CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,734 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-6586 EXP | Multiple PHP remote file inclusion vulnerabilities in Vortex Blog (vBlog, aka C12) a0.1_nonfunc allow remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 2.4% | 2006-12-15 |
| CVE-2006-6633 EXP | PHP remote file inclusion vulnerability in include/yapbb_session.php in YapBB 1.2 Beta2 and earlier allows remote attackers to execute arbitrary PHP c… | Patch early | 7.5 high | 2.4% | 2006-12-18 |
| CVE-2006-6635 EXP | PHP remote file inclusion vulnerability in includes/functions.php in JumbaCMS 0.0.1 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 2.4% | 2006-12-18 |
| CVE-2006-6645 EXP | PHP remote file inclusion vulnerability in language/lang_english/lang_admin.php in the Web Links (mx_links) 2.05 and earlier module for mxBB allows re… | Patch early | 7.5 high | 2.4% | 2006-12-20 |
| CVE-2006-6711 EXP | PHP remote file inclusion vulnerability in compteur/mapage.php in Newxooper 0.9.1 allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 7.5 high | 2.4% | 2006-12-23 |
| CVE-2006-6795 EXP | PHP remote file inclusion vulnerability in gallery/displayCategory.php in the My_eGallery 2.5.6 module in myPHPNuke (MPN) allows remote attackers to e… | Patch early | 7.5 high | 2.4% | 2006-12-28 |
| CVE-2006-6809 EXP | Multiple PHP remote file inclusion vulnerabilities in process.php in Vladimir Menshakov buratinable templator (aka bubla) 1.0.0rc2 and earlier allow r… | Patch early | 7.5 high | 2.4% | 2006-12-29 |
| CVE-2006-6823 EXP | PHP remote file inclusion vulnerability in plugins/metasearch/plug.inc.php in Yrch! 1.0 allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 2.4% | 2006-12-29 |
| CVE-2006-6830 EXP | PHP remote file inclusion vulnerability in b2verifauth.php in b2 Blog 0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 2.4% | 2006-12-31 |
| CVE-2001-0263 EXP | Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM command… | Patch early | 7.5 high | 2.4% | 2001-06-18 |
| CVE-2008-1409 EXP | Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include and execute arbitrary local fil… | Patch early | 7.5 high | 2.4% | 2008-03-20 |
| CVE-2008-2782 EXP | Multiple directory traversal vulnerabilities in OtomiGenX 2.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) i… | Patch early | 7.5 high | 2.4% | 2008-06-19 |
| CVE-2008-3593 EXP | Directory traversal vulnerability in index.php in SyzygyCMS 0.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot… | Patch early | 7.5 high | 2.4% | 2008-08-11 |
| CVE-2008-5953 EXP | Directory traversal vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote attackers to includ… | Patch early | 7.5 high | 2.4% | 2009-01-23 |
| CVE-2011-5110 EXP | Multiple SQL injection vulnerabilities in Blogs Manager 1.101 and earlier allow remote attackers to execute arbitrary SQL commands via the SearchField… | Patch early | 7.5 high | 2.4% | 2012-08-23 |
| CVE-2012-5912 EXP | Multiple SQL injection vulnerabilities in PicoPublisher 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) page.… | Patch early | 7.5 high | 2.4% | 2012-11-17 |
| CVE-2009-2642 EXP | index.php in Desi Short URL Script 1.0 allows remote attackers to bypass authentication by setting the logged cookie to 1 and the uid cookie to an int… | Patch early | 7.5 high | 2.4% | 2009-07-28 |
| CVE-2007-1613 EXP | Directory traversal vulnerability in view.php in MPM Chat 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot)… | Patch early | 7.5 high | 2.4% | 2007-03-23 |
| CVE-2019-10847 EXP | Computrols CBAS 18.0.0 allows Cross-Site Request Forgery. | Patch early | 8.8 high | 2.4% | 2019-05-24 |
| CVE-2008-5901 EXP | iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… | Patch early | 7.5 high | 2.4% | 2009-01-12 |
| CVE-2009-2558 EXP | system/message.php in Admin News Tools 2.5 does not properly restrict access, which allows remote attackers to post news messages via a direct request… | Patch early | 7.5 high | 2.4% | 2009-07-21 |
| CVE-2009-4106 EXP | Unrestricted file upload vulnerability in admintools/editpage-2.php in Agoko CMS 0.4 and earlier allows remote attackers to inject and execute arbitra… | Patch early | 7.5 high | 2.4% | 2009-11-29 |
| CVE-2009-4674 EXP | admin/admin.php in Mole Group Sky Hunter Airline Ticket Sale Script and Bus Ticket Script allows remote attackers to change an arbitrary password via… | Patch early | 7.5 high | 2.4% | 2010-03-05 |
| CVE-2014-2347 EXP | Amtelco miSecureMessages (aka MSM) 6.2 does not properly manage sessions, which allows remote authenticated users to obtain sensitive information via… | Patch early | 7.0 high | 2.4% | 2014-05-06 |
| CVE-2024-23733 EXP | The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core_Fix7 allows remote attackers… | Patch early | 7.5 high | 2.4% | 2025-01-29 |
| CVE-2008-5058 EXP | SQL injection vulnerability in siteadmin/loginsucess.php in Pre Simple CMS allows remote attackers to execute arbitrary SQL commands via the user para… | Patch early | 7.5 high | 2.4% | 2008-11-13 |
| CVE-2009-4625 EXP | SQL injection vulnerability in the updateOnePage function in components/com_bfsurvey_pro/controller.php in BF Survey Pro Free (com_bfsurvey_profree) 1… | Patch early | 7.5 high | 2.4% | 2010-01-18 |
| CVE-2006-6790 EXP | Direct static code injection vulnerability in chat/login.php in Ultimate PHP Board (UPB) 2.0b1 and earlier allows remote attackers to inject arbitrary… | Patch early | 7.5 high | 2.4% | 2006-12-28 |
| CVE-2002-1505 EXP | SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the database and possi… | Patch early | 7.5 high | 2.4% | 2003-04-02 |
| CVE-2007-3963 EXP | Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web… | Patch early | 9.3 high | 2.4% | 2007-07-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt