CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,932 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
150,708 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-5087 EXP | Multiple PHP remote file inclusion vulnerabilities in evoBB 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path… | Patch early | 7.5 high | 3.6% | 2006-09-29 |
| CVE-2013-6041 EXP | index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cooki… | Patch early | 7.5 high | 3.6% | 2014-12-27 |
| CVE-2008-3375 EXP | The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrativ… | Patch early | 7.5 high | 3.6% | 2008-07-30 |
| CVE-2007-0677 EXP | PHP remote file inclusion vulnerability in fw/class.Quick_Config_Browser.php in Cadre PHP Framework 20020724 allows remote attackers to execute arbitr… | Patch early | 7.5 high | 3.6% | 2007-02-03 |
| CVE-2007-3192 EXP | admin/setup.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to read and modify configuration settings via a direc… | Patch early | 9.4 high | 3.6% | 2007-06-12 |
| CVE-2008-4624 EXP | PHP remote file inclusion vulnerability in init.php in Fast Click SQL Lite 1.1.7, when register_globals is enabled, allows remote attackers to execute… | Patch early | 9.3 high | 3.6% | 2008-10-21 |
| CVE-2005-0959 EXP | Buffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a long path. | Patch early | 7.5 high | 3.6% | 2005-05-02 |
| CVE-2007-5117 EXP | Multiple PHP remote file inclusion vulnerabilities in FrontAccounting (FA) 1.13, when register_globals is enabled, allow remote attackers to execute a… | Patch early | 9.3 high | 3.6% | 2007-09-27 |
| CVE-2006-6341 EXP | Multiple PHP remote file inclusion vulnerabilities in mg.applanix 1.3.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 3.6% | 2006-12-07 |
| CVE-2009-0120 EXP | The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by se… | Patch early | 7.8 high | 3.6% | 2009-01-15 |
| CVE-2008-7001 EXP | Unrestricted file upload vulnerability in the file manager in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary code via unkn… | Patch early | 7.5 high | 3.6% | 2009-08-19 |
| CVE-2002-2425 EXP | Sun AnswerBook2 1.2 through 1.4.2 allows remote attackers to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a dir… | Patch early | 10.0 high | 3.5% | 2002-12-31 |
| CVE-2008-3455 EXP | PHP remote file inclusion vulnerability in include/admin.php in JnSHosts PHP Hosting Directory 2.0 allows remote attackers to execute arbitrary PHP co… | Patch early | 10.0 high | 3.5% | 2008-08-04 |
| CVE-2008-4704 EXP | PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 10.0 high | 3.5% | 2008-10-23 |
| CVE-2008-5066 EXP | PHP remote file inclusion vulnerability in upload/admin/frontpage_right.php in Agares Media ThemeSiteScript 1.0 allows remote attackers to execute arb… | Patch early | 10.0 high | 3.5% | 2008-11-13 |
| CVE-2006-5256 EXP | PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 3.5% | 2006-10-12 |
| CVE-2006-5527 EXP | PHP remote file inclusion vulnerability in lib.editor.inc.php in Intelimen InteliEditor 1.2.x allows remote attackers to execute arbitrary PHP code vi… | Patch early | 7.5 high | 3.5% | 2006-10-26 |
| CVE-2006-5796 EXP | Multiple PHP remote file inclusion vulnerabilities in Soholaunch Pro Edition 4.9 r46 and earlier, when register_globals is enabled, allow remote attac… | Patch early | 7.5 high | 3.5% | 2006-11-08 |
| CVE-2001-0490 EXP | Buffer overflow in WINAMP 2.6x and 2.7x allows attackers to execute arbitrary code via a long string in an AIP file. | Patch early | 7.5 high | 3.5% | 2001-06-27 |
| CVE-2003-0315 EXP | Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP request, whi… | Patch early | 7.5 high | 3.5% | 2003-06-16 |
| CVE-2008-0600 EXP | The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows l… | Patch early | 7.2 high | 3.5% | 2008-02-12 |
| CVE-2008-3371 EXP | Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remote attackers to include and exe… | Patch early | 7.5 high | 3.5% | 2008-07-30 |
| CVE-2008-0251 EXP | Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown v… | Patch early | 10.0 high | 3.5% | 2008-01-12 |
| CVE-2006-5243 EXP | Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Doc 1.4 and earlier, when register_globals is enabled, allow remote attackers to e… | Patch early | 7.5 high | 3.5% | 2006-10-12 |
| CVE-2013-2580 EXP | Unrestricted file upload vulnerability in cgi-bin/uploadfile in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other mo… | Patch early | 7.1 high | 3.5% | 2013-10-11 |
| CVE-2019-0959 EXP | An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker… | Patch early | 7.0 high | 3.5% | 2019-06-12 |
| CVE-2016-6253 EXP | mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary file… | Patch early | 7.8 high | 3.5% | 2017-01-20 |
| CVE-2008-2672 EXP | Multiple directory traversal vulnerabilities in ErfurtWiki R1.02b and earlier, when register_globals is enabled, allow remote attackers to include and… | Patch early | 7.5 high | 3.5% | 2008-06-12 |
| CVE-2010-3081 EXP | The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly all… | Patch early | 7.8 high | 3.5% | 2010-09-24 |
| CVE-2007-1930 EXP | Directory traversal vulnerability in download2.php in cattaDoc 2.21, and possibly other versions including 3.0, allows remote attackers to read arbitr… | Patch early | 7.8 high | 3.5% | 2007-04-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt