CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,226 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-1586 EXP | ZynOS 3.40 allows remote attackers to cause a denial of service (link restart) by sending a request for the name \M via the SMB Mail Slot Protocol. | Patch early | 7.8 high | 3.1% | 2007-03-21 |
| CVE-2007-2149 EXP | Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier stores usernames and unencrypted passwords in (1) classes/vars.php and (2) classes/varstuff.p… | Patch early | 10.0 high | 3.1% | 2007-04-19 |
| CVE-2023-24788 EXP | NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/sales/customer_delivery.php. | Patch early | 8.8 high | 3.1% | 2023-03-23 |
| CVE-2002-0142 EXP | CGI handler in John Roy Pi3Web for Windows 2.0 beta 1 and 2 allows remote attackers to cause a denial of service (crash) via a series of requests whos… | Patch early | 7.5 high | 3.1% | 2002-03-25 |
| CVE-2005-1959 EXP | jammail.pl in jamchen JamMail 1.8 allows remote attackers to execute arbitrary commands via shell metacharacters in the mail parameter. | Patch early | 7.5 high | 3.1% | 2005-06-12 |
| CVE-2007-3284 EXP | corefoundation.dll in Apple Safari 3.0.1 (552.12.2) for Windows allows remote attackers to cause a denial of service (crash) via certain forms that tr… | Patch early | 7.8 high | 3.1% | 2007-06-19 |
| CVE-2020-7991 EXP | Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password. | Patch early | 8.8 high | 3.1% | 2020-01-26 |
| CVE-2007-3636 EXP | Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via unspecifi… | Patch early | 7.5 high | 3.1% | 2007-07-10 |
| CVE-2012-4035 EXP | The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the member_id and new_password pa… | Patch early | 7.5 high | 3.1% | 2012-08-12 |
| CVE-2006-0076 EXP | PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter… | Patch early | 7.5 high | 3.1% | 2006-01-04 |
| CVE-2007-2857 EXP | PHP remote file inclusion vulnerability in sample/xls2mysql in ABC Excel Parser Pro 4.0 allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 3.1% | 2007-05-24 |
| CVE-2002-0931 EXP | Cross-site scripting vulnerabilities in MyHelpDesk 20020509, and possibly other versions, allows remote attackers to execute script as other users via… | Patch early | 7.5 high | 3.1% | 2002-10-04 |
| CVE-2003-0121 EXP | Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field,… | Patch early | 7.5 high | 3.1% | 2003-03-18 |
| CVE-2018-8411 EXP | An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windo… | Patch early | 7.8 high | 3.1% | 2018-10-10 |
| CVE-2005-2483 EXP | Eval injection vulnerability in Karrigell before 2.1.8 allows remote attackers to execute arbitrary Python code via modified arguments to a Karrigell… | Patch early | 7.5 high | 3.1% | 2005-08-07 |
| CVE-2006-0478 EXP | CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files, via a direct request to files… | Patch early | 7.5 high | 3.1% | 2006-01-31 |
| CVE-2008-1327 EXP | Gallarific does not require authentication for (1) users.php and (2) index.php, which allows remote attackers to add and edit tasks via a direct reque… | Patch early | 7.5 high | 3.1% | 2008-03-13 |
| CVE-2008-6364 EXP | SQL injection vulnerability in logon_process.jsp in Ad Server Solutions Banner Exchange Solution Java allows remote attackers to execute arbitrary SQL… | Patch early | 7.5 high | 3.1% | 2009-03-02 |
| CVE-2004-1881 EXP | SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via t… | Patch early | 7.5 high | 3.1% | 2004-12-31 |
| CVE-2007-2726 EXP | BitsCast 0.13.0 allows remote attackers to cause a denial of service (application crash) via an RSS 2.0 feed item with certain invalid strings in a pu… | Patch early | 7.8 high | 3.1% | 2007-05-16 |
| CVE-2007-1626 EXP | PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 9.3 high | 3.1% | 2007-03-23 |
| CVE-2004-2073 EXP | Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modif… | Patch early | 7.2 high | 3.1% | 2004-02-06 |
| CVE-2007-1079 EXP | Stack-based buffer overflow in Rhino Software, Inc. FTP Voyager 14.0.0.3 and earlier allows remote servers to cause a denial of service (crash) via a… | Patch early | 7.8 high | 3.1% | 2007-02-22 |
| CVE-2015-7715 EXP | Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the… | Patch early | 8.8 high | 3.1% | 2017-10-18 |
| CVE-2002-0938 EXP | Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as other web users via the actio… | Patch early | 7.5 high | 3.1% | 2002-10-04 |
| CVE-2018-0880 EXP | The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerabi… | Patch early | 7.0 high | 3.1% | 2018-03-14 |
| CVE-2004-1592 EXP | PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying… | Patch early | 7.5 high | 3.1% | 2004-12-31 |
| CVE-2007-1075 EXP | TurboFTP 5.30 Build 572 allows remote servers to cause a denial of service (CPU consumption) via a response with a large number of newline characters. | Patch early | 7.8 high | 3.1% | 2007-02-22 |
| CVE-2023-1211 EXP | SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2. | Patch early | 7.2 high | 3.1% | 2023-03-07 |
| CVE-2008-1860 EXP | Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Confi… | Patch early | 9.3 high | 3% | 2008-04-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt