CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,602 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-2565 EXP | Cdelia Software ImageProcessing allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted BMP file. | Patch early | 7.1 high | 2.6% | 2007-05-09 |
| CVE-2008-4644 EXP | hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For HTTP header. | Patch early | 7.5 high | 2.6% | 2008-10-22 |
| CVE-2002-2019 EXP | PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote attackers to execute arbitrary P… | Patch early | 7.5 high | 2.6% | 2002-12-31 |
| CVE-2008-6099 EXP | PHP remote file inclusion vulnerability in index.php in RPortal 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 2.6% | 2009-02-10 |
| CVE-2019-0881 EXP | An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumeration, aka 'Windows Kernel Elevation of Privilege… | Patch early | 7.8 high | 2.6% | 2019-05-16 |
| CVE-2008-5708 EXP | redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername a… | Patch early | 7.5 high | 2.6% | 2008-12-24 |
| CVE-2009-4806 EXP | admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to rea… | Patch early | 7.5 high | 2.6% | 2010-04-23 |
| CVE-2004-2573 EXP | PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute arbitrary P… | Patch early | 7.5 high | 2.6% | 2004-12-31 |
| CVE-2005-1117 EXP | PHP remote file inclusion vulnerability in index.php in All4WWW-Homepagecreator 1.0a allows remote attackers to execute arbitrary PHP code by modifyin… | Patch early | 7.5 high | 2.6% | 2005-05-02 |
| CVE-2007-5823 EXP | Directory traversal vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to create or overwrite arbitrary files via a .… | Patch early | 7.5 high | 2.6% | 2007-11-05 |
| CVE-2003-1442 EXP | The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain access fro… | Patch early | 7.5 high | 2.6% | 2003-12-31 |
| CVE-2009-3806 EXP | SQL injection vulnerability in feedback_js.php in DedeCMS 5.1 allows remote attackers to execute arbitrary SQL commands via the arcurl parameter. | Patch early | 7.5 high | 2.6% | 2009-10-27 |
| CVE-2014-2008 EXP | SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to execute arbitrary SQL com… | Patch early | 7.5 high | 2.6% | 2014-09-12 |
| CVE-2006-5411 EXP | Unrestricted file upload vulnerability in upload.php for Free Web Publishing System (FreeWPS), possibly 2.11 and earlier, allows remote attackers to u… | Patch early | 7.5 high | 2.6% | 2006-10-20 |
| CVE-2006-4746 EXP | PHP remote file inclusion vulnerability in news/include/customize.php in Web Server Creator 0.1 allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 2.6% | 2006-09-13 |
| CVE-2006-5180 EXP | PHP remote file inclusion vulnerability in include/main.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.42 and earlier allows remote a… | Patch early | 7.5 high | 2.6% | 2006-10-10 |
| CVE-2006-5433 EXP | PHP remote file inclusion vulnerability in modules/guestbook/index.php in ALiCE-CMS 0.1 allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 2.6% | 2006-10-20 |
| CVE-2006-5434 EXP | PHP remote file inclusion vulnerability in p-news.php in P-News 1.16 and 1.17 allows remote attackers to execute arbitrary PHP code via a URL in the p… | Patch early | 7.5 high | 2.6% | 2006-10-20 |
| CVE-2006-5839 EXP | PHP remote file inclusion vulnerability in ad_main.php in PHPAdventure 1.1-Alpha and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 2.6% | 2006-11-10 |
| CVE-2008-2269 EXP | AustinSmoke GasTracker (AS-GasTracker) 1.0.0 allows remote attackers to bypass authentication and gain privileges by setting the gastracker_admin cook… | Patch early | 7.5 high | 2.6% | 2008-05-16 |
| CVE-2008-6092 EXP | phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie. | Patch early | 7.5 high | 2.6% | 2009-02-09 |
| CVE-2009-2231 EXP | MIDAS 1.43 allows remote attackers to bypass authentication and obtain administrative access via an admin account record in a MIDAS cookie. | Patch early | 7.5 high | 2.6% | 2009-06-26 |
| CVE-2009-2233 EXP | The admin interface in AWScripts.com Gallery Search Engine 1.5 allows remote attackers to bypass authentication and gain administrative access by sett… | Patch early | 7.5 high | 2.6% | 2009-06-26 |
| CVE-2015-7865 EXP | nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87… | Patch early | 7.7 high | 2.6% | 2015-11-24 |
| CVE-2006-5615 EXP | PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to execute arbit… | Patch early | 7.5 high | 2.6% | 2006-10-31 |
| CVE-2006-6849 EXP | administration/index.php in Cahier de texte (CDT) 2.2 does not properly exit when authentication fails, which allows remote attackers to perform unaut… | Patch early | 7.5 high | 2.6% | 2006-12-31 |
| CVE-2018-0822 EXP | NTFS in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerabilit… | Patch early | 7.0 high | 2.6% | 2018-02-15 |
| CVE-2018-0823 EXP | The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way t… | Patch early | 7.0 high | 2.6% | 2018-02-15 |
| CVE-2006-5263 EXP | Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to include and execute arbitrary loc… | Patch early | 7.5 high | 2.6% | 2006-10-12 |
| CVE-2009-4546 EXP | globepersonnel_login.asp in Logoshows BBS 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) pb_us… | Patch early | 7.5 high | 2.6% | 2010-01-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt