CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,932 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-0830 EXP | The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (crash) via a malformed dpap: UR… | Patch early | 7.5 high | 2.2% | 2008-02-19 |
| CVE-2012-4927 EXP | SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL c… | Patch early | 7.5 high | 2.2% | 2012-09-15 |
| CVE-2026-24486 EXP | Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default con… | Patch early | 8.6 high | 2.2% | 2026-01-27 |
| CVE-2009-4060 EXP | SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the p… | Patch early | 7.5 high | 2.2% | 2009-11-24 |
| CVE-2014-4307 EXP | SQL injection vulnerability in categories-x.php in WebTitan before 4.04 allows remote attackers to execute arbitrary SQL commands via the sortkey para… | Patch early | 7.5 high | 2.2% | 2014-06-18 |
| CVE-2014-4852 EXP | SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 2.2% | 2014-07-10 |
| CVE-2015-5591 EXP | SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands. | Patch early | 7.2 high | 2.2% | 2019-12-31 |
| CVE-2011-5222 EXP | SQL injection vulnerability in rub2_w.php in PHP Flirt-Projekt 4.8 and possibly earlier allows remote attackers to execute arbitrary SQL commands via… | Patch early | 7.5 high | 2.2% | 2012-10-25 |
| CVE-2011-5230 EXP | Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/LoginModel.php in Seotoaster 1.9… | Patch early | 7.5 high | 2.2% | 2012-10-25 |
| CVE-2013-3536 EXP | SQL injection vulnerability in the gp_LoadUserFromHash function in functions_hash.php in the Group Pay module 1.5 and earlier for WHMCS allows remote… | Patch early | 7.5 high | 2.2% | 2013-05-13 |
| CVE-2011-5218 EXP | SQL injection vulnerability in DotA OpenStats 1.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to inde… | Patch early | 7.5 high | 2.2% | 2012-10-25 |
| CVE-2008-5730 EXP | Multiple CRLF injection vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to have an unknown impact via unspecified vectors invol… | Patch early | 7.5 high | 2.2% | 2008-12-26 |
| CVE-2018-8908 EXP | An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft… | Patch early | 8.8 high | 2.2% | 2018-03-31 |
| CVE-2008-1466 EXP | Multiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_default… | Patch early | 7.5 high | 2.2% | 2008-03-24 |
| CVE-2011-5229 EXP | SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attackers to execute arbitrary SQL… | Patch early | 7.5 high | 2.2% | 2012-10-25 |
| CVE-2012-4282 EXP | SQL injection vulnerability in photo.php in Trombinoscope 3.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Patch early | 7.5 high | 2.2% | 2012-08-13 |
| CVE-2013-3531 EXP | SQL injection vulnerability in meneger.php in RadioCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the playlist_id parameter. | Patch early | 7.5 high | 2.2% | 2013-05-10 |
| CVE-2013-3537 EXP | Multiple SQL injection vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_po… | Patch early | 7.5 high | 2.2% | 2013-05-13 |
| CVE-2013-3721 EXP | SQL injection vulnerability in awards.php in PsychoStats 3.2.2b allows remote attackers to execute arbitrary SQL commands via the d parameter. | Patch early | 7.5 high | 2.2% | 2013-05-31 |
| CVE-2013-5311 EXP | Multiple SQL injection vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to execute arbitrary SQL commands via the "n" parameter to… | Patch early | 7.5 high | 2.2% | 2013-08-19 |
| CVE-2006-6739 EXP | PHP remote file inclusion vulnerability in buycd.php in Paristemi 0.8.3 allows remote attackers to execute arbitrary PHP code via a URL in the HTTP_DO… | Patch early | 7.5 high | 2.2% | 2006-12-26 |
| CVE-2006-5312 EXP | PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows remote attackers to execute arb… | Patch early | 7.5 high | 2.2% | 2006-10-17 |
| CVE-2006-6550 EXP | PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 2.2% | 2006-12-14 |
| CVE-2006-6551 EXP | PHP remote file inclusion vulnerability in libs/tucows/api/cartridges/crt_TUCOWS_domains/lib/domainutils.inc.php in Tucows Client Code Suite (CCS) 1.2… | Patch early | 7.5 high | 2.2% | 2006-12-14 |
| CVE-2006-6575 EXP | PHP remote file inclusion vulnerability in ldap.php in Brian Drawert Yet Another PHP LDAP Admin Project (yaplap) 0.6 and 0.6.1 allows remote attackers… | Patch early | 7.5 high | 2.2% | 2006-12-15 |
| CVE-2006-6590 EXP | PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the s… | Patch early | 7.5 high | 2.2% | 2006-12-15 |
| CVE-2017-12970 EXP | Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authentication of authenticated users for… | Patch early | 8.8 high | 2.2% | 2017-08-23 |
| CVE-2017-16513 EXP | Ipswitch WS_FTP Professional before 12.6.0.3 has buffer overflows in the local search field and the backup locations field, aka WSCLT-1729. | Patch early | 7.8 high | 2.2% | 2017-11-03 |
| CVE-2009-5102 EXP | SQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL commands via the bpe_nid para… | Patch early | 7.5 high | 2.2% | 2011-10-21 |
| CVE-2008-6119 EXP | Static code injection vulnerability in gooplecms/admin/account/action/editpass.php in Goople CMS 1.7 allows remote attackers to inject arbitrary PHP c… | Patch early | 7.5 high | 2.2% | 2009-02-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt