CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,367 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-1999-0069 EXP | Solaris ufsrestore buffer overflow. | Patch early | 8.4 high | 1.4% | 1998-04-29 |
| CVE-2006-6209 EXP | Multiple SQL injection vulnerabilities in MidiCart ASP Shopping Cart and ASP Plus Shopping Cart allow remote attackers to execute arbitrary SQL comman… | Patch early | 7.5 high | 1.4% | 2006-12-01 |
| CVE-2016-1583 EXP | The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denia… | Patch early | 7.8 high | 1.4% | 2016-06-27 |
| CVE-2003-1050 EXP | Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long command line arguments to (1) db2… | Patch early | 7.2 high | 1.4% | 2004-09-28 |
| CVE-2008-6429 EXP | SQL injection vulnerability in the PrayerCenter (com_prayercenter) component 1.4.9 and earlier for Joomla! allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 1.4% | 2009-03-06 |
| CVE-2018-5969 EXP | Cross Site Request Forgery (CSRF) exists in Photography CMS 1.0 via clients/resources/ajax/ajax_new_admin.php, as demonstrated by adding an admin acco… | Patch early | 8.8 high | 1.4% | 2018-01-24 |
| CVE-2013-5697 EXP | SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote attackers to execute arbitrary S… | Patch early | 7.5 high | 1.4% | 2013-09-30 |
| CVE-2016-8972 EXP | IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV… | Patch early | 7.8 high | 1.4% | 2017-02-15 |
| CVE-2015-5996 EXP | Cross-site request forgery (CSRF) vulnerability on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 allows remote attackers to hijack… | Patch early | 8.8 high | 1.4% | 2015-12-31 |
| CVE-2008-6992 EXP | GreenSQL Firewall (greensql-fw), possibly before 0.9.2 or 0.9.4, allows remote attackers to bypass the SQL injection protection mechanism via a WHERE… | Patch early | 7.5 high | 1.4% | 2009-08-19 |
| CVE-2007-2523 EXP | CA Anti-Virus for the Enterprise r8 and Threat Manager r8 before 20070510 use weak permissions (NULL security descriptor) for the Task Service shared… | Patch early | 7.2 high | 1.4% | 2007-05-11 |
| CVE-2006-0318 EXP | SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 1.4% | 2006-01-19 |
| CVE-2014-3757 EXP | SQL injection vulnerability in sorter.php in the phpManufaktur kitForm extension 0.43 and earlier for the KeepInTouch (KIT) module allows remote attac… | Patch early | 7.5 high | 1.4% | 2014-05-15 |
| CVE-2009-1049 EXP | SQL injection vulnerability in articleCall.php in Bloginator 1A allows remote attackers to execute arbitrary SQL commands via the id parameter. | Patch early | 7.5 high | 1.4% | 2009-03-24 |
| CVE-2018-18435 EXP | KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any user full permission "Everyon… | Patch early | 7.8 high | 1.4% | 2019-03-21 |
| CVE-2018-0438 EXP | A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administra… | Patch early | 7.8 high | 1.4% | 2018-10-05 |
| CVE-2005-0385 EXP | Buffer overflow in luxman before 0.41, if used with certain insecure svgalib libraries, allows local users to execute arbitrary code via a long -f com… | Patch early | 7.2 high | 1.4% | 2005-05-02 |
| CVE-2003-0834 EXP | Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment variable and… | Patch early | 7.2 high | 1.4% | 2003-12-01 |
| CVE-2003-0752 EXP | SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass authentication via a mod… | Patch early | 7.5 high | 1.4% | 2003-10-20 |
| CVE-2013-5321 EXP | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitra… | Patch early | 7.5 high | 1.4% | 2013-08-20 |
| CVE-2011-1760 EXP | utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to conduct eval injection attacks and gain privileges via shell metacharacters i… | Patch early | 7.2 high | 1.4% | 2011-06-09 |
| CVE-2006-2857 EXP | SQL injection vulnerability in index.php in LifeType 1.0.4 allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a… | Patch early | 7.5 high | 1.4% | 2006-06-06 |
| CVE-2008-6216 EXP | SQL injection vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to execute ar… | Patch early | 7.5 high | 1.4% | 2009-02-20 |
| CVE-2008-4072 EXP | Multiple SQL injection vulnerabilities in index.php in phsBlog 0.2 allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter… | Patch early | 7.5 high | 1.4% | 2008-09-15 |
| CVE-2004-2326 EXP | SQL injection vulnerability in IP3 Networks NetAccess Appliance before firmware 3.1.18b13 allows remote attackers to bypass authentication via the (1)… | Patch early | 7.5 high | 1.4% | 2004-12-31 |
| CVE-2017-3563 EXP | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5… | Patch early | 8.8 high | 1.4% | 2017-04-24 |
| CVE-2006-2263 EXP | SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows remote attackers to execute arbitrary SQL commands via the cid parameter. | Patch early | 7.5 high | 1.4% | 2006-05-09 |
| CVE-2014-1597 EXP | SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remote attackers to execute arbitra… | Patch early | 7.5 high | 1.4% | 2014-02-27 |
| CVE-2010-1496 EXP | SQL injection vulnerability in the JoltCard (com_joltcard) component 1.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via t… | Patch early | 7.5 high | 1.4% | 2010-04-23 |
| CVE-2010-2609 EXP | SQL injection vulnerability in show_search_result.php in 2daybiz Job Search Engine Script allows remote attackers to execute arbitrary SQL commands vi… | Patch early | 7.5 high | 1.4% | 2010-07-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt