CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,557 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
150,568 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-5760 EXP | Multiple PHP remote file inclusion vulnerabilities in phpDynaSite 3.2.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 3.8% | 2006-11-06 |
| CVE-2007-0919 EXP | Directory traversal vulnerability in Nickolas Grigoriadis Mini Web server (MiniWebsvr) 0.0.6 allows remote attackers to list the directory immediately… | Patch early | 7.8 high | 3.8% | 2007-02-14 |
| CVE-2006-4953 EXP | Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary SQL commands via the (1) adr_s… | Patch early | 7.5 high | 3.8% | 2006-09-23 |
| CVE-2002-1767 EXP | Buffer overflow in tnslsnr of Oracle 8i Database Server 8.1.5 for Linux allows local users to execute arbitrary code as the oracle user via a long com… | Patch early | 7.2 high | 3.8% | 2002-12-31 |
| CVE-2010-3944 EXP | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate user-mode input, which allows local… | Patch early | 7.2 high | 3.8% | 2010-12-16 |
| CVE-2009-2223 EXP | Directory traversal vulnerability in locms/smarty.php in LightOpenCMS 0.1 allows remote attackers to include and execute arbitrary local files via a .… | Patch early | 9.3 high | 3.8% | 2009-06-26 |
| CVE-2015-1725 EXP | Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win… | Patch early | 7.2 high | 3.8% | 2015-06-10 |
| CVE-2009-1780 EXP | admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to… | Patch early | 7.5 high | 3.8% | 2009-05-22 |
| CVE-2007-0496 EXP | PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP… | Patch early | 10.0 high | 3.8% | 2007-01-25 |
| CVE-2007-2792 EXP | SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 for Mambo and Joomla! allows re… | Patch early | 7.5 high | 3.8% | 2007-05-22 |
| CVE-2008-3164 EXP | Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execu… | Patch early | 7.6 high | 3.8% | 2008-07-14 |
| CVE-2021-31152 EXP | Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change pass… | Patch early | 8.8 high | 3.8% | 2021-04-14 |
| CVE-2007-2778 EXP | Multiple directory traversal vulnerabilities in MolyX BOARD 2.5.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parame… | Patch early | 7.8 high | 3.8% | 2007-05-21 |
| CVE-2022-26180 EXP | qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI. | Patch early | 8.8 high | 3.8% | 2022-04-08 |
| CVE-2009-2111 EXP | Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP code via a crafted (1) url and… | Patch early | 10.0 high | 3.7% | 2009-06-18 |
| CVE-2010-2959 EXP | Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21,… | Patch early | 7.2 high | 3.7% | 2010-09-08 |
| CVE-2010-2739 EXP | Buffer overflow in the CreateDIBPalette function in win32k.sys in Microsoft Windows XP SP3, Server 2003 R2 Enterprise SP2, Vista Business SP1, Windows… | Patch early | 7.2 high | 3.7% | 2010-09-07 |
| CVE-2013-2579 EXP | TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 have an empty passw… | Patch early | 10.0 high | 3.7% | 2013-10-11 |
| CVE-2008-2192 EXP | Static code injection vulnerability in box/minichat/boxpop.php in IT!CMS (aka itcms) 1.9 allows remote attackers to inject arbitrary PHP code into box… | Patch early | 10.0 high | 3.7% | 2008-05-14 |
| CVE-2008-6748 EXP | Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the play action in a mega:// URI. | Patch early | 9.3 high | 3.7% | 2009-04-24 |
| CVE-2014-10031 EXP | Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary code via a long string in a U… | Patch early | 7.5 high | 3.7% | 2015-01-13 |
| CVE-2007-2774 EXP | Multiple PHP remote file inclusion vulnerabilities in SunLight CMS 5.3 allow remote attackers to execute arbitrary PHP code via a URL in the root para… | Patch early | 7.5 high | 3.7% | 2007-05-21 |
| CVE-2017-14960 EXP | xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL Injection. | Patch early | 7.5 high | 3.7% | 2018-01-04 |
| CVE-2007-2367 EXP | Buffer overflow in wserve_console.exe in Wserve HTTP Server (whttp) 4.6 allows remote attackers to cause a denial of service (forced application exit)… | Patch early | 10.0 high | 3.7% | 2007-04-30 |
| CVE-2000-0776 EXP | Mediahouse Statistics Server 5.02x allows remote attackers to execute arbitrary commands via a long HTTP GET request. | Patch early | 7.5 high | 3.7% | 2000-10-20 |
| CVE-2001-0216 EXP | PALS Library System pals-cgi program allows remote attackers to execute arbitrary commands via shell metacharacters in the documentName parameter. | Patch early | 7.5 high | 3.7% | 2001-06-02 |
| CVE-2001-1160 EXP | udirectory.pl in Microburst Technologies uDirectory 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in… | Patch early | 7.5 high | 3.7% | 2001-06-18 |
| CVE-2025-60188 EXP | Insertion of Sensitive Information Into Sent Data vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Retrieve Embedded Sensitive Da… | Patch early | 7.5 high | 3.7% | 2025-11-06 |
| CVE-2008-7065 EXP | Siemens C450 IP and C475 IP VoIP devices allow remote attackers to cause a denial of service (disconnected calls and device reboot) via a crafted SIP… | Patch early | 7.8 high | 3.7% | 2009-08-25 |
| CVE-2008-4380 EXP | The web interface in Samsung DVR SHR2040 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, related to the fil… | Patch early | 7.8 high | 3.7% | 2008-10-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt