CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,905 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
150,698 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-2473 EXP | SQL injection vulnerability in stylesheet.php in CMS Made Simple 1.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the t… | Patch early | 7.5 high | 3.7% | 2007-05-02 |
| CVE-2000-0306 EXP | Buffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message. | Patch early | 10.0 high | 3.7% | 2001-03-12 |
| CVE-2019-17624 EXP | "" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sending ct.c_char 1000 times, an att… | Patch early | 7.8 high | 3.7% | 2019-10-16 |
| CVE-2006-4036 EXP | PHP remote file inclusion vulnerability in includes/usercp_register.php in ZoneMetrics ZoneX Publishers Gold Edition 1.0.3 and earlier allows remote a… | Patch early | 7.5 high | 3.7% | 2006-08-09 |
| CVE-2006-4853 EXP | SQL injection vulnerability in kategorix.asp in Haberx 1.02 through 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter… | Patch early | 7.5 high | 3.7% | 2006-09-19 |
| CVE-2005-4039 EXP | Directory traversal vulnerability in arhiva.php in Web4Future Portal Solutions News Portal allows remote attackers to read arbitrary files via the dir… | Patch early | 7.8 high | 3.7% | 2005-12-06 |
| CVE-2008-3879 EXP | The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to… | Patch early | 9.3 high | 3.7% | 2008-09-02 |
| CVE-2006-6094 EXP | Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) catID parameter to a… | Patch early | 7.5 high | 3.7% | 2006-11-24 |
| CVE-2002-1482 EXP | SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrat… | Patch early | 10.0 high | 3.7% | 2003-04-22 |
| CVE-2007-5826 EXP | Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote attackers to create or overwri… | Patch early | 9.3 high | 3.7% | 2007-11-05 |
| CVE-2008-0427 EXP | Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the file paramet… | Patch early | 7.8 high | 3.7% | 2008-01-23 |
| CVE-2007-3974 EXP | admin/ajoutaut.php in JBlog 1.0 does not require authentication, which allows remote attackers to create arbitrary accounts via modified mot and droit… | Patch early | 7.5 high | 3.7% | 2007-07-25 |
| CVE-2000-0589 EXP | SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configuration. | Patch early | 7.5 high | 3.7% | 2000-06-26 |
| CVE-2001-0308 EXP | UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling th… | Patch early | 7.5 high | 3.7% | 2001-05-03 |
| CVE-2011-0751 EXP | Directory traversal vulnerability in nhttpd (aka Nostromo webserver) before 1.9.4 allows remote attackers to execute arbitrary programs or read arbitr… | Patch early | 7.5 high | 3.7% | 2011-03-16 |
| CVE-2016-0173 EXP | The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R… | Patch early | 7.8 high | 3.7% | 2016-05-11 |
| CVE-2016-7188 EXP | The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles library loading, which allows local… | Patch early | 7.8 high | 3.7% | 2016-10-14 |
| CVE-2019-0735 EXP | An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, a… | Patch early | 7.8 high | 3.7% | 2019-04-09 |
| CVE-2007-2373 EXP | SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote attackers to execute arbitrary SQ… | Patch early | 7.5 high | 3.7% | 2007-04-30 |
| CVE-2013-4147 EXP | Multiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attackers to cause a denial of service… | Patch early | 7.5 high | 3.7% | 2013-08-09 |
| CVE-2012-0992 EXP | interface/fax/fax_dispatch.php in OpenEMR 4.1.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the file p… | Patch early | 8.5 high | 3.7% | 2012-02-07 |
| CVE-2015-2508 EXP | The Adobe Type Manager Library in Microsoft Windows 10 allows local users to gain privileges via a crafted application, aka "Font Driver Elevation of… | Patch early | 7.2 high | 3.7% | 2015-09-09 |
| CVE-2007-1986 EXP | Multiple PHP remote file inclusion vulnerabilities in barnraiser AROUNDMe 0.7.7 allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 3.7% | 2007-04-12 |
| CVE-2006-4166 EXP | PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the image… | Patch early | 7.5 high | 3.7% | 2006-08-16 |
| CVE-2005-1224 EXP | Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChannel parame… | Patch early | 7.5 high | 3.7% | 2005-05-02 |
| CVE-2003-1092 EXP | Unknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) Tool version of the file package before 3.41, related to "a memory alloc… | Patch early | 7.5 high | 3.7% | 2003-12-31 |
| CVE-2005-1550 EXP | easymsgb.pl in Easy Message Board allows remote attackers to execute arbitrary commands via shell metacharacters in the print parameter. | Patch early | 7.5 high | 3.7% | 2005-05-14 |
| CVE-2005-1307 EXP | The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the produ… | Patch early | 7.2 high | 3.7% | 2005-05-17 |
| CVE-2006-1793 EXP | Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) clas… | Patch early | 7.6 high | 3.6% | 2006-04-17 |
| CVE-2007-0637 EXP | Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local file… | Patch early | 7.5 high | 3.6% | 2007-01-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt