CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,415 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-1801 EXP | Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arbitrary local files via a .. (d… | Patch early | 7.5 high | 2.9% | 2007-04-02 |
| CVE-2024-0399 EXP | The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, l… | Patch early | 8.1 high | 2.9% | 2024-04-15 |
| CVE-2019-1364 EXP | An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k… | Patch early | 7.8 high | 2.9% | 2019-10-10 |
| CVE-2006-3042 EXP | Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) go_inf… | Patch early | 7.5 high | 2.9% | 2006-06-15 |
| CVE-2006-0214 EXP | Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupl… | Patch early | 7.5 high | 2.9% | 2006-01-15 |
| CVE-2006-6526 EXP | PHP remote file inclusion vulnerability in index.php in Gizzar 03162002 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 2.9% | 2006-12-14 |
| CVE-2006-6546 EXP | PHP remote file inclusion vulnerability in inc/shows.inc.php in cutenews aj-fork (CN:AJ) 167f and earlier allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 2.9% | 2006-12-14 |
| CVE-2006-6553 EXP | PHP remote file inclusion vulnerability in includes/newssuite_constants.php in the NewsSuite 1.03 module for mxBB allows remote attackers to execute a… | Patch early | 7.5 high | 2.9% | 2006-12-14 |
| CVE-2006-6691 EXP | Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to execute arbitrary PHP code vi… | Patch early | 7.5 high | 2.9% | 2006-12-21 |
| CVE-2006-6850 EXP | PHP remote file inclusion vulnerability in include.php in the Roster Module (character_roster) in Shadowed Portal 5.7 allows remote attackers to execu… | Patch early | 7.5 high | 2.9% | 2006-12-31 |
| CVE-2009-1050 EXP | Bloginator 1A allows remote attackers to bypass authentication and gain administrative access by setting the identifyYourself cookie. | Patch early | 7.5 high | 2.9% | 2009-03-24 |
| CVE-2010-3205 EXP | PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the i… | Patch early | 7.5 high | 2.9% | 2010-09-03 |
| CVE-2023-28293 EXP | Windows Kernel Elevation of Privilege Vulnerability | Patch early | 7.8 high | 2.9% | 2023-04-11 |
| CVE-2017-0411 EXP | An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context… | Patch early | 7.8 high | 2.9% | 2017-02-08 |
| CVE-2005-1200 EXP | PHP remote file inclusion vulnerability in main_index.php in AZ Bulletin Board (AZbb) 1.0.07a through 1.0.07c allows remote attackers to execute arbit… | Patch early | 7.5 high | 2.9% | 2005-05-02 |
| CVE-2002-1469 EXP | scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass… | Patch early | 7.5 high | 2.9% | 2003-04-22 |
| CVE-2006-1838 EXP | edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie. | Patch early | 7.5 high | 2.9% | 2006-04-19 |
| CVE-2008-2216 EXP | Unrestricted file upload vulnerability in src/yopy_upload.php in Project-Based Calendaring System (PBCS) 0.7.1 allows remote authenticated users to up… | Patch early | 9.0 high | 2.9% | 2008-05-14 |
| CVE-2007-6311 EXP | SQL injection vulnerability in (1) index.php, and possibly (2) admin/index.php, in Falt4Extreme RC4 10.9.2007 allows remote attackers to execute arbit… | Patch early | 7.5 high | 2.9% | 2007-12-11 |
| CVE-2002-0244 EXP | Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument t… | Patch early | 7.5 high | 2.9% | 2002-05-29 |
| CVE-2008-6232 EXP | Pre Shopping Mall allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid coo… | Patch early | 7.5 high | 2.9% | 2009-02-20 |
| CVE-2007-1633 EXP | Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include… | Patch early | 7.5 high | 2.9% | 2007-03-23 |
| CVE-2006-1363 EXP | images.php in Justin White (aka YTZ) Free Web Publishing System (FreeWPS) 2.11 allows remote attackers to execute arbitrary PHP code by uploading a .p… | Patch early | 7.5 high | 2.9% | 2006-03-23 |
| CVE-2009-1246 EXP | Multiple directory traversal vulnerabilities in Blogplus 1.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in… | Patch early | 7.5 high | 2.9% | 2009-04-06 |
| CVE-2009-0070 EXP | Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (applic… | Patch early | 9.3 high | 2.9% | 2009-01-08 |
| CVE-2008-4499 EXP | Multiple directory traversal vulnerabilities in PHP Web Explorer 0.99b and earlier allow remote attackers to include and execute arbitrary local files… | Patch early | 9.3 high | 2.9% | 2008-10-09 |
| CVE-2018-7216 EXP | Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal allows remote authenticated user… | Patch early | 8.0 high | 2.9% | 2018-02-18 |
| CVE-2008-4244 EXP | Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the usuario and pass cookies to 1. | Patch early | 7.5 high | 2.9% | 2008-09-25 |
| CVE-2013-5917 EXP | SQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL comman… | Patch early | 7.5 high | 2.9% | 2013-09-23 |
| CVE-2007-2155 EXP | Directory traversal vulnerability in template.php in in phpFaber TopSites 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the… | Patch early | 7.8 high | 2.9% | 2007-04-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt