CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,169 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-4329 EXP | Multiple PHP remote file inclusion vulnerabilities in Web News 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_o… | Patch early | 6.8 medium | 7% | 2007-08-14 |
| CVE-1999-0068 EXP | CGI PHP mylog script allows an attacker to read any file on the target server. | Patch early | 7.5 high | 7% | 1997-10-19 |
| CVE-2008-4428 EXP | Unrestricted file upload vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier allows remote attackers to exe… | Patch early | 10.0 high | 7% | 2008-10-03 |
| CVE-2018-9107 EXP | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla!… | Patch early | 8.8 high | 7% | 2018-03-28 |
| CVE-2009-0967 EXP | The FTP server in Serv-U 7.0.0.1 through 7.4.0.1 allows remote authenticated users to cause a denial of service (service hang) via a large number of S… | Patch early | 4.0 medium | 7% | 2009-03-19 |
| CVE-2014-1947 EXP | Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial o… | Patch early | 7.8 high | 7% | 2020-02-17 |
| CVE-2001-0626 EXP | O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request contain… | Patch early | 7.5 high | 7% | 2001-08-22 |
| CVE-2001-0839 EXP | ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers to modify ac… | Patch early | 7.5 high | 7% | 2001-12-06 |
| CVE-2002-0413 EXP | Cross-site scripting vulnerability in ReBB allows remote attackers to execute arbitrary Javascript and steal cookies via an IMG tag whose URL includes… | Patch early | 7.5 high | 7% | 2002-08-12 |
| CVE-2002-1009 EXP | Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web scri… | Patch early | 7.5 high | 7% | 2002-10-04 |
| CVE-2007-6567 EXP | Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to include and execute arbit… | Patch early | 6.4 medium | 7% | 2007-12-28 |
| CVE-2001-1010 EXP | Directory traversal vulnerability in pagecount CGI script in Sambar Server before 5.0 beta 5 allows remote attackers to overwrite arbitrary files via… | Patch early | 5.0 medium | 7% | 2001-07-22 |
| CVE-2005-0436 EXP | Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode p… | Patch early | 7.5 high | 7% | 2005-05-02 |
| CVE-2002-0207 EXP | Buffer overflow in Real Networks RealPlayer 8.0 and earlier allows remote attackers to execute arbitrary code via a header length value that exceeds t… | Patch early | 7.5 high | 7% | 2002-05-16 |
| CVE-2002-2353 EXP | tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests. | Patch early | 6.4 medium | 7% | 2002-12-31 |
| CVE-2006-2735 EXP | PHP remote file inclusion vulnerability in language/lang_english/lang_activity.php in Activity MOD Plus (Amod) 1.1.0, as used with phpBB when register… | Patch early | 5.1 medium | 7% | 2006-06-01 |
| CVE-2006-4963 EXP | Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via a .. (dot… | Patch early | 6.4 medium | 7% | 2006-09-23 |
| CVE-2007-4905 EXP | Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute arbitrary PHP files via the imag… | Patch early | 7.5 high | 7% | 2007-09-17 |
| CVE-2005-1382 EXP | The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter… | Patch early | 5.0 medium | 7% | 2005-05-03 |
| CVE-2008-1647 EXP | The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0, and earlier in ChilkatHttp Ac… | Patch early | 9.3 high | 7% | 2008-04-02 |
| CVE-2007-2936 EXP | Multiple PHP remote file inclusion vulnerabilities in Frequency Clock 0.1b (Beta 0.1) allow remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 7% | 2007-05-31 |
| CVE-2007-2941 EXP | Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 for vBulletin allow remote atta… | Patch early | 7.5 high | 7% | 2007-05-31 |
| CVE-2000-0926 EXP | SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable. | Patch early | 7.5 high | 7% | 2000-12-19 |
| CVE-2002-0589 EXP | PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass an… | Patch early | 7.5 high | 7% | 2002-06-18 |
| CVE-2002-0734 EXP | b2edit.showposts.php in B2 2.0.6pre2 and earlier does not properly load the b2config.php file in some configurations, which allows remote attackers to… | Patch early | 7.5 high | 7% | 2002-08-12 |
| CVE-2013-3614 EXP | Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to obtain access via a brute-force… | Patch early | 9.3 high | 7% | 2013-09-17 |
| CVE-2013-6366 EXP | The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a Runtime.getRuntime().e… | Patch early | 6.5 medium | 7% | 2013-11-04 |
| CVE-2016-7851 EXP | Adobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulnerability could be exploited in… | Patch early | 6.1 medium | 7% | 2016-11-08 |
| CVE-2005-1333 EXP | Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac OS X 10.3.9 allows remote attackers to read arbitra… | Patch early | 5.0 medium | 7% | 2005-05-04 |
| CVE-2017-7018 EXP | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… | Patch early | 8.8 high | 7% | 2017-07-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt