CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,707 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-1496 EXP | Local file inclusion in WebCalendar before 1.2.5. | Patch early | 8.8 high | 2.5% | 2020-01-27 |
| CVE-2003-0395 EXP | Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing th… | Patch early | 7.5 high | 2.5% | 2003-07-02 |
| CVE-2018-10256 EXP | A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL… | Patch early | 8.8 high | 2.5% | 2018-05-01 |
| CVE-2007-0760 EXP | EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an admin/ URL, which allows remote a… | Patch early | 7.5 high | 2.5% | 2007-02-06 |
| CVE-2008-7069 EXP | All Club CMS (ACCMS) 0.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers… | Patch early | 7.5 high | 2.5% | 2009-08-25 |
| CVE-2012-2924 EXP | PHP remote file inclusion vulnerability in admin/setup.inc.php in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary PHP cod… | Patch early | 7.5 high | 2.5% | 2012-05-21 |
| CVE-2008-6775 EXP | HTC Touch Pro and HTC Touch Cruise vCard allows remote attackers to cause denial of service (CPU consumption, SMS consumption, and connectivity loss)… | Patch early | 7.1 high | 2.5% | 2009-05-01 |
| CVE-2012-1934 EXP | SQL injection vulnerability in admin/country/edit.php in Newscoop before 3.5.5 and 4.x before 4 RC4 allows remote attackers to execute arbitrary SQL c… | Patch early | 7.5 high | 2.5% | 2012-08-27 |
| CVE-2008-2682 EXP | _RealmAdmin/login.asp in Realm CMS 2.3 and earlier allows remote attackers to bypass authentication and access admin pages via certain modified cookie… | Patch early | 7.5 high | 2.5% | 2008-06-12 |
| CVE-2008-3454 EXP | JnSHosts PHP Hosting Directory 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the "adm" cookie value t… | Patch early | 7.5 high | 2.5% | 2008-08-04 |
| CVE-2008-3557 EXP | Free Hosting Manager 1.2 and 2.0 allows remote attackers to bypass authentication and gain administrative access by setting both the adminuser and log… | Patch early | 7.5 high | 2.5% | 2008-08-08 |
| CVE-2008-6279 EXP | RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to obtain sensitive information via an invalid PHPSESSID cookie, whi… | Patch early | 7.8 high | 2.5% | 2009-02-25 |
| CVE-2010-3307 EXP | Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 and earlier allow remote attackers to execute ar… | Patch early | 7.5 high | 2.5% | 2010-10-05 |
| CVE-2005-1181 EXP | NOTE: this issue has been disputed by the vendor. PHP remote code injection vulnerability in loader.php for Ariadne CMS 2.4 allows remote attackers t… | Patch early | 7.5 high | 2.5% | 2005-05-02 |
| CVE-2008-1784 EXP | Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2) editu.php, and (3) uidx.php… | Patch early | 7.5 high | 2.5% | 2008-04-15 |
| CVE-2008-6860 EXP | Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a c… | Patch early | 7.5 high | 2.5% | 2009-07-14 |
| CVE-2006-3957 EXP | PHP remote file inclusion vulnerability in payment.php in BosDev BosDates allows remote attackers to execute arbitrary PHP code via a URL in the insPa… | Patch early | 7.5 high | 2.5% | 2006-08-01 |
| CVE-2006-4366 EXP | PHP remote file inclusion vulnerability in index.php in RedBLoG 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the root_path p… | Patch early | 7.5 high | 2.5% | 2006-08-26 |
| CVE-2006-5837 EXP | Static code injection vulnerability in chat_panel.php in the SimpleChat 1.0.0 module for iWare Professional CMS allows remote attackers to inject arbi… | Patch early | 7.5 high | 2.5% | 2006-11-10 |
| CVE-2005-3952 EXP | SQL injection vulnerability in PHP Labs Top Auction allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) type parame… | Patch early | 7.5 high | 2.5% | 2005-12-01 |
| CVE-2006-3517 EXP | PHP remote file inclusion vulnerability in stats.php in RW::Download, when register_globals is enabled, allows remote attackers to execute arbitrary P… | Patch early | 7.5 high | 2.5% | 2006-07-11 |
| CVE-2006-3755 EXP | PHP remote file inclusion vulnerability in Include/editor/class.rich.php in FlushCMS 1.0.0-pre2 and earlier allows remote attackers to execute arbitra… | Patch early | 7.5 high | 2.5% | 2006-07-21 |
| CVE-2006-4678 EXP | PHP remote file inclusion vulnerability in News Evolution 3.0.3 allows remote attackers to execute arbitrary PHP code via the _NE[AbsPath] parameter i… | Patch early | 7.5 high | 2.5% | 2006-09-11 |
| CVE-2007-2672 EXP | SQL injection vulnerability in index.php in PHP Coupon Script 3.0 allows remote attackers to execute arbitrary SQL commands via the bus parameter in a… | Patch early | 7.5 high | 2.5% | 2007-05-14 |
| CVE-2012-5874 EXP | Multiple SQL injection vulnerabilities in the (1) update_whosonline_reg and (2) update_whosonline_guest functions in Elite Bulletin Board before 2.1.2… | Patch early | 7.5 high | 2.5% | 2013-01-12 |
| CVE-2013-2690 EXP | SQL injection vulnerability in index.php in Synchroweb Technology SynConnect 2.0 allows remote attackers to execute arbitrary SQL commands via the log… | Patch early | 7.5 high | 2.5% | 2013-03-28 |
| CVE-2009-2003 EXP | Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative access by setting the (1) c7portal… | Patch early | 7.5 high | 2.5% | 2009-06-08 |
| CVE-2006-0962 EXP | SQL injection vulnerability in vuBB 0.2 allows remote attackers to execute arbitrary SQL commands via the pass parameter in a cookie. | Patch early | 7.5 high | 2.5% | 2006-03-02 |
| CVE-2006-6878 EXP | admin/uploads.php in PHP-Update 2.7 and earlier allows remote attackers to gain privileges by setting the rights[7] parameter to 1 during a login acti… | Patch early | 7.5 high | 2.5% | 2006-12-31 |
| CVE-2007-1932 EXP | Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute arbitrary local files via a ..… | Patch early | 7.5 high | 2.5% | 2007-04-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt