CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,891 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-1381 EXP | Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by… | Patch early | 7.2 high | 2.3% | 2002-12-23 |
| CVE-2010-3483 EXP | cms_write.php in Primitive CMS 1.0.9 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct r… | Patch early | 7.5 high | 2.3% | 2010-09-22 |
| CVE-2008-7188 EXP | ClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the profile of arbitrary users via a… | Patch early | 7.5 high | 2.3% | 2009-09-09 |
| CVE-2007-6565 EXP | Multiple SQL injection vulnerabilities in Blakord Portal 1.3.A Beta and earlier allow remote attackers to execute arbitrary SQL commands via the id pa… | Patch early | 7.5 high | 2.3% | 2007-12-28 |
| CVE-2018-0821 EXP | AppContainer in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vuln… | Patch early | 7.0 high | 2.3% | 2018-02-15 |
| CVE-2008-1512 EXP | Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers to include… | Patch early | 7.5 high | 2.3% | 2008-03-25 |
| CVE-2008-2895 EXP | Directory traversal vulnerability in index.php in AproxEngine 5.1.0.4 allows remote attackers to include and execute arbitrary local files via a .. (d… | Patch early | 7.5 high | 2.3% | 2008-06-27 |
| CVE-2008-3031 EXP | Directory traversal vulnerability in index.php in Simple PHP Agenda 2.2.4 and earlier allows remote attackers to include and execute arbitrary local f… | Patch early | 7.5 high | 2.3% | 2008-07-07 |
| CVE-2008-5771 EXP | Directory traversal vulnerability in test.php in PHP Weather 2.2.2 allows remote attackers to include and execute arbitrary local files via directory… | Patch early | 7.5 high | 2.3% | 2008-12-30 |
| CVE-2008-5948 EXP | Directory traversal vulnerability in index.php in BNCwi 1.04 and earlier allows remote attackers to include and execute arbitrary local files via a ..… | Patch early | 7.5 high | 2.3% | 2009-01-23 |
| CVE-2008-6224 EXP | Directory traversal vulnerability in visualizza.php in Way Of The Warrior (WOTW) 5.0 and earlier allows remote attackers to read arbitrary files via a… | Patch early | 7.5 high | 2.3% | 2009-02-20 |
| CVE-2008-6673 EXP | asp/bs_login.asp in QuickerSite 1.8.5 does not properly restrict access to administrative functionality, which allows remote attackers to (1) change t… | Patch early | 7.5 high | 2.3% | 2009-04-08 |
| CVE-2007-2287 EXP | PHP remote file inclusion vulnerability in accept.php in comus 2.0 Final allows remote attackers to execute arbitrary PHP code via a URL in the DOCUME… | Patch early | 7.5 high | 2.3% | 2007-04-26 |
| CVE-2007-2288 EXP | PHP remote file inclusion vulnerability in info.php in Doruk100.net doruk100net allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 2.3% | 2007-04-26 |
| CVE-2013-7192 EXP | Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbitrary SQL commands via the (1)… | Patch early | 7.5 high | 2.3% | 2013-12-21 |
| CVE-2006-7146 EXP | PHP remote file inclusion vulnerability in bug.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execut… | Patch early | 7.5 high | 2.3% | 2007-03-07 |
| CVE-2008-1324 EXP | Multiple directory traversal vulnerabilities in index.php in Travelsized CMS 0.4.1 allow remote attackers to include and execute arbitrary local files… | Patch early | 7.5 high | 2.3% | 2008-03-13 |
| CVE-2020-15046 EXP | The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi… | Patch early | 8.8 high | 2.3% | 2020-06-24 |
| CVE-2009-0514 EXP | Multiple directory traversal vulnerabilities in WebFrame 0.76 allow remote attackers to include and execute arbitrary local files via directory traver… | Patch early | 7.5 high | 2.3% | 2009-02-11 |
| CVE-2009-0722 EXP | Directory traversal vulnerability in admin.php in Potato News 1.0.0 allows remote attackers to include and execute arbitrary files via a .. (dot dot)… | Patch early | 7.5 high | 2.3% | 2009-02-24 |
| CVE-2009-1846 EXP | Multiple directory traversal vulnerabilities in SiteX 0.7.4 Build 418 and earlier allow remote attackers to include and execute arbitrary local files… | Patch early | 7.5 high | 2.3% | 2009-06-01 |
| CVE-2012-4993 EXP | torrent_functions.php in RivetTracker 1.03 and earlier does not properly restrict access, which allows remote attackers to have an unspecified impact. | Patch early | 7.5 high | 2.3% | 2012-09-19 |
| CVE-2010-1272 EXP | PHP remote file inclusion vulnerability in includes/tgpinc.php in Gnat-TGP 1.2.20 and earlier allows remote attackers to execute arbitrary PHP code vi… | Patch early | 7.5 high | 2.3% | 2010-04-06 |
| CVE-2010-1337 EXP | Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and other versions, allow remote a… | Patch early | 7.5 high | 2.3% | 2010-04-09 |
| CVE-2010-1360 EXP | Multiple PHP remote file inclusion vulnerabilities in FAQEngine 4.24.00 allow remote attackers to execute arbitrary PHP code via a URL in the path_faq… | Patch early | 7.5 high | 2.3% | 2010-04-13 |
| CVE-2010-3204 EXP | Multiple PHP remote file inclusion vulnerabilities in Pecio CMS 2.0.5 allow remote attackers to execute arbitrary PHP code via a URL in the template p… | Patch early | 7.5 high | 2.3% | 2010-09-03 |
| CVE-2010-3206 EXP | Multiple PHP remote file inclusion vulnerabilities in DiY-CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang param… | Patch early | 7.5 high | 2.3% | 2010-09-03 |
| CVE-2010-3209 EXP | Multiple PHP remote file inclusion vulnerabilities in Seagull 0.6.7 allow remote attackers to execute arbitrary PHP code via a URL in the includeFile… | Patch early | 7.5 high | 2.3% | 2010-09-03 |
| CVE-2010-3210 EXP | Multiple PHP remote file inclusion vulnerabilities in Multi-lingual E-Commerce System 0.2 allow remote attackers to execute arbitrary PHP code via a U… | Patch early | 7.5 high | 2.3% | 2010-09-03 |
| CVE-2010-3419 EXP | Multiple PHP remote file inclusion vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 2.2.3 allow remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 2.3% | 2010-09-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt