CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,173 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-2205 EXP | PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers… | Patch early | 7.5 high | 3.1% | 2007-04-24 |
| CVE-2020-8495 EXP | In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an attacker with… | Patch early | 7.5 high | 3.1% | 2020-01-30 |
| CVE-2008-0433 EXP | PHP remote file inclusion vulnerability in theme/phpAutoVideo/LightTwoOh/sidebar.php in Agares phpAutoVideo 2.21 and earlier allows remote attackers t… | Patch early | 7.5 high | 3.1% | 2008-01-23 |
| CVE-1999-0382 EXP | The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated p… | Patch early | 7.2 high | 3.1% | 1999-03-12 |
| CVE-2008-5167 EXP | PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals is enabled, allows remote att… | Patch early | 9.3 high | 3.1% | 2008-11-19 |
| CVE-2008-1000 EXP | Directory traversal vulnerability in ContentServer.py in the Wiki Server in Apple Mac OS X 10.5.2 (aka Leopard) allows remote authenticated users to w… | Patch early | 8.5 high | 3.1% | 2008-03-18 |
| CVE-2017-8926 EXP | Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte… | Patch early | 7.8 high | 3.1% | 2017-05-15 |
| CVE-2018-7746 EXP | An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/channel/modifychannel. For example,… | Patch early | 8.8 high | 3.1% | 2018-03-07 |
| CVE-2007-2420 EXP | SQL injection vulnerability in bry.asp in Burak Yilmaz Blog 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Patch early | 7.5 high | 3.1% | 2007-05-02 |
| CVE-2006-6866 EXP | STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usern… | Patch early | 7.8 high | 3.1% | 2006-12-31 |
| CVE-2001-0329 EXP | Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_… | Patch early | 7.5 high | 3.1% | 2001-06-27 |
| CVE-1999-0836 EXP | UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack. | Patch early | 10.0 high | 3.1% | 1998-12-02 |
| CVE-2007-0828 EXP | PHP remote file inclusion vulnerability in affichearticles.php3 in MySQLNewsEngine allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 3.1% | 2007-02-07 |
| CVE-2007-0508 EXP | PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitrary PHP code via a URL in the B… | Patch early | 7.5 high | 3.1% | 2007-01-26 |
| CVE-2008-7047 EXP | NatterChat 1.1 allows remote attackers to bypass authentication and gain administrator privileges to read or delete rooms and messages via a direct re… | Patch early | 7.5 high | 3.1% | 2009-08-24 |
| CVE-2015-7563 EXP | Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticate… | Patch early | 8.8 high | 3.1% | 2017-04-12 |
| CVE-2006-6377 EXP | Uploadscript 1.2 and earlier stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain the ad… | Patch early | 7.5 high | 3.1% | 2006-12-07 |
| CVE-2007-1040 EXP | Directory traversal vulnerability in archives.php in Xpression News (X-News) 1.0.1 allows remote attackers to include arbitrary files or obtain sensit… | Patch early | 7.5 high | 3.1% | 2007-02-21 |
| CVE-2008-6936 EXP | Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cau… | Patch early | 9.3 high | 3.1% | 2009-08-11 |
| CVE-2008-6939 EXP | TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adm cookie t… | Patch early | 7.5 high | 3.1% | 2009-08-12 |
| CVE-2009-4854 EXP | addons/import.php in TalkBack 2.3.14 allows remote attackers to execute arbitrary commands via the result parameter. | Patch early | 7.5 high | 3.1% | 2010-05-07 |
| CVE-2008-1651 EXP | Directory traversal vulnerability in admin/login.php in EasyNews 4.0 allows remote attackers to include and execute arbitrary local files via a .. (do… | Patch early | 7.5 high | 3.1% | 2008-04-02 |
| CVE-2008-3183 EXP | PHP remote file inclusion vulnerability in ktmlpro/includes/ktedit/toolbar.php in gapicms 9.0.2 allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 3.1% | 2008-07-15 |
| CVE-2008-3401 EXP | PHP remote file inclusion vulnerability in hioxRandomAd.php in HIOX Random Ad (HRA) 1.3 allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 3.1% | 2008-07-31 |
| CVE-2008-3402 EXP | Multiple PHP remote file inclusion vulnerabilities in HIOX Browser Statistics (HBS) 2.0 allow remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 3.1% | 2008-07-31 |
| CVE-2005-3926 EXP | Direct static code injection vulnerability in error.php in GuppY 4.5.9 and earlier, when register_globals is disabled, allows remote attackers to exec… | Patch early | 7.5 high | 3.1% | 2005-11-30 |
| CVE-2006-2826 EXP | SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute arbitrary SQL commands via the… | Patch early | 7.5 high | 3.1% | 2006-06-05 |
| CVE-2006-3562 EXP | PHP remote file inclusion vulnerabilities in plume cms 1.0.4 allow remote attackers to execute arbitrary PHP code via a URL in the _PX_config[manager_… | Patch early | 7.5 high | 3.1% | 2006-07-13 |
| CVE-2013-3213 EXP | Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) picklist… | Patch early | 7.5 high | 3.1% | 2014-04-02 |
| CVE-2019-13529 EXP | An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the… | Patch early | 8.8 high | 3.1% | 2019-10-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt