CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,534 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-5937 EXP | AyeView 2.20 allows user-assisted attackers to cause a denial of service (memory consumption or application crash) via a bitmap (aka .bmp) file with l… | Patch early | 7.8 high | 2.7% | 2009-01-22 |
| CVE-2008-0490 EXP | SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to execute arbitrary SQL command… | Patch early | 7.5 high | 2.7% | 2008-01-30 |
| CVE-2008-0507 EXP | SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the i… | Patch early | 7.5 high | 2.7% | 2008-01-31 |
| CVE-2007-6237 EXP | cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows… | Patch early | 9.0 high | 2.7% | 2007-12-04 |
| CVE-2009-1647 EXP | Heap-based buffer overflow in popcorn.exe in Ultrafunk Popcorn 1.87 allows remote POP3 servers to cause a denial of service (application crash) via a… | Patch early | 9.3 high | 2.7% | 2009-05-15 |
| CVE-2005-2229 EXP | Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access… | Patch early | 7.5 high | 2.7% | 2005-07-12 |
| CVE-2005-0887 EXP | Eval injection vulnerability in Double Choco Latte before 0.9.4.3 allows remote attackers to execute arbitrary PHP code via the menuAction variable in… | Patch early | 7.5 high | 2.7% | 2005-03-24 |
| CVE-2008-1646 EXP | SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands v… | Patch early | 7.5 high | 2.7% | 2008-04-02 |
| CVE-2009-2122 EXP | SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote attackers to execute arbitrary SQL… | Patch early | 7.5 high | 2.7% | 2009-06-19 |
| CVE-2009-3913 EXP | SQL injection vulnerability in summary.php in Xerox Fiery Webtools allows remote attackers to execute arbitrary SQL commands via the select parameter. | Patch early | 7.5 high | 2.7% | 2009-11-09 |
| CVE-2006-0075 EXP | Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (ma… | Patch early | 7.5 high | 2.7% | 2006-01-04 |
| CVE-2004-1722 EXP | SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule p… | Patch early | 7.5 high | 2.7% | 2004-08-17 |
| CVE-2008-6292 EXP | Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) username_cookie to "admin," (2) right… | Patch early | 7.5 high | 2.7% | 2009-02-26 |
| CVE-2008-6293 EXP | admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie… | Patch early | 7.5 high | 2.7% | 2009-02-26 |
| CVE-2008-6294 EXP | admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie c… | Patch early | 7.5 high | 2.7% | 2009-02-26 |
| CVE-2009-3760 EXP | Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote at… | Patch early | 7.5 high | 2.7% | 2009-10-22 |
| CVE-2006-5764 EXP | PHP remote file inclusion vulnerability in contact.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 2.7% | 2006-11-06 |
| CVE-2007-0307 EXP | PHP remote file inclusion vulnerability in include/common.php in Poplar Gedcom Viewer 2.0 and earlier allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 2.7% | 2007-01-18 |
| CVE-2007-1130 EXP | PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 2.7% | 2007-02-27 |
| CVE-2007-1131 EXP | PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fus… | Patch early | 7.5 high | 2.7% | 2007-02-27 |
| CVE-2007-1219 EXP | PHP remote file inclusion vulnerability in actions/del.php in Admin Phorum 3.3.1a allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 7.5 high | 2.7% | 2007-03-02 |
| CVE-2007-2257 EXP | PHP remote file inclusion vulnerability in subscp.php in Fully Modded phpBB2 allows remote attackers to execute arbitrary PHP code via a URL in the ph… | Patch early | 7.5 high | 2.7% | 2007-04-25 |
| CVE-2017-1000366 EXP | glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially r… | Patch early | 7.8 high | 2.7% | 2017-06-19 |
| CVE-2006-5078 EXP | PHP remote file inclusion vulnerability in view/general.php in Kristian Niemi Polaring 00.04.03 and earlier allows remote attackers to execute arbitra… | Patch early | 7.5 high | 2.7% | 2006-09-29 |
| CVE-2006-5079 EXP | PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 2.7% | 2006-09-29 |
| CVE-2005-1384 EXP | Multiple SQL injection vulnerabilities in phpCoin 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to index… | Patch early | 7.5 high | 2.7% | 2005-05-03 |
| CVE-2015-8356 EXP | Multiple SQL injection vulnerabilities in the mcart.xls module 6.5.2 and earlier for Bitrix allow remote authenticated users to execute arbitrary SQL… | Patch early | 8.0 high | 2.7% | 2017-04-14 |
| CVE-2017-9429 EXP | SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitrary SQL commands via the id par… | Patch early | 8.8 high | 2.7% | 2017-06-13 |
| CVE-2005-3978 EXP | Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition… | Patch early | 7.5 high | 2.7% | 2005-12-03 |
| CVE-2008-1624 EXP | Directory traversal vulnerability in v2demo/page.php in Jshop Server 1.x through 2.x allows remote attackers to include and execute arbitrary local fi… | Patch early | 7.5 high | 2.7% | 2008-04-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt