CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,696 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-4591 EXP | Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller Pro 3.25, allow remote attack… | Patch early | 7.5 high | 2.6% | 2006-09-06 |
| CVE-2024-56898 EXP | Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions… | Patch early | 8.8 high | 2.6% | 2025-02-03 |
| CVE-2008-5883 EXP | Absolute path traversal vulnerability in front-end/dir.php in mini-pub 0.3 and earlier allows remote attackers to list arbitrary directories via a ful… | Patch early | 7.8 high | 2.6% | 2009-01-12 |
| CVE-2008-5997 EXP | Absolute path traversal vulnerability in admin/fileKontrola/browser.asp in Omnicom Content Platform (OCP) 2.0 allows remote attackers to list arbitrar… | Patch early | 7.8 high | 2.6% | 2009-01-28 |
| CVE-2008-2882 EXP | upgrade.asp in sHibby sHop 2.2 and earlier does not require administrative authentication, which allows remote attackers to update a file or have unsp… | Patch early | 7.5 high | 2.6% | 2008-06-26 |
| CVE-2008-6516 EXP | Multiple directory traversal vulnerabilities in phpKF-Portal 1.10 allow remote attackers to include arbitrary files via a .. (dot dot) in the (1) tema… | Patch early | 7.5 high | 2.6% | 2009-03-25 |
| CVE-2006-5554 EXP | Directory traversal vulnerability in index.php in Imageview 5 allows remote attackers to read or execute arbitrary local files via a .. (dot dot) in t… | Patch early | 7.5 high | 2.6% | 2006-10-26 |
| CVE-2006-5597 EXP | join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accounts via modified (1) frmMailBo… | Patch early | 7.5 high | 2.6% | 2006-10-28 |
| CVE-2007-1340 EXP | PHP remote file inclusion vulnerability in eintrag.php in Weltennetz News-Letterman 1.1 allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 2.6% | 2007-03-08 |
| CVE-2017-13068 EXP | QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain… | Patch early | 7.5 high | 2.6% | 2017-10-06 |
| CVE-2008-3203 EXP | js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web conte… | Patch early | 7.5 high | 2.6% | 2008-07-17 |
| CVE-2008-5949 EXP | Multiple PHP remote file inclusion vulnerabilities in ccTiddly 1.7.4 and 1.7.6 allow remote attackers to execute arbitrary PHP code via a URL in the c… | Patch early | 7.5 high | 2.6% | 2009-01-23 |
| CVE-2008-6965 EXP | AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called dir… | Patch early | 7.5 high | 2.6% | 2009-08-13 |
| CVE-2018-0982 EXP | An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulner… | Patch early | 7.0 high | 2.6% | 2018-06-14 |
| CVE-2007-4503 EXP | SQL injection vulnerability in index.php in the Nice Talk component (com_nicetalk) 0.9.3 and earlier for Joomla! allows remote attackers to execute ar… | Patch early | 7.5 high | 2.6% | 2007-08-23 |
| CVE-2007-4506 EXP | SQL injection vulnerability in index.php in the NeoRecruit component (com_neorecruit) 1.4 and earlier for Joomla! allows remote attackers to execute a… | Patch early | 7.5 high | 2.6% | 2007-08-23 |
| CVE-2008-6302 EXP | TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_Admin/admi… | Patch early | 7.5 high | 2.6% | 2009-02-26 |
| CVE-2009-2770 EXP | PowerUpload 2.4 allows remote attackers to bypass authentication and gain administrative access via a MIME encoded value of admin for the myadminname… | Patch early | 7.5 high | 2.6% | 2009-08-14 |
| CVE-2005-3259 EXP | Multiple SQL injection vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to execute arbitrary SQL commands and bypass a… | Patch early | 7.5 high | 2.6% | 2005-10-20 |
| CVE-2006-0324 EXP | SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the usernam… | Patch early | 7.5 high | 2.6% | 2006-01-19 |
| CVE-2006-0308 EXP | PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, module for PHP-Nuke allows remote… | Patch early | 7.5 high | 2.6% | 2006-01-19 |
| CVE-2004-1707 EXP | The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library… | Patch early | 7.2 high | 2.6% | 2004-07-30 |
| CVE-2006-4606 EXP | Multiple SQL injection vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to execute arbitrary SQL commands via the (1) id_tem… | Patch early | 7.5 high | 2.6% | 2006-09-07 |
| CVE-2006-5669 EXP | PHP remote file inclusion vulnerability in gestion/savebackup.php in Gepi 1.4.0 and earlier, and possibly other versions before 1.4.4, allows remote a… | Patch early | 7.5 high | 2.6% | 2006-11-03 |
| CVE-2006-6966 EXP | phpGraphy before 0.9.13a does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric para… | Patch early | 7.5 high | 2.6% | 2007-02-04 |
| CVE-2009-0639 EXP | PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 2.6% | 2009-02-18 |
| CVE-2012-5224 EXP | PHP remote file inclusion vulnerability in vb/includes/vba_cmps_include_bottom.php in vBadvanced CMPS 3.2.2 and earlier allows remote attackers to exe… | Patch early | 7.5 high | 2.6% | 2012-10-01 |
| CVE-2014-10029 EXP | SQL injection vulnerability in profile.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to execute arbitrary SQL commands vi… | Patch early | 7.5 high | 2.6% | 2015-01-13 |
| CVE-2014-2303 EXP | Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8 before -s… | Patch early | 7.5 high | 2.6% | 2014-06-13 |
| CVE-2006-6773 EXP | pages/register/register.php in Fishyshoop 0.930 beta allows remote attackers to create arbitrary administrative users by setting the is_admin HTTP POS… | Patch early | 7.5 high | 2.6% | 2006-12-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt