CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,041 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-5440 EXP | Multiple PHP remote file inclusion vulnerabilities in CRS Manager allow remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT… | Patch early | 7.5 high | 3.2% | 2007-10-14 |
| CVE-2024-42471 EXP | actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to… | Patch early | 7.3 high | 3.2% | 2024-09-02 |
| CVE-2021-24174 EXP | The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as… | Patch early | 8.1 high | 3.2% | 2021-04-05 |
| CVE-2007-4806 EXP | PHP remote file inclusion vulnerability in modules/Discipline/CategoryBreakdownTime.php in Focus/SIS 1.0 allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 3.2% | 2007-09-11 |
| CVE-2007-4807 EXP | Multiple PHP remote file inclusion vulnerabilities in Focus/SIS 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the staticpath p… | Patch early | 7.5 high | 3.2% | 2007-09-11 |
| CVE-2000-0798 EXP | The truncate function in IRIX 6.x does not properly check for privileges when the file is in the xfs file system, which allows local users to delete t… | Patch early | 10.0 high | 3.2% | 2000-10-20 |
| CVE-2025-24076 EXP | Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | Patch early | 7.3 high | 3.2% | 2025-03-11 |
| CVE-2008-6937 EXP | Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cau… | Patch early | 10.0 high | 3.2% | 2009-08-11 |
| CVE-2007-1493 EXP | nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, which allows remote attackers to e… | Patch early | 7.5 high | 3.2% | 2007-03-16 |
| CVE-2009-1516 EXP | Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependent… | Patch early | 7.5 high | 3.2% | 2009-05-04 |
| CVE-2021-27885 EXP | usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism. | Patch early | 8.8 high | 3.2% | 2021-03-02 |
| CVE-2006-1031 EXP | config/config_inc.php in iGENUS Webmail 2.02 and earlier allows remote attackers to include arbitrary local files via the SG_HOME parameter. | Patch early | 7.5 high | 3.2% | 2006-03-07 |
| CVE-2018-0749 EXP | The Microsoft Server Message Block (SMB) Server in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and… | Patch early | 7.8 high | 3.2% | 2018-01-04 |
| CVE-2018-17182 EXP | An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An… | Patch early | 7.8 high | 3.2% | 2018-09-19 |
| CVE-2006-3777 EXP | PHP remote file inclusion vulnerability in index.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 3.2% | 2006-07-24 |
| CVE-2007-6378 EXP | Directory traversal vulnerability in upload.dll in BadBlue 2.72b and earlier allows remote attackers to create or overwrite arbitrary files via a .. (… | Patch early | 7.5 high | 3.2% | 2007-12-15 |
| CVE-2007-0633 EXP | PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attackers to execute arbitrary PHP c… | Patch early | 7.5 high | 3.2% | 2007-01-31 |
| CVE-2007-0662 EXP | PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 3.2% | 2007-02-01 |
| CVE-2007-0701 EXP | PHP remote file inclusion vulnerability in inc/common.inc.php in Epistemon 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 3.2% | 2007-02-04 |
| CVE-2005-1203 EXP | Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands via the (1… | Patch early | 7.5 high | 3.2% | 2005-05-02 |
| CVE-2006-4285 EXP | PHP remote file inclusion vulnerability in news.php in Fantastic News 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 3.2% | 2006-08-22 |
| CVE-2015-7381 EXP | Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to exec… | Patch early | 7.5 high | 3.2% | 2015-09-28 |
| CVE-2007-2722 EXP | Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instability) via certain invalid string… | Patch early | 7.8 high | 3.2% | 2007-05-16 |
| CVE-2007-2671 EXP | Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in an HREF attribute in an A elem… | Patch early | 7.1 high | 3.2% | 2007-05-14 |
| CVE-1999-0968 EXP | Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges. | Patch early | 7.5 high | 3.2% | 1998-12-26 |
| CVE-2008-7064 EXP | Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5,… | Patch early | 7.5 high | 3.2% | 2009-08-25 |
| CVE-2023-0905 EXP | A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the fi… | Patch early | 7.3 high | 3.2% | 2023-02-18 |
| CVE-2006-5053 EXP | PHP remote file inclusion vulnerability in webnews/template.php in Web-News 1.6.3 and earlier allows remote attackers to execute arbitrary PHP code vi… | Patch early | 7.5 high | 3.2% | 2006-09-28 |
| CVE-2006-5061 EXP | PHP remote file inclusion vulnerability in mcf.php in Advanced-Clan-Script (AVCX) 3.4 and earlier allows remote attackers to execute arbitrary PHP cod… | Patch early | 7.5 high | 3.2% | 2006-09-28 |
| CVE-2006-5304 EXP | PHP remote file inclusion vulnerability in inc/settings.php in IncCMS Core 1.0.0 and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 3.2% | 2006-10-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt