CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,922 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
150,703 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-0702 EXP | Multiple PHP remote file inclusion vulnerabilities in phpEventMan 1.0.2 allow remote attackers to execute arbitrary PHP code via a URL in the level pa… | Patch early | 7.5 high | 3.6% | 2007-02-04 |
| CVE-2008-4439 EXP | PHP remote file inclusion vulnerability in admin/bin/patch.php in MartinWood Datafeed Studio before 1.6.3 allows remote attackers to execute arbitrary… | Patch early | 10.0 high | 3.6% | 2008-10-03 |
| CVE-2006-3692 EXP | PHP remote file inclusion vulnerability in enduser/listmessenger.php in ListMessenger 0.9.3 allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 3.6% | 2006-07-21 |
| CVE-2007-3400 EXP | The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.7, allows remote attackers to… | Patch early | 9.3 high | 3.6% | 2007-06-26 |
| CVE-2009-0465 EXP | The SaveDoc method in the All_In_The_Box.AllBox ActiveX control in ALL_IN_THE_BOX.OCX in Synactis ALL In-The-Box ActiveX 3 allows remote attackers to… | Patch early | 9.3 high | 3.6% | 2009-02-10 |
| CVE-2002-2360 EXP | The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary fi… | Patch early | 9.3 high | 3.6% | 2002-12-31 |
| CVE-2007-0535 EXP | Multiple eval injection vulnerabilities in Vote! Pro 4.0, and possibly earlier, allow remote attackers to execute arbitrary code via requests to unspe… | Patch early | 7.5 high | 3.6% | 2007-01-26 |
| CVE-2007-2527 EXP | Multiple PHP remote file inclusion vulnerabilities in DynamicPAD before 1.03.31 allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 3.6% | 2007-05-08 |
| CVE-2019-6214 EXP | A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.… | Patch early | 8.6 high | 3.6% | 2019-03-05 |
| CVE-2006-2137 EXP | PHP remote file inclusion vulnerability in master.php in OpenPHPNuke and 2.3.3 earlier allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 3.6% | 2006-05-02 |
| CVE-2006-0944 EXP | Archangel Weblog 0.90.02 allows remote attackers to bypass authentication by setting the ba_admin cookie to 1. | Patch early | 7.5 high | 3.6% | 2006-03-01 |
| CVE-2007-6082 EXP | Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary P… | Patch early | 9.3 high | 3.6% | 2007-11-22 |
| CVE-2006-4267 EXP | Multiple SQL injection vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) oid paramet… | Patch early | 7.5 high | 3.6% | 2006-08-21 |
| CVE-2017-6979 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… | Patch early | 7.0 high | 3.6% | 2017-05-22 |
| CVE-2013-5582 EXP | Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass a… | Patch early | 7.8 high | 3.6% | 2020-02-11 |
| CVE-2003-0842 EXP | Stack-based buffer overflow in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode, a… | Patch early | 7.5 high | 3.6% | 2003-11-17 |
| CVE-2006-7120 EXP | PHP remote file inclusion vulnerability in lib/php/phphtmllib-2.5.4/examples/example6.php for maintain 3.0.0-RC2 allows remote attackers to execute ar… | Patch early | 10.0 high | 3.6% | 2007-03-06 |
| CVE-2006-3689 EXP | PHP remote file inclusion vulnerability in user-func.php in Codeworks Gnomedia SubberZ[Lite] allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 3.6% | 2006-07-21 |
| CVE-2005-3157 EXP | SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL commands via the msg_send paramete… | Patch early | 7.5 high | 3.6% | 2005-10-06 |
| CVE-2006-2636 EXP | newsadmin.asp in Katy Whitton NewsCMSLite allows remote attackers to bypass authentication and gain administrative access by setting the loggedIn cook… | Patch early | 7.5 high | 3.6% | 2006-05-30 |
| CVE-2007-2503 EXP | Directory traversal vulnerability in turbulence.php in PHP Turbulence 0.0.1 alpha allows remote attackers to include and execute arbitrary local files… | Patch early | 10.0 high | 3.6% | 2007-05-04 |
| CVE-2007-2639 EXP | Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside the TFTP root via unspecified ve… | Patch early | 10.0 high | 3.6% | 2007-05-13 |
| CVE-2006-5402 EXP | Multiple PHP remote file inclusion vulnerabilities in PHPmybibli 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 7.5 high | 3.6% | 2006-10-18 |
| CVE-2013-7375 EXP | SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execute arbitr… | Patch early | 7.5 high | 3.6% | 2014-05-05 |
| CVE-2004-0734 EXP | Web_Store.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter. | Patch early | 7.5 high | 3.6% | 2004-07-27 |
| CVE-2005-1289 EXP | index.cgi in E-Cart 2004 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and possibly (2… | Patch early | 7.5 high | 3.6% | 2005-05-02 |
| CVE-2016-0891 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM before 3.7 allow remote attackers to hijack the aut… | Patch early | 8.8 high | 3.6% | 2016-04-20 |
| CVE-2017-15236 EXP | Tiandy IP cameras 5.56.17.120 do not properly restrict a certain proprietary protocol, which allows remote attackers to read settings via a crafted re… | Patch early | 7.5 high | 3.6% | 2017-10-11 |
| CVE-2006-4103 EXP | PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 3.6% | 2006-08-14 |
| CVE-2006-4365 EXP | Multiple PHP remote file inclusion vulnerabilities in VistaBB 2.0.33 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 3.6% | 2006-08-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt