4% | 2017-01-10 |
| CVE-2006-3986 EXP | PHP remote file inclusion vulnerability in index.php in Knusperleicht Newsletter 3.5 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 3.4% | 2006-08-05 |
| CVE-2006-4129 EXP | PHP remote file inclusion vulnerability in admin.webring.docs.php in the Webring Component (com_webring) 1.0 and earlier for Joomla! allows remote att… | Patch early | 7.5 high | 3.4% | 2006-08-14 |
| CVE-2006-4456 EXP | PHP remote file inclusion vulnerability in functions.php in phpECard 2.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 3.4% | 2006-08-31 |
| CVE-2006-4645 EXP | PHP remote file inclusion vulnerability in akarru.gui/main_content.php in Akarru Social BookMarking Engine 0.4.3.34 and earlier, and possibly 0.4.4.12… | Patch early | 7.5 high | 3.4% | 2006-09-08 |
| CVE-2008-6366 EXP | SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 3.4% | 2009-03-02 |
| CVE-2008-5045 EXP | Heap-based buffer overflow in Network-Client FTP Now 2.6, and possibly other versions, allows remote FTP servers to cause a denial of service (crash)… | Patch early | 10.0 high | 3.4% | 2008-11-13 |
| CVE-2006-2737 EXP | utilities/register.asp in Nukedit 4.9.6 and earlier allows remote attackers to create new users as part of arbitrary groups, including the administrat… | Patch early | 7.5 high | 3.4% | 2006-06-01 |
| CVE-2008-5580 EXP | mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the sFileName argumen… | Patch early | 7.5 high | 3.4% | 2008-12-15 |
| CVE-2000-0442 EXP | Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command. | Patch early | 7.5 high | 3.3% | 2000-05-24 |
| CVE-2000-1037 EXP | Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows… | Patch early | 7.5 high | 3.3% | 2000-12-11 |
| CVE-2008-6365 EXP | SQL injection vulnerability in logon.jsp in Ad Server Solutions Ad Management Software Java allows remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 3.3% | 2009-03-02 |
| CVE-2012-4908 EXP | Google Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Policy and obtain access to local files via vectors inv… | Patch early | 7.5 high | 3.3% | 2012-09-13 |
| CVE-2006-2527 EXP | Admin/admin.php in phpBazar 2.1.0 and earlier allows remote attackers to bypass the authentication process and gain unauthorized access to the adminis… | Patch early | 7.5 high | 3.3% | 2006-05-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt