CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,108 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-2541 EXP | PHP remote file inclusion vulnerability in includes/ajax_listado.php in Versado CMS 1.07 allows remote attackers to execute arbitrary PHP code via a U… | Patch early | 7.5 high | 3.2% | 2007-05-09 |
| CVE-2007-2544 EXP | PHP remote file inclusion vulnerability in templates/default/tpl_message.php in PHP TopTree BBS 2.0.1a and earlier allows remote attackers to execute… | Patch early | 7.5 high | 3.2% | 2007-05-09 |
| CVE-2007-2709 EXP | PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 3.2% | 2007-05-16 |
| CVE-2008-1982 EXP | SQL injection vulnerability in ss_load.php in the Spreadsheet (wpSS) 0.6 and earlier plugin for WordPress allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 3.2% | 2008-04-27 |
| CVE-2006-5919 EXP | PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2 allows remote attackers to ex… | Patch early | 7.5 high | 3.2% | 2006-11-15 |
| CVE-2009-3576 EXP | Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table… | Patch early | 9.3 high | 3.2% | 2009-11-24 |
| CVE-2008-1492 EXP | Multiple directory traversal vulnerabilities in CoronaMatrix phpAddressBook 2.11 allow remote attackers to include and execute arbitrary local files v… | Patch early | 7.5 high | 3.2% | 2008-03-25 |
| CVE-1999-0947 EXP | AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via shell meta… | Patch early | 7.5 high | 3.2% | 1999-11-02 |
| CVE-1999-1436 EXP | Ray Chan WWW Authorization Gateway 0.1 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "user" parame… | Patch early | 7.5 high | 3.2% | 1998-07-08 |
| CVE-2001-0614 EXP | Carello E-Commerce 1.2.1 and earlier allows a remote attacker to gain additional privileges and execute arbitrary commands via a specially constructed… | Patch early | 7.5 high | 3.2% | 2001-08-22 |
| CVE-2008-3384 EXP | Multiple directory traversal vulnerabilities in help/help.php in Interact Learning Community Environment Interact 2.4.1 allow remote attackers to incl… | Patch early | 7.5 high | 3.2% | 2008-07-30 |
| CVE-2006-5494 EXP | Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allow remote a… | Patch early | 7.5 high | 3.2% | 2006-10-25 |
| CVE-2006-5612 EXP | PHP remote file inclusion vulnerability in aide.php3 (aka aide.php) in GestArt beta 1, when register_globals is enabled, allows remote attackers to ex… | Patch early | 7.5 high | 3.2% | 2006-10-31 |
| CVE-2002-2306 EXP | Sharman Networks KaZaA Media Desktop 1.7.1 allows remote attackers to cause a denial of service (CPU consumption) by sending several large messages. | Patch early | 7.8 high | 3.2% | 2002-12-31 |
| CVE-2018-8208 EXP | An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Brid… | Patch early | 7.0 high | 3.2% | 2018-06-14 |
| CVE-2006-4423 EXP | Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[_… | Patch early | 7.5 high | 3.2% | 2006-08-29 |
| CVE-2019-14328 EXP | The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section. | Patch early | 8.8 high | 3.2% | 2019-07-28 |
| CVE-2006-6150 EXP | PHP remote file inclusion vulnerability in memory/OWLMemoryProperty.php in OWLLib 1.0 allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 3.2% | 2006-11-28 |
| CVE-2008-0546 EXP | Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL comman… | Patch early | 7.5 high | 3.2% | 2008-02-01 |
| CVE-2013-1453 EXP | plugins/system/highlight/highlight.php in Joomla! 3.0.x through 3.0.2 and 2.5.x through 2.5.8 allows attackers to unserialize arbitrary PHP objects to… | Patch early | 7.5 high | 3.1% | 2013-02-13 |
| CVE-2006-0164 EXP | phgstats.inc.php in phgstats before 0.5.1, if register_globals is enabled, allows remote attackers to include arbitrary files and execute arbitrary PH… | Patch early | 7.5 high | 3.1% | 2006-01-11 |
| CVE-2006-0684 EXP | change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, wh… | Patch early | 7.5 high | 3.1% | 2006-02-15 |
| CVE-2003-0004 EXP | Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter. | Patch early | 7.2 high | 3.1% | 2003-02-19 |
| CVE-2007-2094 EXP | PHP remote file inclusion vulnerability in index.php in Anthologia 0.5.2 allows remote attackers to execute arbitrary PHP code via a URL in the ads_fi… | Patch early | 7.5 high | 3.1% | 2007-04-18 |
| CVE-2007-2346 EXP | Multiple PHP remote file inclusion vulnerabilities in PHP-Generics 1.0 beta allow remote attackers to execute arbitrary PHP code via a URL in the _APP… | Patch early | 7.5 high | 3.1% | 2007-04-27 |
| CVE-2009-4752 EXP | PHP remote file inclusion vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 3.1% | 2010-03-26 |
| CVE-2007-2743 EXP | PHP remote file inclusion vulnerability in custom_vars.php in GlossWord 1.8.1 allows remote attackers to execute arbitrary PHP code via a URL in the s… | Patch early | 7.5 high | 3.1% | 2007-05-17 |
| CVE-2007-3160 EXP | PHP remote file inclusion vulnerability in admin/header.php in PHP Real Estate Classifieds Premium Plus allows remote attackers to execute arbitrary P… | Patch early | 7.5 high | 3.1% | 2007-06-11 |
| CVE-2002-1757 EXP | PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for scripts via… | Patch early | 7.5 high | 3.1% | 2002-12-31 |
| CVE-2014-8425 EXP | The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files. | Patch early | 7.8 high | 3.1% | 2014-11-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt