CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,922 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-9769 EXP | PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as administrator. | Patch early | 8.8 high | 2.3% | 2019-03-14 |
| CVE-2026-44403 EXP | Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenti… | Patch early | 7.2 high | 2.3% | 2026-05-12 |
| CVE-2006-5209 EXP | PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used in phpBB 2… | Patch early | 7.5 high | 2.3% | 2006-10-10 |
| CVE-2006-6890 EXP | Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remote attackers to download passwo… | Patch early | 7.5 high | 2.3% | 2006-12-31 |
| CVE-2007-4942 EXP | PHP remote file inclusion vulnerability in modules/Discipline/StudentFieldBreakdown.php in Focus/SIS 1.0 allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 2.3% | 2007-09-18 |
| CVE-2007-5567 EXP | PHP remote file inclusion vulnerability in _lib/fckeditor/upload_config.php in Galmeta Post 0.11 allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 2.3% | 2007-10-18 |
| CVE-2008-3575 EXP | PHP remote file inclusion vulnerability in modules/calendar/minicalendar.php in ezContents CMS allows remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 2.3% | 2008-08-10 |
| CVE-2009-4085 EXP | PHP remote file inclusion vulnerability in assets/plugins/mp3_id/mp3_id.php in PHP Traverser 0.8.0 allows remote attackers to execute arbitrary PHP co… | Patch early | 7.5 high | 2.3% | 2009-11-29 |
| CVE-2007-2014 EXP | PHP remote file inclusion vulnerability in include/blocks/week_events.php in MyNews 4.2.2 allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 2.3% | 2007-04-12 |
| CVE-2007-2710 EXP | PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2.00-P00 and earlier allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 2.3% | 2007-05-16 |
| CVE-2026-34472 EXP | Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on th… | Patch early | 7.1 high | 2.3% | 2026-03-30 |
| CVE-2006-2887 EXP | Multiple SQL injection vulnerabilities in myNewsletter 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the UserName par… | Patch early | 7.5 high | 2.3% | 2006-06-07 |
| CVE-2007-6568 EXP | PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitr… | Patch early | 7.5 high | 2.3% | 2007-12-28 |
| CVE-2008-1712 EXP | PHP remote file inclusion vulnerability in includes/functions_weblog.php in mxBB mx_blogs 2.0.0 beta allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 2.3% | 2008-04-09 |
| CVE-2009-3966 EXP | Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLoggedIn cookie to true. | Patch early | 7.5 high | 2.3% | 2009-11-18 |
| CVE-2009-4671 EXP | Login.php in RoomPHPlanning 1.6 allows remote attackers to bypass authentication and obtain administrative access by setting the room_phplanning cooki… | Patch early | 7.5 high | 2.3% | 2010-03-05 |
| CVE-2011-1985 EXP | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, an… | Patch early | 7.1 high | 2.3% | 2011-10-12 |
| CVE-2006-4876 EXP | Multiple SQL injection vulnerabilities in Jupiter CMS allow remote attackers to execute arbitrary SQL commands via (1) the user name during login, or… | Patch early | 7.5 high | 2.3% | 2006-09-19 |
| CVE-2007-0342 EXP | WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element wit… | Patch early | 7.5 high | 2.3% | 2007-01-18 |
| CVE-2007-1615 EXP | SQL injection vulnerability in index.php in ScriptMagix Jokes 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid… | Patch early | 7.5 high | 2.3% | 2007-03-23 |
| CVE-2011-1060 EXP | SQL injection vulnerability in the member function in classes/member.php in WSN Guest 1.24 allows remote attackers to execute arbitrary SQL commands v… | Patch early | 7.5 high | 2.3% | 2011-02-23 |
| CVE-2008-2448 EXP | Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) admi… | Patch early | 7.5 high | 2.3% | 2008-05-27 |
| CVE-2008-5651 EXP | SQL injection vulnerability in plugins/bookmarker/bookmarker_backend.php in MyioSoft EasyBookMarker 4.0 allows remote attackers to execute arbitrary S… | Patch early | 7.5 high | 2.3% | 2008-12-17 |
| CVE-2008-6952 EXP | SQL injection vulnerability in Rss.php in MauryCMS 0.53.2 and earlier allows remote attackers to execute arbitrary SQL commands via the c parameter. | Patch early | 7.5 high | 2.3% | 2009-08-12 |
| CVE-2008-6446 EXP | Static code injection vulnerability in the Guestbook component in CMS MAXSITE allows remote attackers to inject arbitrary PHP code into the guestbook… | Patch early | 7.5 high | 2.3% | 2009-03-09 |
| CVE-2018-6007 EXP | CSRF exists in the JS Support Ticket 1.1.0 component for Joomla! and allows attackers to inject HTML or edit a ticket. | Patch early | 8.8 high | 2.3% | 2018-01-29 |
| CVE-2005-0691 EXP | PHP remote file inclusion vulnerability in article mode for modules.php in SocialMPN allows remote attackers to execute arbitrary PHP code by modifyin… | Patch early | 7.5 high | 2.3% | 2005-03-06 |
| CVE-2007-6091 EXP | Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System (JBS) 2.0, and possibly JiRo's Upload Manager (aka JiRo's Upload Sys… | Patch early | 7.5 high | 2.3% | 2007-11-22 |
| CVE-2007-6518 EXP | Multiple SQL injection vulnerabilities in search.php in WoltLab Burning Board (wBB) Lite 1.0.2 pl3e allow remote attackers to execute arbitrary SQL co… | Patch early | 7.5 high | 2.3% | 2007-12-24 |
| CVE-2008-3058 EXP | Multiple SQL injection vulnerabilities in Octeth Oempro 3.5.5.1, and possibly other versions before 4, allow remote attackers to execute arbitrary SQL… | Patch early | 7.5 high | 2.3% | 2008-12-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt