CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,813 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-2255 EXP | Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (… | Patch early | 7.5 high | 2.4% | 2006-05-09 |
| CVE-2007-4456 EXP | SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL co… | Patch early | 7.5 high | 2.4% | 2007-08-21 |
| CVE-2007-6566 EXP | SQL injection vulnerability in post.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary SQL commands v… | Patch early | 7.5 high | 2.4% | 2007-12-28 |
| CVE-2004-0132 EXP | Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote… | Patch early | 7.5 high | 2.4% | 2004-03-03 |
| CVE-2008-5336 EXP | SQL injection vulnerability in index.php in WebStudio CMS allows remote attackers to execute arbitrary SQL commands via the pageid parameter. | Patch early | 7.5 high | 2.4% | 2008-12-05 |
| CVE-2010-4721 EXP | SQL injection vulnerability in news.php in Immo Makler allows remote attackers to execute arbitrary SQL commands via the id parameter. | Patch early | 7.5 high | 2.4% | 2011-02-01 |
| CVE-2019-0943 EXP | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successf… | Patch early | 7.8 high | 2.4% | 2019-06-12 |
| CVE-2008-5571 EXP | SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via th… | Patch early | 7.5 high | 2.4% | 2008-12-15 |
| CVE-2008-6837 EXP | SQL injection vulnerability in Zoph 0.7.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different issue than… | Patch early | 7.5 high | 2.4% | 2009-06-27 |
| CVE-2011-4337 EXP | Static code injection vulnerability in translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to inject arbitr… | Patch early | 7.5 high | 2.4% | 2012-01-29 |
| CVE-2008-0609 EXP | Directory traversal vulnerability in index.php in DivideConcept VHD Web Pack 2.0 allows remote attackers to include and execute arbitrary local files… | Patch early | 7.5 high | 2.4% | 2008-02-06 |
| CVE-2008-2343 EXP | News Manager 2.0 allows remote attackers to bypass restrictions and obtain sensitive information via a direct request to (1) db/connect_str.php and (2… | Patch early | 7.5 high | 2.4% | 2008-05-19 |
| CVE-2008-2353 EXP | Directory traversal vulnerability in admin.php in GNU/Gallery 1.1.1.0 and earlier allows remote attackers to include and execute arbitrary local files… | Patch early | 7.5 high | 2.4% | 2008-05-20 |
| CVE-2008-2993 EXP | Multiple directory traversal vulnerabilities in index.php in FOG Forum 0.8.1 allow remote attackers to include and execute arbitrary local files via a… | Patch early | 7.5 high | 2.4% | 2008-07-03 |
| CVE-2008-4519 EXP | Multiple directory traversal vulnerabilities in Fastpublish CMS 1.9999 d allow remote attackers to include and execute arbitrary local files via a ..… | Patch early | 7.5 high | 2.4% | 2008-10-09 |
| CVE-2001-1127 EXP | Buffer overflow in Progress database 8.3D and 9.1C could allow a local user to execute arbitrary code via (1) _proapsv, (2) _mprosrv, (3) _mprshut, (4… | Patch early | 7.2 high | 2.4% | 2001-10-05 |
| CVE-2009-4465 EXP | DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and config… | Patch early | 7.5 high | 2.4% | 2009-12-30 |
| CVE-2010-5055 EXP | SQL injection vulnerability in index.php in Almnzm 2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Patch early | 7.5 high | 2.4% | 2011-11-23 |
| CVE-2017-9650 EXP | An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and p… | Patch early | 7.8 high | 2.4% | 2017-08-25 |
| CVE-2007-5650 EXP | Directory traversal vulnerability in system.php in ReloadCMS 1.2.7 allows remote attackers to include and execute arbitrary local files via a .. (dot… | Patch early | 7.5 high | 2.4% | 2007-10-23 |
| CVE-2005-4011 EXP | SQL injection vulnerability in calendar.php in Codewalkers ltwCalendar (aka PHP Event Calendar) 4.2, 4.1.3, and earlier allows remote attackers to exe… | Patch early | 7.5 high | 2.4% | 2005-12-05 |
| CVE-2008-2970 EXP | Multiple session fixation vulnerabilities in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allow remote attackers to hijack web ses… | Patch early | 7.5 high | 2.4% | 2008-07-02 |
| CVE-2013-5640 EXP | Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (1) answer_id or (2) question_i… | Patch early | 7.5 high | 2.4% | 2014-04-01 |
| CVE-2010-4980 EXP | SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via the pid p… | Patch early | 7.5 high | 2.4% | 2011-11-01 |
| CVE-2013-3081 EXP | SQL injection vulnerability in the checkEmailFormat function in plugins/jojo_core/classes/Jojo.php in Jojo before 1.2.2 allows remote attackers to exe… | Patch early | 7.5 high | 2.4% | 2014-06-09 |
| CVE-2009-0766 EXP | Directory traversal vulnerability in default.php in Kipper 2.01 allows remote attackers to include and execute arbitrary local files via directory tra… | Patch early | 7.5 high | 2.4% | 2009-03-06 |
| CVE-2015-1372 EXP | SQL injection vulnerability in ferretCMS 1.0.4-alpha allows remote attackers to execute arbitrary SQL commands via the p parameter in an update action… | Patch early | 7.5 high | 2.4% | 2015-01-27 |
| CVE-2008-4667 EXP | Directory traversal vulnerability in rss.php in ArabCMS 2.0 beta 1 allows remote attackers to include and execute arbitrary local files via a .. (dot… | Patch early | 7.5 high | 2.4% | 2008-10-22 |
| CVE-2008-4781 EXP | Directory traversal vulnerability in update.php in MyKtools 2.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot… | Patch early | 7.5 high | 2.4% | 2008-10-29 |
| CVE-2007-6366 EXP | Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter… | Patch early | 7.5 high | 2.4% | 2007-12-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt