CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,164 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-1889 EXP | Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privi… | Patch early | 7.8 high | 2% | 2010-08-11 |
| CVE-2010-4894 EXP | SQL injection vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to execute arbitrary SQL commands via the name parameter.… | Patch early | 7.5 high | 2% | 2011-10-08 |
| CVE-2004-1703 EXP | Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that… | Patch early | 8.8 high | 2% | 2004-07-30 |
| CVE-2016-8742 EXP | The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file pe… | Patch early | 7.8 high | 2% | 2018-02-12 |
| CVE-2007-6083 EXP | SQL injection vulnerability in admin/index.php in IceBB 1.0-rc6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP… | Patch early | 7.5 high | 2% | 2007-11-22 |
| CVE-2011-4833 EXP | Multiple SQL injection vulnerabilities in the Leads module in SugarCRM 6.1 before 6.1.7, 6.2 before 6.2.4, 6.3 before 6.3.0RC3, and 6.4 before 6.4.0be… | Patch early | 7.5 high | 2% | 2011-12-15 |
| CVE-2006-6157 EXP | SQL injection vulnerability in index.php in ContentNow 1.39 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid param… | Patch early | 7.5 high | 2% | 2006-11-28 |
| CVE-2009-3489 EXP | Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) s… | Patch early | 7.8 high | 2% | 2009-09-30 |
| CVE-2017-8849 EXP | smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount helper DBUS service. | Patch early | 7.8 high | 1.9% | 2017-05-17 |
| CVE-2018-7886 EXP | An issue was discovered in CloudMe 1.11.0. An unauthenticated local attacker that can connect to the "CloudMe Sync" client application listening on 12… | Patch early | 7.8 high | 1.9% | 2018-03-15 |
| CVE-2011-4448 EXP | SQL injection vulnerability in actions/usersettings/usersettings.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to execute arbitrary SQL com… | Patch early | 7.5 high | 1.9% | 2012-09-05 |
| CVE-2015-6396 EXP | The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via craf… | Patch early | 7.8 high | 1.9% | 2016-08-08 |
| CVE-1999-1191 EXP | Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument. | Patch early | 7.2 high | 1.9% | 1997-05-19 |
| CVE-2020-26218 EXP | touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting. The vulnerability allows an attacker to inject HTML payloads which could result… | Patch early | 8.0 high | 1.9% | 2020-11-11 |
| CVE-2026-46522 EXP | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a miss… | Patch early | 7.5 high | 1.9% | 2026-06-10 |
| CVE-2014-6046 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack the authentication of unspecifie… | Patch early | 8.8 high | 1.9% | 2018-08-28 |
| CVE-2017-9810 EXP | There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4… | Patch early | 8.8 high | 1.9% | 2017-07-17 |
| CVE-2018-1213 EXP | Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 and 8.1.0.2… | Patch early | 8.8 high | 1.9% | 2018-03-26 |
| CVE-2007-2092 EXP | Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) allows remote attackers to inject arbitrary PHP co… | Patch early | 7.5 high | 1.9% | 2007-04-18 |
| CVE-2018-14894 EXP | CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file) to bypass intended access re… | Patch early | 7.8 high | 1.9% | 2019-04-09 |
| CVE-2018-6888 EXP | An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using… | Patch early | 8.0 high | 1.9% | 2018-02-12 |
| CVE-2012-2105 EXP | Multiple SQL injection vulnerabilities in login.php in Timesheet Next Gen 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) u… | Patch early | 7.5 high | 1.9% | 2012-09-19 |
| CVE-2009-0964 EXP | UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. N… | Patch early | 7.5 high | 1.9% | 2009-03-19 |
| CVE-2010-2554 EXP | The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on it… | Patch early | 7.8 high | 1.9% | 2010-08-11 |
| CVE-2026-25099 EXP | Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can t… | Patch early | 8.8 high | 1.9% | 2026-03-27 |
| CVE-2003-0144 EXP | Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems,… | Patch early | 7.2 high | 1.9% | 2003-03-31 |
| CVE-2026-42471 EXP | Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke client (Connection.php:76) calls unserialize() on data recei… | Patch early | 8.1 high | 1.9% | 2026-05-01 |
| CVE-2010-1300 EXP | SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbitrary SQL commands via the calb… | Patch early | 7.5 high | 1.9% | 2010-04-07 |
| CVE-2008-2565 EXP | Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the id param… | Patch early | 7.5 high | 1.9% | 2008-06-06 |
| CVE-2026-55584 EXP | phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trus… | Patch early | 7.5 high | 1.9% | 2026-08-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt