CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,659 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-7293 EXP | The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to get arbitrary system privileg… | Patch early | 7.8 high | 2.6% | 2017-04-26 |
| CVE-2005-2562 EXP | SQL injection vulnerability in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the l… | Patch early | 7.5 high | 2.6% | 2005-08-16 |
| CVE-2005-3986 EXP | Multiple SQL injection vulnerabilities in Instant Photo Gallery 1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat… | Patch early | 7.5 high | 2.6% | 2005-12-04 |
| CVE-2012-1783 EXP | Tiny Server 1.1.9 and earlier allows remote attackers to cause a denial of service (crash) via a long string in a GET request without an HTTP version… | Patch early | 7.8 high | 2.6% | 2012-03-19 |
| CVE-2010-1301 EXP | SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attackers to execute arbitrary SQL commands via the host_id parameter. | Patch early | 7.5 high | 2.6% | 2010-04-07 |
| CVE-2007-0647 EXP | Format string vulnerability in Help Viewer 3.0.0 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifie… | Patch early | 7.1 high | 2.6% | 2007-02-01 |
| CVE-2009-3703 EXP | Multiple SQL injection vulnerabilities in the WP-Forum plugin before 2.4 for WordPress allow remote attackers to execute arbitrary SQL commands via (1… | Patch early | 7.5 high | 2.6% | 2009-12-18 |
| CVE-2005-2827 EXP | The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify kernel memory and execution flow… | Patch early | 7.2 high | 2.6% | 2005-12-14 |
| CVE-2013-4987 EXP | PineApp Mail-SeCure before 3.70 allows remote authenticated users to gain privileges by leveraging console access and providing shell metacharacters i… | Patch early | 8.5 high | 2.6% | 2013-11-08 |
| CVE-2006-3381 EXP | SturGeoN Upload allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension, then directly accessing the file. NO… | Patch early | 7.5 high | 2.6% | 2006-07-06 |
| CVE-2006-7152 EXP | default.asp in ASP-Nuke Community 1.5 and earlier allows remote attackers to gain privileges by setting certain pseudo cookie values. | Patch early | 8.5 high | 2.6% | 2007-03-07 |
| CVE-2006-0583 EXP | SQL injection vulnerability in mailarticle.php in Clever Copy 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ID par… | Patch early | 7.5 high | 2.6% | 2006-02-08 |
| CVE-2005-3325 EXP | Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry_main.php… | Patch early | 7.5 high | 2.6% | 2005-10-27 |
| CVE-2005-3727 EXP | SQL injection vulnerability in debug/query_results.jsp in Idetix Software Systems Revize CMS allows remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 2.6% | 2005-11-21 |
| CVE-2003-1343 EXP | Trend Micro ScanMail for Exchange (SMEX) before 3.81 and before 6.1 might install a back door account in smg_Smxcfg30.exe, which allows remote attacke… | Patch early | 7.5 high | 2.6% | 2003-12-31 |
| CVE-2008-6300 EXP | Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass… | Patch early | 7.5 high | 2.6% | 2009-02-26 |
| CVE-2011-3645 EXP | Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.jsp, which… | Patch early | 7.5 high | 2.6% | 2011-09-27 |
| CVE-2002-0440 EXP | Trend Micro InterScan VirusWall HTTP proxy 3.6 with the "Skip scanning if Content-length equals 0" option enabled allows malicious web servers to bypa… | Patch early | 7.5 high | 2.6% | 2002-07-26 |
| CVE-2005-0021 EXP | Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as de… | Patch early | 7.2 high | 2.6% | 2005-05-02 |
| CVE-2007-0703 EXP | PHP remote file inclusion vulnerability in library/StageLoader.php in WebBuilder 2.0 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 2.6% | 2007-02-04 |
| CVE-2007-0704 EXP | PHP remote file inclusion vulnerability in install.php in Somery 0.4.6 allows remote attackers to execute arbitrary PHP code via a URL in the skindir… | Patch early | 7.5 high | 2.6% | 2007-02-04 |
| CVE-2001-0751 EXP | Cisco switches and routers running CBOS 2.3.8 and earlier use predictable TCP Initial Sequence Numbers (ISN), which allows remote attackers to spoof o… | Patch early | 7.5 high | 2.6% | 2001-10-18 |
| CVE-2009-1587 EXP | index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by setting the login_id, group_id, lo… | Patch early | 7.5 high | 2.6% | 2009-05-07 |
| CVE-2009-1638 EXP | Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access by setting the JobCareerAdmin c… | Patch early | 7.5 high | 2.6% | 2009-05-15 |
| CVE-2009-4675 EXP | admin/admin_info/index.php in the Mole Group Gastro Portal (Restaurant Directory) Script does not require administrative authentication, which allows… | Patch early | 7.5 high | 2.6% | 2010-03-05 |
| CVE-2005-0929 EXP | SQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote attackers to execute arbitrary SQL commands via (1) the sl parameter to showmemb… | Patch early | 7.5 high | 2.6% | 2005-05-02 |
| CVE-2008-1868 EXP | admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database ba… | Patch early | 7.5 high | 2.6% | 2008-04-17 |
| CVE-2006-1252 EXP | Eval injection vulnerability in cal.php in Light Weight Calendar (LWC) 1.0 allows remote attackers to execute arbitrary PHP code via the date paramete… | Patch early | 7.5 high | 2.6% | 2006-03-19 |
| CVE-2004-0641 EXP | Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP Initial Sequence Numbers (ISNs)… | Patch early | 7.5 high | 2.6% | 2004-08-05 |
| CVE-2004-1596 EXP | The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as passwords and router settings… | Patch early | 7.5 high | 2.6% | 2004-10-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt