CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,461 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
150,530 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-0359 EXP | Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device crash) via SIP INVITE commands w… | Patch early | 7.5 high | 4% | 2006-01-22 |
| CVE-2006-1212 EXP | Unspecified vulnerability in index.php in Core CoreNews 2.0.1 allows remote attackers to execute arbitrary commands via the page parameter, possibly d… | Patch early | 7.5 high | 4% | 2006-03-14 |
| CVE-2008-4592 EXP | Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and execute arbitrary local files vi… | Patch early | 10.0 high | 4% | 2008-10-16 |
| CVE-2008-6677 EXP | Unrestricted file upload vulnerability in fckeditor251/editor/filemanager/connectors/asp/upload.asp in QuickerSite 1.8.5 allows remote attackers to ex… | Patch early | 7.5 high | 4% | 2009-04-08 |
| CVE-2015-2370 EXP | The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and… | Patch early | 7.2 high | 4% | 2015-07-14 |
| CVE-2016-0006 EXP | The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2… | Patch early | 7.3 high | 4% | 2016-01-13 |
| CVE-2001-0818 EXP | A buffer overflow the '\s' console command in MDBMS 0.99b9 and earlier allows remote attackers to execute arbitrary commands by sending the command a… | Patch early | 7.5 high | 4% | 2001-12-06 |
| CVE-2009-1443 EXP | Multiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and attack vectors. | Patch early | 10.0 high | 4% | 2009-04-27 |
| CVE-2018-19459 EXP | Adult Filter 1.0 has a Buffer Overflow via a crafted Black Domain List file. | Patch early | 7.8 high | 4% | 2018-11-22 |
| CVE-2013-7179 EXP | The ping functionality in cgi-bin/diagnostic.cgi on Seowon Intech SWC-9100 routers allows remote attackers to execute arbitrary commands via shell met… | Patch early | 8.3 high | 4% | 2014-02-04 |
| CVE-2007-1423 EXP | Multiple PHP remote file inclusion vulnerabilities in WORK system e-commerce 3.0.5 and earlier allow remote attackers to execute arbitrary PHP code vi… | Patch early | 9.3 high | 4% | 2007-03-13 |
| CVE-2023-30868 EXP | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jon Christopher CMS Tree Page View plugin <= 1.6.7 versions. | Patch early | 7.1 high | 4% | 2023-05-18 |
| CVE-2005-1503 EXP | Multiple SQL injection vulnerabilities in MidiCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) searchstring… | Patch early | 7.5 high | 4% | 2005-05-11 |
| CVE-2006-4993 EXP | Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.4.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 4% | 2006-09-26 |
| CVE-2007-1225 EXP | The connection log file implementation in Grok Developments NetProxy 4.03 does not record requests that omit http:// in a URL, which might allow remot… | Patch early | 10.0 high | 4% | 2007-03-02 |
| CVE-2007-3251 EXP | Multiple directory traversal vulnerabilities in e-Vision CMS 2.02 and earlier allow remote attackers to (1) include and execute arbitrary local files… | Patch early | 7.8 high | 4% | 2007-06-18 |
| CVE-2006-1747 EXP | PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root p… | Patch early | 7.5 high | 4% | 2006-04-12 |
| CVE-2006-0688 EXP | PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 4% | 2006-02-15 |
| CVE-2007-6188 EXP | Multiple directory traversal vulnerabilities in TuMusika Evolution 1.7R5 allow remote attackers to include and execute arbitrary local files via a ..… | Patch early | 7.5 high | 4% | 2007-11-30 |
| CVE-2015-6098 EXP | Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and… | Patch early | 7.2 high | 4% | 2015-11-11 |
| CVE-2018-8410 EXP | An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory, aka "Windows Registry Elevat… | Patch early | 7.8 high | 4% | 2018-09-13 |
| CVE-2005-4065 EXP | SQL injection vulnerability in the search module in Edgewall Trac before 0.9.2 allows remote attackers to execute arbitrary SQL commands via unknown v… | Patch early | 7.5 high | 4% | 2005-12-07 |
| CVE-2003-1405 EXP | DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3. | Patch early | 7.5 high | 4% | 2003-12-31 |
| CVE-2007-3935 EXP | PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary PHP code v… | Patch early | 9.3 high | 4% | 2007-07-21 |
| CVE-2005-2210 EXP | Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL. | Patch early | 7.5 high | 4% | 2005-07-11 |
| CVE-2005-2644 EXP | Buffer overflow in JaguarEditControl.dll in Isemarket JaguarControl allows remote attackers to cause a denial of service (crash) and possibly execute… | Patch early | 7.5 high | 4% | 2005-08-23 |
| CVE-2006-5014 EXP | Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladm… | Patch early | 8.8 high | 4% | 2006-09-27 |
| CVE-2007-0585 EXP | include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain source code of files via the conff… | Patch early | 9.3 high | 4% | 2007-01-30 |
| CVE-2007-2506 EXP | WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attackers to cause a denial of service… | Patch early | 7.8 high | 4% | 2007-05-04 |
| CVE-2017-5633 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) chang… | Patch early | 8.0 high | 4% | 2017-03-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt