CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,879 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-8295 EXP | SQL injection vulnerability in joblogs.php in Bacula-Web 5.2.10 allows remote attackers to execute arbitrary SQL commands via the jobid parameter. | Patch early | 7.5 high | 2.3% | 2014-10-15 |
| CVE-2014-9095 EXP | Multiple SQL injection vulnerabilities in Raritan Power IQ 4.1.0 and 4.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) sort o… | Patch early | 7.5 high | 2.3% | 2014-11-26 |
| CVE-2014-9345 EXP | SQL injection vulnerability in Guruperl.net Advertise With Pleasure! Professional (aka AWP PRO) 6.6 and earlier allows remote attackers to execute arb… | Patch early | 7.5 high | 2.3% | 2014-12-08 |
| CVE-2014-9348 EXP | SQL injection vulnerability in the formulaireRobot function in admin/robots.lib.php in RobotStats 1.0 allows remote attackers to execute arbitrary SQL… | Patch early | 7.5 high | 2.3% | 2014-12-08 |
| CVE-2014-9440 EXP | SQL injection vulnerability in browse.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL commands via the category parameter. | Patch early | 7.5 high | 2.3% | 2015-01-02 |
| CVE-2006-7107 EXP | PHP remote file inclusion vulnerability in upgrade.php in Coalescent Systems freePBX 2.1.3 allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 2.3% | 2007-03-03 |
| CVE-2018-10312 EXP | index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member. | Patch early | 8.8 high | 2.3% | 2018-04-24 |
| CVE-2018-7176 EXP | FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permi… | Patch early | 8.8 high | 2.3% | 2018-02-16 |
| CVE-2009-0765 EXP | Directory traversal vulnerability in index.php in Kipper 2.01 allows remote attackers to include and execute arbitrary local files via a .. (dot dot)… | Patch early | 7.5 high | 2.3% | 2009-03-06 |
| CVE-2009-1319 EXP | Directory traversal vulnerability in includes/ini.inc.php in GuestCal 2.1 allows remote attackers to include and execute arbitrary files via a .. (dot… | Patch early | 7.5 high | 2.3% | 2009-04-17 |
| CVE-2009-1502 EXP | Directory traversal vulnerability in plugin.php in S-Cms 1.1 Stable and 1.5.2 allows remote attackers to include and execute arbitrary local files via… | Patch early | 7.5 high | 2.3% | 2009-05-01 |
| CVE-2009-1649 EXP | Directory traversal vulnerability in arch.php in beLive 0.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the arch parameter… | Patch early | 7.5 high | 2.3% | 2009-05-16 |
| CVE-2009-1847 EXP | Directory traversal vulnerability in index.php in Easy PX 41 CMS 9.0 B1 allows remote attackers to include and execute arbitrary local files via a ..… | Patch early | 7.5 high | 2.3% | 2009-06-01 |
| CVE-2007-5844 EXP | Directory traversal vulnerability in inc/includes.inc in GuppY 4.6.3 allows remote attackers to include and execute arbitrary local files via a .. (do… | Patch early | 7.5 high | 2.3% | 2007-11-06 |
| CVE-2009-2124 EXP | Directory traversal vulnerability in page.php in Elvin 1.2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) i… | Patch early | 7.5 high | 2.3% | 2009-06-19 |
| CVE-2009-3507 EXP | Directory traversal vulnerability in modules.php in CMSphp 0.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot… | Patch early | 7.5 high | 2.3% | 2009-10-01 |
| CVE-2009-4723 EXP | Directory traversal vulnerability in confirm.php in Netpet CMS 1.9 allows remote attackers to include and execute arbitrary local files via a .. (dot… | Patch early | 7.5 high | 2.3% | 2010-03-18 |
| CVE-2006-7119 EXP | PHP remote file inclusion vulnerability in kernel/system/startup.php in J. He PHPGiggle 12.08 and earlier, as distributed on comscripts.com, allows re… | Patch early | 7.5 high | 2.3% | 2007-03-06 |
| CVE-2024-27620 EXP | An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request to the API. | Patch early | 7.5 high | 2.3% | 2024-04-06 |
| CVE-2009-2305 EXP | The ARD-9808 DVR card security camera allows remote attackers to cause a denial of service via a long URI composed of //.\ (slash slash dot backslash)… | Patch early | 7.8 high | 2.3% | 2009-07-02 |
| CVE-2008-6022 EXP | PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in an older version of Xnova, possibly 0.8 sp1, allows remote attackers to ex… | Patch early | 7.5 high | 2.3% | 2009-02-02 |
| CVE-2008-6023 EXP | PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in a newer version of Xnova, possibly 0.8 sp1, allows remote attackers to exe… | Patch early | 7.5 high | 2.3% | 2009-02-02 |
| CVE-2009-1444 EXP | PHP remote file inclusion vulnerability in indexk.php in WebPortal CMS 0.8-beta allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 2.3% | 2009-04-27 |
| CVE-2009-1452 EXP | Multiple PHP remote file inclusion vulnerabilities in theme/format.php in SMA-DB 0.3.13 allow remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 2.3% | 2009-04-28 |
| CVE-2009-4220 EXP | PHP remote file inclusion vulnerability in includes/classes/pctemplate.php in PointComma 3.8b2 and earlier allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 2.3% | 2009-12-07 |
| CVE-2009-4604 EXP | PHP remote file inclusion vulnerability in mamboleto.php in the Fernando Soares Mamboleto (com_mamboleto) component 2.0 RC3 for Joomla! allows remote… | Patch early | 7.5 high | 2.3% | 2010-01-12 |
| CVE-2014-9528 EXP | SQL injection vulnerability in the actionIndex function in protected/modules_core/notification/controllers/ListController.php in HumHub 0.10.0-rc.1 an… | Patch early | 7.5 high | 2.3% | 2015-01-06 |
| CVE-2009-0458 EXP | Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Ware Support 1.x allow remote attackers to execute arbitrary SQL command… | Patch early | 7.5 high | 2.3% | 2009-02-10 |
| CVE-2007-3136 EXP | PHP remote file inclusion vulnerability in inc/nuke_include.php in newsSync 1.5.0rc6 allows remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 2.3% | 2007-06-08 |
| CVE-2007-3585 EXP | PHP remote file inclusion vulnerability in games.php in MyCMS 0.9.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 2.3% | 2007-07-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt