CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,813 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-1325 EXP | Multiple directory traversal vulnerabilities in index.php in Uberghey CMS 0.3.1 allow remote attackers to include and execute arbitrary local files vi… | Patch early | 7.5 high | 2.4% | 2008-03-13 |
| CVE-2004-1622 EXP | SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter. | Patch early | 7.5 high | 2.4% | 2004-10-21 |
| CVE-2005-1011 EXP | SQL injection vulnerability in content.asp in SiteEnable allows remote attackers to execute arbitrary SQL commands via the sortby parameter. | Patch early | 7.5 high | 2.4% | 2005-05-02 |
| CVE-2017-9418 EXP | SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute arbitrary SQL commands via the t… | Patch early | 8.8 high | 2.4% | 2017-06-12 |
| CVE-2009-1066 EXP | SQL injection vulnerability in the referral function in admin/lib/lib_logs.php in Pixie CMS 1.01a allows remote attackers to execute arbitrary SQL com… | Patch early | 7.5 high | 2.4% | 2009-03-26 |
| CVE-2007-1402 EXP | The Rediff Toolbar 2.0 ActiveX control in redifftoolbar.dll allows remote attackers to cause a denial of service via unspecified manipulations, possib… | Patch early | 7.5 high | 2.4% | 2007-03-10 |
| CVE-2008-7153 EXP | SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote attackers to… | Patch early | 7.5 high | 2.4% | 2009-09-02 |
| CVE-2009-3542 EXP | Directory traversal vulnerability in ls.php in LittleSite (aka LS or LittleSite.php) 0.1 allows remote attackers to include and execute arbitrary loca… | Patch early | 7.5 high | 2.4% | 2009-10-02 |
| CVE-2001-1106 EXP | The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which… | Patch early | 7.5 high | 2.4% | 2001-07-25 |
| CVE-2018-18794 EXP | School Event Management System 1.0 allows CSRF via user/controller.php?action=edit. | Patch early | 8.8 high | 2.4% | 2018-11-16 |
| CVE-2018-18797 EXP | School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php. | Patch early | 8.8 high | 2.4% | 2018-11-16 |
| CVE-2018-18799 EXP | School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos. | Patch early | 8.8 high | 2.4% | 2018-11-16 |
| CVE-2007-5307 EXP | ELSEIF CMS Beta 0.6 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter… | Patch early | 7.5 high | 2.4% | 2007-10-09 |
| CVE-2007-5733 EXP | Unrestricted file upload vulnerability in upload/upload.php in Japanese PHP Gallery Hosting, when Open directory mode is enabled, allows remote attack… | Patch early | 7.5 high | 2.4% | 2007-10-30 |
| CVE-2007-5737 EXP | Unrestricted file upload vulnerability in component/upload.jsp in Korean GHBoard allows remote attackers to upload arbitrary files via unspecified vec… | Patch early | 7.5 high | 2.4% | 2007-10-30 |
| CVE-2006-6137 EXP | Multiple PHP remote file inclusion vulnerabilities in Sisfo Kampus 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the (1) exec… | Patch early | 7.5 high | 2.4% | 2006-11-28 |
| CVE-2006-6812 EXP | Multiple PHP remote file inclusion vulnerabilities in myPHPCalendar 10.1 allow remote attackers to execute arbitrary PHP code via a URL in the cal_dir… | Patch early | 7.5 high | 2.4% | 2006-12-29 |
| CVE-2007-0314 EXP | Multiple PHP remote file inclusion vulnerabilities in Article System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE… | Patch early | 7.5 high | 2.4% | 2007-01-18 |
| CVE-2010-5289 EXP | Buffer overflow in the Authenticate method in the INCREDISPOOLERLib.Pop ActiveX control in ImSpoolU.dll in IncrediMail 2.0 allows remote attackers to… | Patch early | 7.5 high | 2.4% | 2013-08-25 |
| CVE-2013-5117 EXP | SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNuke allows remote attackers to… | Patch early | 7.5 high | 2.4% | 2014-03-12 |
| CVE-2008-0850 EXP | Multiple SQL injection vulnerabilities in Dokeos 1.8.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to whoisonlin… | Patch early | 7.5 high | 2.4% | 2008-02-21 |
| CVE-2008-2912 EXP | Multiple PHP remote file inclusion vulnerabilities in Contenido CMS 4.8.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) co… | Patch early | 7.5 high | 2.4% | 2008-06-30 |
| CVE-2001-0520 EXP | Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts within certain… | Patch early | 7.5 high | 2.4% | 2001-08-14 |
| CVE-2001-0521 EXP | Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags wi… | Patch early | 7.5 high | 2.4% | 2001-08-14 |
| CVE-2004-1553 EXP | SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or… | Patch early | 7.5 high | 2.4% | 2004-12-31 |
| CVE-2002-0607 EXP | members.asp in Snitz Forums 2000 version 3.3.03 and earlier allows remote attackers to execute arbitrary code via a SQL injection attack on the parame… | Patch early | 7.5 high | 2.4% | 2002-06-18 |
| CVE-2013-3294 EXP | Multiple SQL injection vulnerabilities in Exponent CMS before 2.2.0 release candidate 1 allow remote attackers to execute arbitrary SQL commands via t… | Patch early | 7.5 high | 2.4% | 2014-02-11 |
| CVE-2014-2211 EXP | SQL injection vulnerability in portal/addtoapplication.php in POSH (aka Posh portal or Portaneo) 3.0 before 3.3.0 allows remote attackers to execute a… | Patch early | 7.5 high | 2.4% | 2014-03-03 |
| CVE-2018-14575 EXP | Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject. | Patch early | 8.8 high | 2.4% | 2019-03-21 |
| CVE-2007-2673 EXP | SQL injection vulnerability in includes/funcs_vendors.php in Censura 1.15.04, and other versions before 1.16.04, allows remote attackers to execute ar… | Patch early | 7.5 high | 2.4% | 2007-05-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt