CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,429 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-16065 EXP | A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows an attacker to execute SQL comm… | Patch early | 8.8 high | 2.8% | 2020-03-19 |
| CVE-2008-5497 EXP | BandSite CMS 1.1.4 allows remote attackers to bypass authentication and gain administrative access by setting the login_auth cookie to true. | Patch early | 7.5 high | 2.8% | 2008-12-12 |
| CVE-2007-5752 EXP | adduser.php in PHP-AGTC Membership (AGTC-Membership) System 1.1a does not require authentication, which allows remote attackers to create accounts via… | Patch early | 7.5 high | 2.8% | 2007-10-31 |
| CVE-2010-2005 EXP | Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitrary PHP code via a URL in (1)… | Patch early | 7.5 high | 2.8% | 2010-05-20 |
| CVE-2007-2934 EXP | Directory traversal vulnerability in skins/common.css.php in Vistered Little 1.6a allows remote attackers to read arbitrary files via a .. (dot dot) i… | Patch early | 7.8 high | 2.8% | 2007-05-31 |
| CVE-2013-3525 EXP | SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the… | Patch early | 7.5 high | 2.8% | 2013-05-10 |
| CVE-2004-2053 EXP | PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitrary PHP code via the site param… | Patch early | 7.5 high | 2.8% | 2004-07-24 |
| CVE-2006-2818 EXP | PHP remote file inclusion vulnerability in common-menu.php in Cameron McKay Informium 0.12.0 allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 2.8% | 2006-06-05 |
| CVE-2006-2888 EXP | PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 2.8% | 2006-06-07 |
| CVE-2006-3375 EXP | PHP remote file inclusion vulnerability in includes/header.inc.php in Randshop 1.1.1 allows remote attackers to execute arbitrary PHP code via the dat… | Patch early | 7.5 high | 2.8% | 2006-07-06 |
| CVE-2006-3998 EXP | PHP remote file inclusion vulnerability in conf.php in WoWRoster (aka World of Warcraft Roster) 1.5.1 and earlier allows remote attackers to execute a… | Patch early | 7.5 high | 2.8% | 2006-08-05 |
| CVE-2006-4363 EXP | PHP remote file inclusion vulnerability in admin.cropcanvas.php in the CropImage component (com_cropimage) 1.0 for Mambo allows remote attackers to ex… | Patch early | 7.5 high | 2.8% | 2006-08-27 |
| CVE-2006-4545 EXP | PHP remote file inclusion vulnerability in ModuleBased CMS Pre-Alpha allows remote attackers to execute arbitrary PHP code via the _SERVER parameter i… | Patch early | 7.5 high | 2.8% | 2006-09-06 |
| CVE-2018-0882 EXP | The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerabi… | Patch early | 7.0 high | 2.8% | 2018-03-14 |
| CVE-2008-0845 EXP | SQL injection vulnerability in wp-people-popup.php in Dean Logan WP-People plugin 1.6.1 for WordPress allows remote attackers to execute arbitrary SQL… | Patch early | 7.5 high | 2.8% | 2008-02-20 |
| CVE-2009-0331 EXP | Directory traversal vulnerability in gallery/comment.php in Enhanced Simple PHP Gallery (ESPG) 1.72 allows remote attackers to read arbitrary files vi… | Patch early | 7.8 high | 2.8% | 2009-01-29 |
| CVE-2007-2664 EXP | PHP remote file inclusion vulnerability in includes/common.php in Yaap 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 2.8% | 2007-05-14 |
| CVE-2008-2228 EXP | PHP remote file inclusion vulnerability in portfolio/commentaires/derniers_commentaires.php in Cyberfolio 7.12, when register_globals is enabled, allo… | Patch early | 9.3 high | 2.8% | 2008-05-14 |
| CVE-2009-1582 EXP | Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended rest… | Patch early | 7.5 high | 2.8% | 2009-05-07 |
| CVE-2016-6772 EXP | An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbitrary code within the context of a privileg… | Patch early | 7.8 high | 2.8% | 2017-01-12 |
| CVE-2007-1818 EXP | PHP remote file inclusion vulnerability in MOD_forum_fields_parse.php in the Forum picture and META tags 1.7 module for phpBB allows remote attackers… | Patch early | 7.5 high | 2.8% | 2007-04-02 |
| CVE-2008-7040 EXP | SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remote attackers to execute arbitr… | Patch early | 7.5 high | 2.8% | 2009-08-24 |
| CVE-2009-2383 EXP | SQL injection vulnerability in BTE_RW_webajax.php in the Related Sites plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL comma… | Patch early | 7.5 high | 2.8% | 2009-07-08 |
| CVE-2009-4424 EXP | SQL injection vulnerability in results.php in the Pyrmont plugin 2 for WordPress allows remote attackers to execute arbitrary SQL commands via the id… | Patch early | 7.5 high | 2.8% | 2009-12-28 |
| CVE-2009-4748 EXP | SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows remote attackers to execute ar… | Patch early | 7.5 high | 2.8% | 2010-03-26 |
| CVE-2004-2745 EXP | Directory traversal vulnerability in Anteco Visual Technologies OwnServer 1.0 and earlier allows remote attackers to read arbitrary files via a .. (do… | Patch early | 7.8 high | 2.8% | 2004-12-31 |
| CVE-2004-2067 EXP | SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL a… | Patch early | 7.5 high | 2.8% | 2004-07-29 |
| CVE-2024-48827 EXP | An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the Change Password function. | Patch early | 8.8 high | 2.8% | 2024-10-11 |
| CVE-2006-0852 EXP | Direct static code injection vulnerability in write.php in Admbook 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via the X-F… | Patch early | 7.5 high | 2.8% | 2006-02-23 |
| CVE-2013-0699 EXP | The Galil RIO-47100 Pocket PLC allows remote attackers to cause a denial of service via a session that includes "repeated requests." | Patch early | 7.1 high | 2.8% | 2013-05-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt