CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,169 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-1492 EXP | Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allow local users to gain root pri… | Patch early | 7.2 high | 1.7% | 2003-04-02 |
| CVE-2017-3813 EXP | A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthenticated,… | Patch early | 7.8 high | 1.7% | 2017-02-09 |
| CVE-2014-9113 EXP | CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the… | Patch early | 7.2 high | 1.7% | 2014-12-02 |
| CVE-2012-4260 EXP | Multiple SQL injection vulnerabilities in myCare2x allow remote attackers to execute arbitrary SQL commands via the (1) aktion or (2) callurl paramete… | Patch early | 7.5 high | 1.7% | 2012-08-13 |
| CVE-2012-6519 EXP | SQL injection vulnerability in modules/poll/index.php in DIY-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the start parameter… | Patch early | 7.5 high | 1.7% | 2013-01-24 |
| CVE-2006-2065 EXP | SQL injection vulnerability in save.php in PHPSurveyor 0.995 and earlier allows remote attackers to execute arbitrary SQL commands via the surveyid co… | Patch early | 7.5 high | 1.7% | 2006-04-27 |
| CVE-2006-4300 EXP | SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id paramet… | Patch early | 7.5 high | 1.7% | 2006-08-23 |
| CVE-2007-6579 EXP | Multiple SQL injection vulnerabilities in Ip Reg 0.3 allow remote attackers to execute arbitrary SQL commands via the vlan_id parameter to (1) vlanvie… | Patch early | 7.5 high | 1.7% | 2007-12-28 |
| CVE-2015-4681 EXP | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwords. | Patch early | 7.8 high | 1.7% | 2017-09-19 |
| CVE-2009-4698 EXP | Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commands via the… | Patch early | 7.5 high | 1.7% | 2010-03-15 |
| CVE-2007-2207 EXP | SQL injection vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to execute arbitrary SQL commands v… | Patch early | 7.5 high | 1.7% | 2007-04-24 |
| CVE-2007-4208 EXP | SQL injection vulnerability in default.asp in Next Gen Portfolio Manager allows remote attackers to execute arbitrary SQL commands via the (1) Users_E… | Patch early | 7.5 high | 1.7% | 2007-08-08 |
| CVE-2011-0182 EXP | The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle call gates, which allows local users to gain privi… | Patch early | 7.2 high | 1.7% | 2011-03-23 |
| CVE-2010-5032 EXP | SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers to execute arbitrary SQL comma… | Patch early | 7.5 high | 1.7% | 2011-11-02 |
| CVE-2017-6331 EXP | Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a type of attack that bypasses t… | Patch early | 7.1 high | 1.7% | 2017-11-06 |
| CVE-2004-1842 EXP | Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag… | Patch early | 8.8 high | 1.7% | 2004-12-31 |
| CVE-2014-2560 EXP | The PhonerLite phone before 2.15 provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote at… | Patch early | 7.5 high | 1.7% | 2020-02-12 |
| CVE-2008-0301 EXP | Multiple SQL injection vulnerabilities in Mapbender 2.4.4 allow remote attackers to execute arbitrary SQL commands via the gaz parameter to mod_gazett… | Patch early | 7.5 high | 1.7% | 2008-03-11 |
| CVE-2008-0428 EXP | Multiple SQL injection vulnerabilities in the login function in system/class_permissions.php in bloofoxCMS 0.3 allow remote attackers to execute arbit… | Patch early | 7.5 high | 1.7% | 2008-01-23 |
| CVE-2008-2862 EXP | Multiple SQL injection vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via… | Patch early | 7.5 high | 1.7% | 2008-06-25 |
| CVE-2008-2917 EXP | SQL injection vulnerability in productsofcat.asp in E-SMART CART allows remote attackers to execute arbitrary SQL commands via the category_id paramet… | Patch early | 7.5 high | 1.7% | 2008-06-30 |
| CVE-2008-6180 EXP | SQL injection vulnerability in system/nlb_user.class.php in NewLife Blogger 3.0 and earlier, and possibly 3.3.1, allows remote attackers to execute ar… | Patch early | 7.5 high | 1.7% | 2009-02-19 |
| CVE-2017-6970 EXP | AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an NfSen sock… | Patch early | 8.4 high | 1.7% | 2017-03-22 |
| CVE-2003-0735 EXP | SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries, as demons… | Patch early | 7.5 high | 1.7% | 2003-10-20 |
| CVE-2018-12897 EXP | SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow. | Patch early | 7.8 high | 1.7% | 2018-09-07 |
| CVE-1999-0306 EXP | buffer overflow in HP xlock program. | Patch early | 7.2 high | 1.7% | 1997-11-04 |
| CVE-2015-2142 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to (1) hijack t… | Patch early | 8.0 high | 1.7% | 2017-10-06 |
| CVE-2000-0993 EXP | Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in command… | Patch early | 7.2 high | 1.7% | 2000-12-19 |
| CVE-2004-1846 EXP | Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via the (1) ID parameter to more.… | Patch early | 7.5 high | 1.7% | 2004-03-20 |
| CVE-2006-0823 EXP | Multiple SQL injection vulnerabilities in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to inject arbitrary SQL com… | Patch early | 7.5 high | 1.7% | 2006-02-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt