CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,887 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-0488 EXP | Directory traversal vulnerability in tseekdir.cgi in VB Marketing allows remote attackers to include and execute arbitrary local files via directory t… | Patch early | 7.5 high | 2.3% | 2008-01-30 |
| CVE-2008-1565 EXP | Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module for phpBB allows remote attackers to include and execute arbitrary loca… | Patch early | 7.5 high | 2.3% | 2008-03-31 |
| CVE-2008-7155 EXP | NetRisk 1.9.7 does not properly restrict access to admin/change_submit.php, which allows remote attackers to change the password of arbitrary users vi… | Patch early | 7.5 high | 2.3% | 2009-09-02 |
| CVE-2009-2960 EXP | CuteFlow 2.10.3 and 2.11.0_c does not properly restrict access to pages/edituser.php, which allows remote attackers to modify usernames and passwords… | Patch early | 7.5 high | 2.3% | 2009-08-25 |
| CVE-2000-0244 EXP | The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication. | Patch early | 10.0 high | 2.3% | 2000-03-29 |
| CVE-2010-4851 EXP | Multiple SQL injection vulnerabilities in Eclime 1.1.2b allow remote attackers to execute arbitrary SQL commands via the (1) ref or (2) poll_id parame… | Patch early | 7.5 high | 2.3% | 2011-09-27 |
| CVE-2006-1706 EXP | Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a)… | Patch early | 7.5 high | 2.3% | 2006-04-11 |
| CVE-2006-0135 EXP | SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authent… | Patch early | 7.5 high | 2.3% | 2006-01-09 |
| CVE-2008-6772 EXP | login/register_form.php in YourPlace 1.0.2 and earlier does not check that a username already exists when a new account is created, which allows remot… | Patch early | 7.5 high | 2.3% | 2009-04-29 |
| CVE-2010-4810 EXP | Multiple PHP remote file inclusion vulnerabilities in AR Web Content Manager (AWCM) 2.1 final allow remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 2.3% | 2011-07-08 |
| CVE-2010-4924 EXP | PHP remote file inclusion vulnerability in logic/controller.class.php in clearBudget 0.9.8 allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 2.3% | 2011-10-09 |
| CVE-2013-4879 EXP | SQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to execute arbitrary SQL commands v… | Patch early | 7.5 high | 2.3% | 2013-08-14 |
| CVE-2006-7104 EXP | PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a component for M… | Patch early | 7.5 high | 2.3% | 2007-03-03 |
| CVE-2008-6189 EXP | SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php,… | Patch early | 7.5 high | 2.3% | 2009-02-19 |
| CVE-2009-0535 EXP | Directory traversal vulnerability in export.php in Thyme 1.3 and earlier, when register_globals is disabled, allows remote attackers to read arbitrary… | Patch early | 7.5 high | 2.3% | 2009-02-11 |
| CVE-2009-4974 EXP | Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly have unspecifie… | Patch early | 7.5 high | 2.3% | 2010-07-28 |
| CVE-2006-4867 EXP | SQL injection vulnerability in mods.php in GNUTurk 2G and earlier allows remote attackers to execute arbitrary SQL commands via the t_id parameter whe… | Patch early | 7.5 high | 2.3% | 2006-09-19 |
| CVE-2006-4906 EXP | SQL injection vulnerability in modules/calendar/week.php in More.groupware 0.74 allows remote attackers to execute arbitrary SQL commands via the new_… | Patch early | 7.5 high | 2.3% | 2006-09-21 |
| CVE-2010-5056 EXP | SQL injection vulnerability in the GBU Facebook (com_gbufacebook) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL command… | Patch early | 7.5 high | 2.3% | 2011-11-23 |
| CVE-2010-5057 EXP | SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the tipodoc_id param… | Patch early | 7.5 high | 2.3% | 2011-11-23 |
| CVE-2010-5062 EXP | SQL injection vulnerability in search.php in MH Products kleinanzeigenmarkt allows remote attackers to execute arbitrary SQL commands via the c parame… | Patch early | 7.5 high | 2.3% | 2011-11-23 |
| CVE-2018-11442 EXP | A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= URI, as demonstrated by adding… | Patch early | 8.8 high | 2.3% | 2018-05-25 |
| CVE-2018-11445 EXP | A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing 1.0. A User can be added with… | Patch early | 8.8 high | 2.3% | 2018-05-25 |
| CVE-2010-0680 EXP | Directory traversal vulnerability in index.php in ZeusCMS 0.2 allows remote attackers to include and execute arbitrary local files via directory trave… | Patch early | 7.5 high | 2.3% | 2010-02-22 |
| CVE-2008-0390 EXP | stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into online.db.txt via the X-Forwa… | Patch early | 7.5 high | 2.3% | 2008-01-23 |
| CVE-2009-4231 EXP | Directory traversal vulnerability in as/lib/plugins.php in SweetRice 0.5.3 and earlier allows remote attackers to include and execute arbitrary local… | Patch early | 7.5 high | 2.3% | 2009-12-08 |
| CVE-2006-3964 EXP | PHP remote file inclusion vulnerability in members.php in Banex PHP MySQL Banner Exchange 2.21 allows remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 2.3% | 2006-08-01 |
| CVE-2007-0758 EXP | PHP remote file inclusion vulnerability in lang.php in PHPProbid 5.24 allows remote attackers to execute arbitrary PHP code via a URL in the SRC attri… | Patch early | 7.5 high | 2.3% | 2007-02-06 |
| CVE-2007-1430 EXP | PHP remote file inclusion vulnerability in include/adodb-connection.inc.php in ClipShare 1.5.3 allows remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 2.3% | 2007-03-13 |
| CVE-2009-1411 EXP | SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 allows remote attackers to execute arbitrary SQL com… | Patch early | 7.5 high | 2.3% | 2009-04-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt