CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,659 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-7278 EXP | SQL injection vulnerability in Naxtech CMS Afroditi 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to default.asp. | Patch early | 7.5 high | 2.6% | 2014-01-08 |
| CVE-2007-3076 EXP | A certain ActiveX control in sasatl.dll in Zenturi ProgramChecker allows remote attackers to download arbitrary files to the client system via the Dow… | Patch early | 7.8 high | 2.6% | 2007-06-06 |
| CVE-2007-6376 EXP | Directory traversal vulnerability in autohtml.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to include and execute arbitrary local files… | Patch early | 7.5 high | 2.6% | 2007-12-15 |
| CVE-2006-4882 EXP | SQL injection vulnerability in Review.asp in Julian Roberts Charon Cart 3 allows remote attackers to execute arbitrary SQL commands via the ProductID… | Patch early | 7.5 high | 2.6% | 2006-09-19 |
| CVE-2006-6545 EXP | PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_errordocs) allows remote attacke… | Patch early | 7.5 high | 2.6% | 2006-12-14 |
| CVE-2006-6560 EXP | PHP remote file inclusion vulnerability in includes/common.php in the mx_modsdb 1.0.0 module for MxBB (aka MX-System) Portal allows remote attackers t… | Patch early | 7.5 high | 2.6% | 2006-12-14 |
| CVE-2006-6615 EXP | PHP remote file inclusion vulnerability in includes/act_constants.php in the Activity Games (mx_act) 0.92 module for mxBB allows remote attackers to e… | Patch early | 7.5 high | 2.6% | 2006-12-18 |
| CVE-2006-6666 EXP | PHP remote file inclusion vulnerability in index.php in VerliAdmin 0.3 and earlier allows remote authenticated users to execute arbitrary PHP code via… | Patch early | 7.5 high | 2.6% | 2006-12-20 |
| CVE-2009-2922 EXP | Absolute path traversal vulnerability in pixaria.image.php in Pixaria Gallery 2.0.0 through 2.3.5 allows remote attackers to read arbitrary files via… | Patch early | 7.8 high | 2.6% | 2009-08-21 |
| CVE-2005-0680 EXP | PHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 2.6% | 2005-03-07 |
| CVE-2005-1312 EXP | PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code via unknown vectors. | Patch early | 7.5 high | 2.6% | 2005-04-24 |
| CVE-2008-0230 EXP | PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 2.6% | 2008-01-11 |
| CVE-2006-6237 EXP | SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remote attackers to execute arbitra… | Patch early | 7.5 high | 2.6% | 2006-12-03 |
| CVE-2008-6269 EXP | Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) ses… | Patch early | 7.5 high | 2.6% | 2009-02-25 |
| CVE-2008-6307 EXP | E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "admin." | Patch early | 7.5 high | 2.6% | 2009-02-26 |
| CVE-2008-6723 EXP | TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLogged cooki… | Patch early | 7.5 high | 2.6% | 2009-04-14 |
| CVE-2008-6743 EXP | RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary valu… | Patch early | 7.5 high | 2.6% | 2009-04-22 |
| CVE-2008-6857 EXP | Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | Patch early | 7.5 high | 2.6% | 2009-07-14 |
| CVE-2008-7007 EXP | Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting the (1) admin_name and (2) admin… | Patch early | 7.5 high | 2.6% | 2009-08-19 |
| CVE-2005-4296 EXP | AppServ Open Project 2.5.3 allows remote attackers to cause a denial of service via a large HTTP request. | Patch early | 7.8 high | 2.6% | 2005-12-16 |
| CVE-2009-3822 EXP | PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat (com_ajaxchat) component 1.0 for Joomla! allows remote attackers to execute arbit… | Patch early | 7.5 high | 2.6% | 2009-10-28 |
| CVE-2008-1402 EXP | MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to cause a (1) denial of service (exception and crash) via a UDP packe… | Patch early | 7.1 high | 2.6% | 2008-03-20 |
| CVE-2017-1000371 EXP | The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocat… | Patch early | 7.8 high | 2.6% | 2017-06-19 |
| CVE-2004-0390 EXP | SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which allows remote attackers to ga… | Patch early | 7.5 high | 2.6% | 2004-12-31 |
| CVE-2005-0494 EXP | The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the… | Patch early | 7.5 high | 2.6% | 2005-02-21 |
| CVE-2006-1013 EXP | PHP remote file include vulnerability in index.php in SMartBlog (aka SMBlog) 1.2 allows remote attackers to include and execute arbitrary PHP files vi… | Patch early | 7.5 high | 2.6% | 2006-03-07 |
| CVE-2018-12254 EXP | router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to a home/requested_user/Sent%20i… | Patch early | 8.8 high | 2.6% | 2018-06-12 |
| CVE-2007-3061 EXP | Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a… | Patch early | 7.8 high | 2.6% | 2007-06-06 |
| CVE-2006-3843 EXP | PHP remote file inclusion vulnerability in com_calendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote attackers to execute arbitrary PH… | Patch early | 7.5 high | 2.6% | 2006-07-25 |
| CVE-2006-4322 EXP | PHP remote file inclusion vulnerability in estateagent.php in the EstateAgent component (com_estateagent) for Mambo, when register_globals is enabled,… | Patch early | 7.5 high | 2.6% | 2006-08-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt