CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,707 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-0966 EXP | PHP remote file inclusion vulnerability in cross.php in YABSoft Mega File Hosting 1.2 allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 2.5% | 2009-03-19 |
| CVE-2019-0552 EXP | An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows Server 20… | Patch early | 8.8 high | 2.5% | 2019-01-08 |
| CVE-2007-6184 EXP | Directory traversal vulnerability in index.php in Project Alumni 1.0.9 allows remote attackers to include and execute arbitrary local files via a .. (… | Patch early | 7.5 high | 2.5% | 2007-11-30 |
| CVE-2013-3687 EXP | AirLive POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD, and possibly other camera models use cleartext to store sensitive inf… | Patch early | 7.8 high | 2.5% | 2013-10-11 |
| CVE-2008-6854 EXP | Xigla Software Absolute FAQ Manager.NET 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a c… | Patch early | 7.5 high | 2.5% | 2009-07-14 |
| CVE-2008-6856 EXP | Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a… | Patch early | 7.5 high | 2.5% | 2009-07-14 |
| CVE-2009-1489 EXP | includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by setting the user cookie parameter… | Patch early | 7.5 high | 2.5% | 2009-04-29 |
| CVE-2009-1617 EXP | Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&lvl=1 value for the twLTadmin c… | Patch early | 7.5 high | 2.5% | 2009-05-12 |
| CVE-2009-1618 EXP | Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value… | Patch early | 7.5 high | 2.5% | 2009-05-12 |
| CVE-2009-1619 EXP | Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1. | Patch early | 7.5 high | 2.5% | 2009-05-12 |
| CVE-2006-2570 EXP | PHP remote file inclusion vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS["CLP… | Patch early | 7.5 high | 2.5% | 2006-05-24 |
| CVE-2006-2819 EXP | PHP remote file inclusion vulnerability in Wiki.php in Barnraiser Igloo 0.1.9 and earlier allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 2.5% | 2006-06-05 |
| CVE-2006-3422 EXP | PHP remote file inclusion vulnerability in WonderEdit Pro CMS allows remote attackers to execute arbitrary PHP code via the config[template_path] para… | Patch early | 7.5 high | 2.5% | 2006-07-07 |
| CVE-2006-3478 EXP | PHP remote file inclusion vulnerability in styles/default/global_header.php in MyPHP CMS 0.3 and earlier, when register_globals is enabled, allows rem… | Patch early | 7.5 high | 2.5% | 2006-07-10 |
| CVE-2006-3520 EXP | PHP remote file inclusion vulnerability in skins/advanced/advanced1.php in Sabdrimer Pro 2.2.4, when register_globals is enabled, allows remote attack… | Patch early | 7.5 high | 2.5% | 2006-07-12 |
| CVE-2006-3917 EXP | PHP remote file inclusion vulnerability in inc/gabarits.php in R. Corson PHP Forge 3 beta 2 and earlier allows remote attackers to execute arbitrary P… | Patch early | 7.5 high | 2.5% | 2006-07-28 |
| CVE-2006-3983 EXP | PHP remote file inclusion vulnerability in editprofile.php in php(Reactor) 1.27pl1 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 2.5% | 2006-08-05 |
| CVE-2006-3991 EXP | PHP remote file inclusion vulnerability in index.php in Vlad Vostrykh Voodoo chat 1.0RC1b and earlier allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 2.5% | 2006-08-05 |
| CVE-2006-4123 EXP | PHP remote file inclusion vulnerability in boitenews4/index.php in Boite de News 4.0.1 allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 2.5% | 2006-08-14 |
| CVE-2006-4205 EXP | Multiple PHP remote file inclusion vulnerabilities in WebDynamite ProjectButler 0.8.4 allow remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 2.5% | 2006-08-17 |
| CVE-2006-4237 EXP | PHP remote file inclusion vulnerability in pageheaderdefault.inc.php in Invisionix Roaming System Remote (IRSR) 0.2 and earlier allows remote attacker… | Patch early | 7.5 high | 2.5% | 2006-08-21 |
| CVE-2006-4594 EXP | Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpAtm) 1.21 and earlier allow remote attackers to execute arbitr… | Patch early | 7.5 high | 2.5% | 2006-09-06 |
| CVE-2006-4604 EXP | PHP remote file inclusion vulnerability in LFXlib/access_manager.php in Lanifex Database of Managed Objects (DMO) 2.3 Beta and earlier allows remote a… | Patch early | 7.5 high | 2.5% | 2006-09-07 |
| CVE-2017-0412 EXP | An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context… | Patch early | 7.8 high | 2.5% | 2017-02-08 |
| CVE-2006-5311 EXP | PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in Buzlas 2006-1 Full allows remote attackers to execute arbitrary PHP c… | Patch early | 7.5 high | 2.5% | 2006-10-17 |
| CVE-2008-2821 EXP | Directory traversal vulnerability in the FTP client in Glub Tech Secure FTP before 2.5.16 on Windows allows remote FTP servers to create or overwrite… | Patch early | 9.3 high | 2.5% | 2008-06-23 |
| CVE-2008-5175 EXP | Directory traversal vulnerability in the FTP client in AceFTP Freeware 3.80.3 and AceFTP Pro 3.80.3 allows remote FTP servers to create or overwrite a… | Patch early | 9.3 high | 2.5% | 2008-11-19 |
| CVE-2023-23399 EXP | Microsoft Excel Remote Code Execution Vulnerability | Patch early | 7.8 high | 2.5% | 2023-03-14 |
| CVE-2010-3742 EXP | Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 allow remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 2.5% | 2010-10-05 |
| CVE-2003-1406 EXP | PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_hea… | Patch early | 7.5 high | 2.5% | 2003-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt