CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,413 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-5050 EXP | Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot d… | Patch early | 7.5 high | 3% | 2007-09-24 |
| CVE-2007-5069 EXP | Directory traversal vulnerability in data/compatible.php in the Nuke Mobile Entertainment 1 addon for PHP-Nuke allows remote attackers to include and… | Patch early | 7.5 high | 3% | 2007-09-24 |
| CVE-2004-1693 EXP | PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifying the mo… | Patch early | 7.5 high | 3% | 2004-09-18 |
| CVE-2004-1820 EXP | PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitra… | Patch early | 7.5 high | 3% | 2004-03-15 |
| CVE-2007-2326 EXP | Multiple PHP remote file inclusion vulnerabilities in HYIP Manager Pro allow remote attackers to execute arbitrary PHP code via a URL in the plugin_fi… | Patch early | 7.5 high | 3% | 2007-04-27 |
| CVE-2007-5845 EXP | Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include and execute arbitrary local file… | Patch early | 7.5 high | 3% | 2007-11-06 |
| CVE-2009-4753 EXP | Multiple buffer overflows in the FTP server on the Addonics NAS Adapter NASU2FW41 with loader 1.17 allow remote attackers to cause a denial of service… | Patch early | 7.1 high | 3% | 2010-03-29 |
| CVE-2019-6249 EXP | An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_inf… | Patch early | 8.8 high | 3% | 2019-01-13 |
| CVE-2024-39304 EXP | ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due… | Patch early | 8.8 high | 3% | 2024-07-26 |
| CVE-2013-0135 EXP | Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1)… | Patch early | 7.5 high | 3% | 2013-04-09 |
| CVE-2005-1005 EXP | ProfitCode PayProCart 3.0 allows remote attackers to bypass authentication and gain administrative privileges to the admin control panel, as demonstra… | Patch early | 7.5 high | 3% | 2005-05-02 |
| CVE-2019-6710 EXP | Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF. | Patch early | 8.8 high | 3% | 2019-03-07 |
| CVE-2006-2794 EXP | Hesabim.asp in ASPSitem 2.0 and earlier allows remote attackers to read private messages of other users via a modified id parameter. | Patch early | 7.8 high | 3% | 2006-06-03 |
| CVE-2015-4630 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x bef… | Patch early | 8.0 high | 3% | 2018-10-18 |
| CVE-2007-0389 EXP | Directory traversal vulnerability in ArsDigita Community System (ACS) 3.4.10 and earlier, and ArsDigita Community Education Solution (ACES) 1.1, allow… | Patch early | 7.8 high | 3% | 2007-01-19 |
| CVE-2007-5820 EXP | Directory traversal vulnerability in index.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers to include and execute arbitrary local files… | Patch early | 9.3 high | 3% | 2007-11-05 |
| CVE-2008-4425 EXP | Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to delete arbitrary fil… | Patch early | 8.8 high | 3% | 2008-10-03 |
| CVE-2005-4657 EXP | Ocean12 Calendar Manager Pro 1.01 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to /admin/vie… | Patch early | 7.5 high | 3% | 2005-12-31 |
| CVE-2006-2295 EXP | Directory traversal vulnerability in Dynamic Galerie 1.0 allows remote attackers to access arbitrary files via an absolute path in the pfad parameter… | Patch early | 7.5 high | 3% | 2006-05-10 |
| CVE-2008-1992 EXP | Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3) default_mail_jmail.asp, which… | Patch early | 7.5 high | 3% | 2008-04-27 |
| CVE-2008-6844 EXP | The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and 4.0.1, allows remote att… | Patch early | 7.5 high | 3% | 2009-07-02 |
| CVE-2006-5596 EXP | Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary files via ..\ (dot dot backsla… | Patch early | 7.5 high | 3% | 2006-10-28 |
| CVE-2016-6664 EXP | mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5… | Patch early | 7.0 high | 3% | 2016-12-13 |
| CVE-2004-2746 EXP | SQL injection vulnerability in adminlogin.asp in XTREME ASP Photo Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) us… | Patch early | 7.5 high | 3% | 2004-12-31 |
| CVE-2008-6734 EXP | Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to include and execute arbitrary local… | Patch early | 9.3 high | 3% | 2009-04-21 |
| CVE-2018-19135 EXP | ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions fo… | Patch early | 8.8 high | 3% | 2018-11-11 |
| CVE-2007-6497 EXP | Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp… | Patch early | 7.5 high | 3% | 2007-12-20 |
| CVE-2005-1360 EXP | PHP remote file inclusion vulnerability in error.php in GrayCMS 1.1 allows remote attackers to execute arbitrary PHP code by modifying the path_prefix… | Patch early | 7.5 high | 3% | 2005-05-02 |
| CVE-2010-1894 EXP | The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly handle unspecified exc… | Patch early | 7.2 high | 3% | 2010-08-11 |
| CVE-2009-3042 EXP | SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL co… | Patch early | 7.5 high | 3% | 2009-09-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt