CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,729 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-3403 EXP | Unrestricted file upload vulnerability in upload.php in dreamLog (aka dreamblog) 0.5 allows remote attackers to upload and execute arbitrary PHP code… | Patch early | 7.5 high | 2.5% | 2007-06-26 |
| CVE-2007-4932 EXP | admin.php in Shop-Script FREE 2.0 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which… | Patch early | 7.5 high | 2.5% | 2007-09-18 |
| CVE-2008-5880 EXP | admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "ok". | Patch early | 7.5 high | 2.5% | 2009-01-08 |
| CVE-2008-6664 EXP | action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies… | Patch early | 7.5 high | 2.5% | 2009-04-08 |
| CVE-2008-6855 EXP | Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a ce… | Patch early | 7.5 high | 2.5% | 2009-07-14 |
| CVE-2008-6858 EXP | Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain valu… | Patch early | 7.5 high | 2.5% | 2009-07-14 |
| CVE-2008-6859 EXP | Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a… | Patch early | 7.5 high | 2.5% | 2009-07-14 |
| CVE-2008-6861 EXP | Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to… | Patch early | 7.5 high | 2.5% | 2009-07-14 |
| CVE-2008-6862 EXP | Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | Patch early | 7.5 high | 2.5% | 2009-07-14 |
| CVE-2008-6863 EXP | Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to… | Patch early | 7.5 high | 2.5% | 2009-07-14 |
| CVE-2008-6864 EXP | Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a… | Patch early | 7.5 high | 2.5% | 2009-07-14 |
| CVE-2008-6919 EXP | profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie… | Patch early | 7.5 high | 2.5% | 2009-08-10 |
| CVE-2008-7051 EXP | AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2)… | Patch early | 7.5 high | 2.5% | 2009-08-24 |
| CVE-2012-4034 EXP | Multiple SQL injection vulnerabilities in PBBoard 2.1.4 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to the… | Patch early | 7.5 high | 2.5% | 2012-08-12 |
| CVE-2007-1082 EXP | FTP Explorer 1.0.1 Build 047, and other versions before 1.0.1.52, allows remote servers to cause a denial of service (CPU consumption) via a long resp… | Patch early | 7.1 high | 2.5% | 2007-02-22 |
| CVE-2008-5322 EXP | Wysi Wiki Wyg 1.0 allows remote attackers to obtain system information via an invalid categup parameter to index.php, which calls the phpinfo function… | Patch early | 7.8 high | 2.5% | 2008-12-03 |
| CVE-2005-0860 EXP | PHP remote file inclusion vulnerability in TRG News Script 3.0 allows remote attackers to execute arbitrary PHP code via the dir parameter to (1) arti… | Patch early | 7.5 high | 2.5% | 2005-05-02 |
| CVE-2007-2942 EXP | SQL injection vulnerability in user.php in My Little Forum 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the id parame… | Patch early | 7.5 high | 2.5% | 2007-05-31 |
| CVE-2007-3052 EXP | SQL injection vulnerability in index.php in the PNphpBB2 1.2i and earlier module for PostNuke allows remote attackers to execute arbitrary SQL command… | Patch early | 7.5 high | 2.5% | 2007-06-06 |
| CVE-2007-4053 EXP | SQL injection vulnerability in include/img_view.class.php in LinPHA 1.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via th… | Patch early | 7.5 high | 2.5% | 2007-07-30 |
| CVE-2006-6838 EXP | Rediff Bol Downloader ActiveX (OCX) control allows remote attackers to execute arbitrary files, and obtain sensitive information (usernames and pathna… | Patch early | 7.5 high | 2.5% | 2006-12-31 |
| CVE-2008-0231 EXP | Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange Cutout, (4) Lonely Maple, (5) E… | Patch early | 7.5 high | 2.5% | 2008-01-11 |
| CVE-2002-0536 EXP | PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database via a SQL… | Patch early | 7.5 high | 2.5% | 2002-07-03 |
| CVE-2018-15884 EXP | RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter. | Patch early | 8.8 high | 2.5% | 2018-08-28 |
| CVE-2008-2520 EXP | Multiple PHP remote file inclusion vulnerabilities in BigACE 2.4, when register_globals is enabled, allow remote attackers to execute arbitrary PHP co… | Patch early | 7.5 high | 2.5% | 2008-06-03 |
| CVE-2013-7193 EXP | Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) pa para… | Patch early | 7.5 high | 2.5% | 2013-12-21 |
| CVE-2008-2348 EXP | MeltingIce File System 1.0 allows remote attackers to bypass application authentication, create new user accounts, and exceed application quotas via a… | Patch early | 7.5 high | 2.5% | 2008-05-20 |
| CVE-2008-3602 EXP | admin/wr_admin.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9.1 allows remote attackers to bypass authentication and gain administrative a… | Patch early | 7.5 high | 2.5% | 2008-08-12 |
| CVE-2008-4341 EXP | add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by setting a cookie with admin=yes… | Patch early | 7.5 high | 2.5% | 2008-09-30 |
| CVE-2008-5594 EXP | Multiple directory traversal vulnerabilities in index.php in Mini Blog 1.0.1 allow remote attackers to include and execute arbitrary local files via a… | Patch early | 7.5 high | 2.5% | 2008-12-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt