CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,415 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-3082 EXP | Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to include and execute arbitrary local files v… | Patch early | 7.8 high | 2.9% | 2007-06-06 |
| CVE-2018-9926 EXP | An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=core&f=power&v=add. | Patch early | 8.8 high | 2.9% | 2018-04-10 |
| CVE-2006-5624 EXP | Multiple PHP remote file inclusion vulnerabilities in Multi-Page Comment System (MPCS) 1.0.0 and earlier allow remote attackers to execute arbitrary P… | Patch early | 7.5 high | 2.9% | 2006-10-31 |
| CVE-2008-6544 EXP | Multiple PHP remote file inclusion vulnerabilities in Simple Machines Forum (SMF) 1.1.4 allow remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 2.9% | 2009-03-30 |
| CVE-2012-0809 EXP | Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string se… | Patch early | 7.2 high | 2.9% | 2012-02-01 |
| CVE-2007-2770 EXP | Stack-based buffer overflow in Eudora 7.1 allows user-assisted, remote SMTP servers to execute arbitrary code via a long SMTP reply. NOTE: the user m… | Patch early | 9.3 high | 2.9% | 2007-05-21 |
| CVE-2019-8513 EXP | This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to execute arbitrary shell comman… | Patch early | 7.8 high | 2.9% | 2019-12-18 |
| CVE-2007-4420 EXP | Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw Office Viewer Component 5.1 allows remote at… | Patch early | 9.3 high | 2.9% | 2007-08-18 |
| CVE-2007-4763 EXP | PHP remote file inclusion vulnerability in dbmodules/DB_adodb.class.php in PHP Object Framework (PHPOF) 20040226 and earlier allows remote attackers t… | Patch early | 7.5 high | 2.9% | 2007-09-08 |
| CVE-2008-5968 EXP | Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and execute arbitrary local files… | Patch early | 7.5 high | 2.9% | 2009-01-26 |
| CVE-2012-3859 EXP | Unspecified vulnerability in the WebAdmin Portal in Netsweeper has unknown impact and attack vectors, a different vulnerability than CVE-2012-2446 and… | Patch early | 10.0 high | 2.9% | 2012-07-09 |
| CVE-2004-1847 EXP | News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN parameter in the NEWS_LO… | Patch early | 7.5 high | 2.9% | 2004-03-20 |
| CVE-2001-1344 EXP | WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier… | Patch early | 7.5 high | 2.9% | 2001-06-12 |
| CVE-2008-5199 EXP | PHP remote file inclusion vulnerability in include.php in PHPOutsourcing IdeaBox (aka IdeBox) 1.1 allows remote attackers to execute arbitrary PHP cod… | Patch early | 7.5 high | 2.9% | 2008-11-21 |
| CVE-2012-2601 EXP | SQL injection vulnerability in WrVMwareHostList.asp in Ipswitch WhatsUp Gold 15.02 allows remote attackers to execute arbitrary SQL commands via the s… | Patch early | 7.5 high | 2.9% | 2012-08-15 |
| CVE-2008-6158 EXP | Multiple unspecified vulnerabilities in the admin backend in w3b>cms (aka w3blabor CMS) before 3.2.0 have unknown impact and remote attack vectors. | Patch early | 10.0 high | 2.9% | 2009-02-17 |
| CVE-2017-3558 EXP | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5… | Patch early | 8.5 high | 2.9% | 2017-04-24 |
| CVE-1999-1024 EXP | ip_print procedure in Tcpdump 3.4a allows remote attackers to cause a denial of service via a packet with a zero length header, which causes an infini… | Patch early | 7.5 high | 2.9% | 2001-11-28 |
| CVE-2009-1653 EXP | Directory traversal vulnerability in examples/tbs_us_examples_0view.php in TinyButStrong 3.4.0 allows remote attackers to read arbitrary files via a .… | Patch early | 7.8 high | 2.9% | 2009-05-16 |
| CVE-2006-6757 EXP | Directory traversal vulnerability in index.php in cwmExplorer 1.0 allows remote attackers to read arbitrary files and source code, and obtain sensitiv… | Patch early | 7.8 high | 2.9% | 2006-12-27 |
| CVE-2013-3727 EXP | SQL injection vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users to execute arbitrary SQL commands via the groups[] parame… | Patch early | 7.5 high | 2.9% | 2014-03-13 |
| CVE-2008-6934 EXP | Static code injection vulnerability in Sanus|artificium (aka Sanusart) Free simple guestbook PHP script, when downloaded before 20081111, allows remot… | Patch early | 7.5 high | 2.9% | 2009-08-11 |
| CVE-2008-6231 EXP | Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) ad… | Patch early | 7.5 high | 2.9% | 2009-02-20 |
| CVE-2006-2306 EXP | Cross-site scripting (XSS) vulnerability in moreinfo.asp in EPublisherPro allows remote attackers to inject arbitrary web script or HTML via the title… | Patch early | 9.3 high | 2.9% | 2006-05-11 |
| CVE-2014-2533 EXP | /sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a comma… | Patch early | 7.2 high | 2.9% | 2014-03-18 |
| CVE-2007-3138 EXP | Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to include and execute arbitrary lo… | Patch early | 7.5 high | 2.9% | 2007-06-08 |
| CVE-2007-4008 EXP | Directory traversal vulnerability in custom.php in Entertainment Media Sharing CMS allows remote attackers to include and execute arbitrary local file… | Patch early | 7.5 high | 2.9% | 2007-07-26 |
| CVE-2007-4585 EXP | Directory traversal vulnerability in activateuser.php in 2532|Gigs 1.2.1 allows remote attackers to include and execute arbitrary local files via a ..… | Patch early | 7.5 high | 2.9% | 2007-08-29 |
| CVE-2008-6592 EXP | thumbsup.php in Thumbs-Up 1.12, as used in LightNEasy "no database" (aka flat) and SQLite 1.2.2 and earlier, allows remote attackers to copy, rename,… | Patch early | 7.5 high | 2.9% | 2009-04-03 |
| CVE-2017-6529 EXP | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to session hijacking by guessing the UID parameter. | Patch early | 8.8 high | 2.9% | 2017-03-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt