CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,429 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
150,522 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-3156 EXP | The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CA… | Patch early | 9.3 high | 4.1% | 2008-07-11 |
| CVE-2005-3879 EXP | Multiple SQL injection vulnerabilities in Softbiz Resource Repository Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 4.1% | 2005-11-29 |
| CVE-2005-0737 EXP | Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode. | Patch early | 7.5 high | 4.1% | 2005-05-02 |
| CVE-2019-6205 EXP | A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A mal… | Patch early | 7.8 high | 4.1% | 2019-03-05 |
| CVE-2007-1483 EXP | Multiple PHP remote file inclusion vulnerabilities in WebCalendar 0.9.45 allow remote attackers to execute arbitrary PHP code via a URL in the include… | Patch early | 7.5 high | 4.1% | 2007-03-16 |
| CVE-2006-2731 EXP | Multiple SQL injection vulnerabilities in Enigma Haber 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id paramet… | Patch early | 7.5 high | 4.1% | 2006-06-01 |
| CVE-2002-2309 EXP | php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via… | Patch early | 7.8 high | 4.1% | 2002-12-31 |
| CVE-2006-2807 EXP | ASPwebSoft Speedy Asp Discussion Forum allows remote attackers to change the password of any account via a modified account id and possibly arbitrary… | Patch early | 10.0 high | 4.1% | 2006-06-05 |
| CVE-2018-10188 EXP | phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.… | Patch early | 8.8 high | 4.1% | 2018-04-19 |
| CVE-2024-25734 EXP | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is enter… | Patch early | 7.5 high | 4.1% | 2024-03-27 |
| CVE-2007-0680 EXP | PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 4% | 2007-02-03 |
| CVE-2013-1803 EXP | Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) orderby param… | Patch early | 7.5 high | 4% | 2014-05-05 |
| CVE-2008-6834 EXP | Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.01 and 3.01a allow remote attackers to include and execute arbitrary local files via… | Patch early | 10.0 high | 4% | 2009-06-22 |
| CVE-2008-1275 EXP | Multiple unspecified vulnerabilities in the SMTP service in MailEnable Standard Edition 1.x, Professional Edition 3.x and earlier, and Enterprise Edit… | Patch early | 7.8 high | 4% | 2008-03-10 |
| CVE-2003-1097 EXP | Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option. | Patch early | 7.2 high | 4% | 2003-12-31 |
| CVE-2006-0087 EXP | SQL injection vulnerability in (1) pages.php and (2) detail.php in Lizard Cart CMS 1.04 allows remote attackers to execute arbitrary SQL commands via… | Patch early | 7.5 high | 4% | 2006-01-05 |
| CVE-2009-4676 EXP | Stack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute arbitrary code via a long titl… | Patch early | 9.3 high | 4% | 2010-03-05 |
| CVE-2013-2784 EXP | Triangle Research International (aka Tri) Nano-10 PLC devices with firmware before r81 use an incorrect algorithm for bounds checking of data in Modbu… | Patch early | 7.8 high | 4% | 2013-07-10 |
| CVE-2003-0306 EXP | Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClass… | Patch early | 7.2 high | 4% | 2003-06-09 |
| CVE-2006-6568 EXP | Directory traversal vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to include… | Patch early | 10.0 high | 4% | 2006-12-15 |
| CVE-2006-7131 EXP | PHP remote file inclusion vulnerability in extras/mt.php in Jinzora 2.6 allows remote attackers to execute arbitrary PHP code via the web_root paramet… | Patch early | 10.0 high | 4% | 2007-03-06 |
| CVE-2007-2493 EXP | PHP remote file inclusion vulnerability in faq.php in the FAQ & RULES 2.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary P… | Patch early | 10.0 high | 4% | 2007-05-04 |
| CVE-2005-3682 EXP | Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (1) the AuthID parameter in For… | Patch early | 7.5 high | 4% | 2005-11-18 |
| CVE-2002-0250 EXP | Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized users to bypass… | Patch early | 7.5 high | 4% | 2002-05-29 |
| CVE-2008-3464 EXP | afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly val… | Patch early | 7.2 high | 4% | 2008-10-15 |
| CVE-2024-33896 EXP | Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blackli… | Patch early | 7.2 high | 4% | 2024-08-02 |
| CVE-2004-0323 EXP | Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp paramet… | Patch early | 7.5 high | 4% | 2004-12-31 |
| CVE-2006-7070 EXP | Unrestricted file upload vulnerability in manager/media/ibrowser/scripts/rfiles.php in Etomite CMS 0.6.1 and earlier allows remote attackers to upload… | Patch early | 7.5 high | 4% | 2007-03-02 |
| CVE-2008-4878 EXP | Unrestricted file upload vulnerability in the "Add Image Macro" feature in WebCards 1.3 allows remote authenticated administrators to execute arbitrar… | Patch early | 8.5 high | 4% | 2008-11-01 |
| CVE-2017-7178 EXP | CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitra… | Patch early | 8.8 high | 4% | 2017-03-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt