CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,557 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-3529 EXP | videos.php in PHPDirector 0.21 and earlier allows remote attackers to obtain sensitive information via an empty value of the id[] parameter, which rev… | Patch early | 7.8 high | 2.7% | 2007-07-03 |
| CVE-2011-2944 EXP | SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the userna… | Patch early | 7.5 high | 2.7% | 2014-08-12 |
| CVE-2006-6611 EXP | PHP remote file inclusion vulnerability in interface.php in Barman 0.0.1r3 allows remote attackers to execute arbitrary PHP code via a URL in the base… | Patch early | 7.5 high | 2.7% | 2006-12-18 |
| CVE-2006-6612 EXP | PHP remote file inclusion vulnerability in basic.inc.php in PhpMyCms 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the basepa… | Patch early | 7.5 high | 2.7% | 2006-12-18 |
| CVE-2003-1314 EXP | PHP remote file inclusion vulnerability in admin/auth.php in EternalMart Guestbook (EMGB) 1.1 allows remote attackers to execute arbitrary PHP code vi… | Patch early | 7.5 high | 2.7% | 2003-12-31 |
| CVE-2014-5140 EXP | The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, whi… | Patch early | 8.8 high | 2.7% | 2020-01-03 |
| CVE-2006-4636 EXP | Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute arbitrary local files via direc… | Patch early | 7.5 high | 2.7% | 2006-09-08 |
| CVE-2006-7069 EXP | PHP remote file inclusion vulnerability in smarty_config.php in Socketwiz Bookmarks 2.0 and earlier allows remote attackers to execute arbitrary PHP c… | Patch early | 7.5 high | 2.7% | 2007-03-02 |
| CVE-2006-7081 EXP | Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code via the Include parameter to (1… | Patch early | 7.5 high | 2.7% | 2007-03-02 |
| CVE-2007-4287 EXP | PHP remote file inclusion vulnerability in fc_functions/fc_example.php in FishCart 3.2 RC2 and earlier allows remote attackers to execute arbitrary PH… | Patch early | 7.5 high | 2.7% | 2007-08-09 |
| CVE-2018-12326 EXP | Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privile… | Patch early | 8.4 high | 2.7% | 2018-06-17 |
| CVE-2004-2032 EXP | Netgear RP114 allows remote attackers to bypass the keyword based URL filtering by requesting a long URL, as demonstrated using a large number of %20… | Patch early | 7.5 high | 2.7% | 2004-05-24 |
| CVE-2005-4155 EXP | registration.PHP in ATutor 1.5.1 pl2 allows remote attackers to execute arbitrary SQL commands via an e-mail address that ends in a NULL character, wh… | Patch early | 7.5 high | 2.7% | 2005-12-11 |
| CVE-2012-5293 EXP | Multiple PHP remote file inclusion vulnerabilities in SAPID CMS 1.2.3 Stable allow remote attackers to execute arbitrary PHP code via a URL in the (1)… | Patch early | 7.5 high | 2.7% | 2012-10-04 |
| CVE-2002-1720 EXP | SQL injection vulnerability in Spooky Login 2.0 through 2.5 allows remote attackers to bypass authentication and gain privileges via the password fiel… | Patch early | 7.5 high | 2.7% | 2002-12-31 |
| CVE-2005-0980 EXP | PHP remote file inclusion vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary PHP code by modifying the… | Patch early | 7.5 high | 2.7% | 2005-05-02 |
| CVE-2006-2116 EXP | planetGallery allows remote attackers to gain administrator privileges via a direct request to admin/gallery_admin.php. | Patch early | 7.5 high | 2.7% | 2006-05-01 |
| CVE-2006-6720 EXP | PHP remote file inclusion vulnerability in admin/index_sitios.php in Azucar CMS 1.3 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 2.7% | 2006-12-23 |
| CVE-2017-14758 EXP | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone t… | Patch early | 8.8 high | 2.7% | 2017-10-03 |
| CVE-2004-1774 EXP | Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users t… | Patch early | 7.2 high | 2.7% | 2004-08-31 |
| CVE-2007-2307 EXP | PHP remote file inclusion vulnerability in engine/engine.inc.php in WebKalk2 1.9.0 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 2.7% | 2007-04-26 |
| CVE-2007-2341 EXP | PHP remote file inclusion vulnerability in suite/index.php in phpBandManager 0.8 allows remote attackers to execute arbitrary PHP code via a URL in th… | Patch early | 7.5 high | 2.7% | 2007-04-27 |
| CVE-2007-2542 EXP | PHP remote file inclusion vulnerability in header.php in workbench survival guide 0.11 allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 2.7% | 2007-05-09 |
| CVE-2017-7358 EXP | In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and… | Patch early | 7.3 high | 2.7% | 2017-04-05 |
| CVE-2019-0555 EXP | An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbox… | Patch early | 7.8 high | 2.7% | 2019-01-08 |
| CVE-2015-6565 EXP | sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial of service (terminal disruptio… | Patch early | 7.2 high | 2.7% | 2015-08-24 |
| CVE-2007-5706 EXP | Absolute path traversal vulnerability in download.php in Jeebles Directory 2.9.60 allows remote attackers to read arbitrary files via a full pathname… | Patch early | 9.3 high | 2.7% | 2007-10-29 |
| CVE-2008-6737 EXP | Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange packet witho… | Patch early | 7.8 high | 2.7% | 2009-04-21 |
| CVE-2006-2179 EXP | Multiple SQL injection vulnerabilities in CyberBuild allow remote attackers to execute arbitrary SQL commands via the (1) SessionID parameter to login… | Patch early | 7.5 high | 2.7% | 2006-05-04 |
| CVE-2006-2214 EXP | Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sessionid paramet… | Patch early | 7.5 high | 2.7% | 2006-05-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt