CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,286 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-0605 EXP | SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute ar… | Patch early | 7.5 high | 3% | 2010-02-11 |
| CVE-2010-1873 EXP | SQL injection vulnerability in the Jvehicles (com_jvehicles) component 1.0, 2.0, and 2.1111 for Joomla! allows remote attackers to execute arbitrary S… | Patch early | 7.5 high | 3% | 2010-05-12 |
| CVE-2008-2282 EXP | admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_admi… | Patch early | 7.5 high | 3% | 2008-05-18 |
| CVE-2009-4747 EXP | PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to e… | Patch early | 7.5 high | 3% | 2010-03-26 |
| CVE-2008-2081 EXP | Directory traversal vulnerability in index.php in Siteman 2.0.x2 allows remote authenticated administrators to include and execute arbitrary local fil… | Patch early | 9.0 high | 3% | 2008-05-05 |
| CVE-2015-7293 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x. | Patch early | 8.8 high | 3% | 2017-09-25 |
| CVE-2019-6282 EXP | ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlse… | Patch early | 8.8 high | 3% | 2019-03-21 |
| CVE-2008-2822 EXP | Multiple directory traversal vulnerabilities in the FTP client in 3D-FTP Client 8.01 (8.0 build 1) allow remote FTP servers to create or overwrite arb… | Patch early | 9.3 high | 3% | 2008-06-23 |
| CVE-2015-2055 EXP | Zhone GPON 2520 with firmware R4.0.2.566b allows remote attackers to cause a denial of service via a long string in the oldpassword parameter. | Patch early | 7.8 high | 3% | 2015-02-23 |
| CVE-2007-5174 EXP | Directory traversal vulnerability in phpinc/news.php in actSite 1.56 allows remote attackers to include and execute arbitrary local files via a .. (do… | Patch early | 7.5 high | 3% | 2007-10-03 |
| CVE-2017-14848 EXP | WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter. | Patch early | 8.8 high | 3% | 2017-10-03 |
| CVE-2009-2395 EXP | SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 3% | 2009-07-09 |
| CVE-2008-1620 EXP | Directory traversal vulnerability in 2X TFTP service (TFTPd.exe) 3.2.0.0 and earlier in 2X ThinClientServer 5.0_sp1-r3497 and earlier allows remote at… | Patch early | 7.5 high | 3% | 2008-04-02 |
| CVE-2008-4749 EXP | Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, all… | Patch early | 9.3 high | 3% | 2008-10-27 |
| CVE-2007-5684 EXP | Multiple directory traversal vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to include and execute arbitrary files via an abso… | Patch early | 7.5 high | 3% | 2007-10-26 |
| CVE-2006-5102 EXP | PHP remote file inclusion vulnerability in include/editfunc.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.42 and earlier allows remo… | Patch early | 7.5 high | 3% | 2006-10-03 |
| CVE-2015-1862 EXP | The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directo… | Patch early | 7.0 high | 3% | 2018-02-09 |
| CVE-2016-9314 EXP | Sensitive Information Disclosure in com.trend.iwss.gui.servlet.ConfigBackup in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.… | Patch early | 7.8 high | 3% | 2017-02-21 |
| CVE-2008-5840 EXP | PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1. | Patch early | 7.5 high | 3% | 2009-01-05 |
| CVE-2009-3962 EXP | The management interface on the 2wire Gateway 1700HG, 1701HG, 1800HW, 2071, 2700HG, and 2701HG-T with software before 5.29.52 allows remote attackers… | Patch early | 7.8 high | 3% | 2009-11-17 |
| CVE-2007-4551 EXP | PHP remote file inclusion vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 7.5 high | 3% | 2007-08-28 |
| CVE-2008-3033 EXP | RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin fu… | Patch early | 9.3 high | 3% | 2008-07-07 |
| CVE-2015-6541 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attacker… | Patch early | 8.8 high | 3% | 2016-04-08 |
| CVE-2013-2645 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities on the TP-LINK WR1043N router with firmware TL-WR1043ND_V1_120405 allow remote attackers to… | Patch early | 9.3 high | 3% | 2014-10-06 |
| CVE-2023-28285 EXP | Microsoft Office Remote Code Execution Vulnerability | Patch early | 7.8 high | 3% | 2023-04-11 |
| CVE-2007-1720 EXP | Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitra… | Patch early | 7.5 high | 3% | 2007-03-28 |
| CVE-2017-8927 EXP | Buffer overflow in Larson VizEx Reader 9.7.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .ti… | Patch early | 7.8 high | 3% | 2017-05-15 |
| CVE-2006-5733 EXP | Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via… | Patch early | 7.5 high | 3% | 2006-11-06 |
| CVE-2008-4141 EXP | Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 3% | 2008-09-24 |
| CVE-2008-4206 EXP | PHP remote file inclusion vulnerability in config.php in Attachmax Dolphin 2.1.0 and earlier, when register_globals is enabled, allows remote attacker… | Patch early | 7.5 high | 3% | 2008-09-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt