CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,746 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-2534 EXP | Directory traversal vulnerability in admin/admin_frame.php in Phoenix View CMS Pre Alpha2 and earlier allows remote attackers to include and execute a… | Patch early | 7.5 high | 2.4% | 2008-06-03 |
| CVE-2008-5132 EXP | SQL injection vulnerability in inc/ajax/ajax_rating.php in MemHT Portal 4.0.1 allows remote attackers to execute arbitrary SQL commands via the X-Forw… | Patch early | 7.5 high | 2.4% | 2008-11-18 |
| CVE-2008-5993 EXP | Directory traversal vulnerability in image.php in Barcode Generator 1D (barcodegen) 2.0.0 and earlier allows remote attackers to include and execute a… | Patch early | 7.5 high | 2.4% | 2009-01-28 |
| CVE-2009-3064 EXP | Directory traversal vulnerability in debugger/debug_php.php in Ve-EDIT 0.1.4 allows remote attackers to include and execute arbitrary local files via… | Patch early | 7.5 high | 2.4% | 2009-09-03 |
| CVE-2009-3824 EXP | Directory traversal vulnerability in include/processor.php in Greenwood PHP Content Manager 0.3.2 allows remote attackers to include and execute arbit… | Patch early | 7.5 high | 2.4% | 2009-10-28 |
| CVE-2009-4205 EXP | Directory traversal vulnerability in admin.php in Flashlight Free Edition allows remote attackers to include and execute arbitrary local files via a .… | Patch early | 7.5 high | 2.4% | 2009-12-04 |
| CVE-2012-2952 EXP | SQL injection vulnerability in add_ons.php in Jaow 2.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the add_ons paramet… | Patch early | 7.5 high | 2.4% | 2012-05-29 |
| CVE-2006-7063 EXP | Directory traversal vulnerability in profile.php in TinyPHPforum 3.6 and earlier allows remote attackers to include and execute arbitrary files via ".… | Patch early | 7.5 high | 2.4% | 2007-02-24 |
| CVE-2008-0137 EXP | PHP remote file inclusion vulnerability in config.inc.php in SNETWORKS PHP CLASSIFIEDS 5.0 allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 2.4% | 2008-01-08 |
| CVE-2001-0425 EXP | AdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the HTTP request, which is insert… | Patch early | 7.5 high | 2.4% | 2001-06-27 |
| CVE-2013-2581 EXP | cgi-bin/firmwareupgrade in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P1… | Patch early | 7.8 high | 2.4% | 2013-10-11 |
| CVE-2016-6187 EXP | The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buffer size, which allows local us… | Patch early | 7.8 high | 2.4% | 2016-08-06 |
| CVE-2015-1476 EXP | Multiple SQL injection vulnerabilities in xlinkerz ecommerceMajor allow remote attackers to execute arbitrary SQL commands via the (1) productbycat pa… | Patch early | 7.5 high | 2.4% | 2015-02-04 |
| CVE-2015-1477 EXP | SQL injection vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to execute arbitrary SQL commands via… | Patch early | 7.5 high | 2.4% | 2015-02-04 |
| CVE-2015-1518 EXP | SQL injection vulnerability in the search_post function in includes/search.php in Redaxscript before 2.3.0 allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 2.4% | 2015-02-11 |
| CVE-2015-2070 EXP | SQL injection vulnerability in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote attackers to execute arbitrary SQL commands via the catId… | Patch early | 7.5 high | 2.4% | 2015-02-24 |
| CVE-2015-2102 EXP | SQL injection vulnerability in view_item.php in ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) allows remote attackers to execute arbitrary SQL commands via t… | Patch early | 7.5 high | 2.4% | 2015-02-27 |
| CVE-2015-2237 EXP | Multiple SQL injection vulnerabilities in Betster (aka PHP Betoffice) 1.0.4 allow remote attackers to execute arbitrary SQL commands via the id parame… | Patch early | 7.5 high | 2.4% | 2015-03-12 |
| CVE-2014-9096 EXP | Multiple SQL injection vulnerabilities in recover.php in Pligg CMS 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the… | Patch early | 7.5 high | 2.4% | 2014-11-26 |
| CVE-2010-2685 EXP | siteadmin/adduser.php in Customer Paradigm PageDirector CMS does not properly restrict access, which allows remote attackers to bypass intended restri… | Patch early | 7.5 high | 2.4% | 2010-07-12 |
| CVE-2009-2331 EXP | Multiple static code injection vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to inject arbitrary PHP code (1) into settings.ph… | Patch early | 7.5 high | 2.4% | 2009-07-05 |
| CVE-2009-2117 EXP | uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a va… | Patch early | 7.5 high | 2.4% | 2009-06-18 |
| CVE-2015-1467 EXP | Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to execute arbitrary SQL commands via… | Patch early | 7.5 high | 2.4% | 2015-02-06 |
| CVE-2012-1047 EXP | Directory traversal vulnerability in the WWWHELP Service (js/html/wwhelp.htm) in Cyberoam Central Console (CCC) 2.00.2 allows remote attackers to incl… | Patch early | 7.5 high | 2.4% | 2012-02-12 |
| CVE-2025-47175 EXP | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | Patch early | 7.8 high | 2.4% | 2025-06-10 |
| CVE-2018-11670 EXP | An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary PHP code via the content param… | Patch early | 8.8 high | 2.4% | 2018-06-01 |
| CVE-2018-11671 EXP | An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php?m=admin&c=access&a=adduserhan… | Patch early | 8.8 high | 2.4% | 2018-06-01 |
| CVE-2009-2313 EXP | Directory traversal vulnerability in index.php in Jinzora Media Jukebox 2.8 and earlier allows remote attackers to include and execute arbitrary local… | Patch early | 7.5 high | 2.4% | 2009-07-02 |
| CVE-2009-4499 EXP | SQL injection vulnerability in the get_history_lastid function in the nodewatcher component in Zabbix Server before 1.6.8 allows remote attackers to e… | Patch early | 7.5 high | 2.4% | 2009-12-31 |
| CVE-2009-1479 EXP | Directory traversal vulnerability in client/desktop/default.htm in Boxalino before 09.05.25-0421 allows remote attackers to read arbitrary files via a… | Patch early | 7.5 high | 2.4% | 2009-10-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt