CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,413 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-6157 EXP | SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent attackers to obtain sensitive in… | Patch early | 7.5 high | 3% | 2009-02-17 |
| CVE-2004-0070 EXP | PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link param… | Patch early | 7.5 high | 3% | 2004-02-17 |
| CVE-2005-0800 EXP | PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying th… | Patch early | 7.5 high | 3% | 2005-05-02 |
| CVE-2009-3362 EXP | PHP remote file inclusion vulnerability in printnews.php3 in SZNews 2.7 allows remote attackers to execute arbitrary PHP code via a URL in the id para… | Patch early | 7.5 high | 3% | 2009-09-24 |
| CVE-2007-1636 EXP | Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in… | Patch early | 7.5 high | 3% | 2007-03-23 |
| CVE-2006-4779 EXP | PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attackers to exe… | Patch early | 7.5 high | 2.9% | 2006-09-14 |
| CVE-2006-5032 EXP | PHP remote file inclusion vulnerability in dix.php3 in PHPartenaire 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the url_php… | Patch early | 7.5 high | 2.9% | 2006-09-27 |
| CVE-2006-5181 EXP | Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 2.9% | 2006-10-10 |
| CVE-2006-5283 EXP | PHP remote file inclusion vulnerability in ftag.php in Minichat 6.0 allows remote attackers to execute arbitrary PHP code via a URL in the mostrar par… | Patch early | 7.5 high | 2.9% | 2006-10-13 |
| CVE-2006-5421 EXP | WSN Forum 1.3.4 and earlier allows remote attackers to execute arbitrary PHP code via a modified pathname in the pathtoconfig parameter that points to… | Patch early | 7.5 high | 2.9% | 2006-10-20 |
| CVE-2006-5471 EXP | PHP remote file inclusion vulnerability in example/lib/grid3.lib.php in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to ex… | Patch early | 7.5 high | 2.9% | 2006-10-24 |
| CVE-2006-5526 EXP | Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40 and earlier, allow remo… | Patch early | 7.5 high | 2.9% | 2006-10-26 |
| CVE-2007-3547 EXP | Directory traversal vulnerability in qti_checkname.php in QuickTicket 1.2 allows remote attackers to include and execute arbitrary local files a .. (d… | Patch early | 7.8 high | 2.9% | 2007-07-03 |
| CVE-2007-4210 EXP | Multiple SQL injection vulnerabilities in module.php in LANAI (la-nai) CMS 1.2.14 allow remote attackers to execute arbitrary SQL commands via (1) the… | Patch early | 7.5 high | 2.9% | 2007-08-08 |
| CVE-2007-6086 EXP | Directory traversal vulnerability in index.php in VigileCMS 1.4 allows remote attackers to include and execute arbitrary local files via directory tra… | Patch early | 9.3 high | 2.9% | 2007-11-22 |
| CVE-2006-4505 EXP | CRLF injection vulnerability in links.php in NX5Linx 1.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting… | Patch early | 7.5 high | 2.9% | 2006-08-31 |
| CVE-2017-0103 EXP | The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 mishandles registry objects… | Patch early | 7.0 high | 2.9% | 2017-03-17 |
| CVE-2011-5286 EXP | SQL injection vulnerability in social-slider-2/ajax.php in the Social Slider plugin before 7.4.2 for WordPress allows remote attackers to execute arbi… | Patch early | 7.5 high | 2.9% | 2015-01-01 |
| CVE-2014-4938 EXP | SQL injection vulnerability in the WP Rss Poster (wp-rss-poster) plugin 1.0.0 for WordPress allows remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 2.9% | 2014-07-11 |
| CVE-2007-1928 EXP | Directory traversal vulnerability in index.php in witshare 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot)… | Patch early | 7.5 high | 2.9% | 2007-04-10 |
| CVE-2018-12114 EXP | Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts. | Patch early | 8.8 high | 2.9% | 2018-06-14 |
| CVE-2008-1118 EXP | Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets… | Patch early | 7.5 high | 2.9% | 2008-03-14 |
| CVE-2008-2863 EXP | Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create or delete arbitrary directori… | Patch early | 7.5 high | 2.9% | 2008-06-25 |
| CVE-2008-3415 EXP | Directory traversal vulnerability in common.php in CMScout 2.05, when .htaccess is not supported, allows remote attackers to include and execute arbit… | Patch early | 7.5 high | 2.9% | 2008-07-31 |
| CVE-2008-2885 EXP | PHP remote file inclusion vulnerability in src/browser/resource/categories/resource_categories_view.php in Open Digital Assets Repository System (ODAR… | Patch early | 9.3 high | 2.9% | 2008-06-27 |
| CVE-2008-4719 EXP | PHP remote file inclusion vulnerability in cms/classes/openengine/filepool.php in openEngine 2.0 beta2, when register_globals is enabled, allows remot… | Patch early | 9.3 high | 2.9% | 2008-10-23 |
| CVE-2009-2040 EXP | admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authentication and create administrative a… | Patch early | 7.5 high | 2.9% | 2009-06-12 |
| CVE-2010-1266 EXP | Multiple PHP remote file inclusion vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 2.9% | 2010-04-06 |
| CVE-2010-4998 EXP | PHP remote file inclusion vulnerability in ardeaCore/lib/core/ardeaInit.php in ardeaCore PHP Framework 2.2 allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 2.9% | 2011-11-02 |
| CVE-2005-3861 EXP | PHP remote file inclusion vulnerability in content.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 2.9% | 2005-11-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt