CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,932 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
150,779 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-0513 EXP | Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote attackers to read arbitrary files via a .. (d… | Patch early | 7.8 high | 3.5% | 2008-01-31 |
| CVE-2004-2071 EXP | Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authentication in the web interface via a… | Patch early | 7.5 high | 3.5% | 2004-12-31 |
| CVE-2005-0854 EXP | betaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload files via a direct request to… | Patch early | 7.5 high | 3.5% | 2005-05-02 |
| CVE-2006-5281 EXP | PHP remote file inclusion vulnerability in naboard_pnr.php in n@board 3.1.9e and earlier allows remote attackers to execute arbitrary PHP code via a U… | Patch early | 7.5 high | 3.5% | 2006-10-13 |
| CVE-2006-5863 EXP | PHP remote file inclusion vulnerability in inc/session.php for LetterIt 2 allows remote attackers to execute arbitrary PHP code via a URL in the lang… | Patch early | 7.5 high | 3.5% | 2006-11-11 |
| CVE-2007-1600 EXP | PHP remote file inclusion vulnerability in module.php in Digital Eye Gallery 1.1 Beta (aka 0.1.1b) allows remote attackers to execute arbitrary PHP co… | Patch early | 9.3 high | 3.5% | 2007-03-22 |
| CVE-2007-4007 EXP | PHP remote file inclusion vulnerability in index.php in Article Directory (Article Site Directory) allows remote attackers to execute arbitrary PHP co… | Patch early | 9.3 high | 3.5% | 2007-07-26 |
| CVE-2004-2161 EXP | SQL injection vulnerability in file_overview.php in TUTOS 1.1 allows remote attackers to execute arbitrary SQL commands via the link_id parameter. | Patch early | 7.5 high | 3.5% | 2004-12-31 |
| CVE-2007-2843 EXP | Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demons… | Patch early | 10.0 high | 3.5% | 2007-05-24 |
| CVE-2018-12603 EXP | Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users… | Patch early | 8.8 high | 3.5% | 2018-06-25 |
| CVE-2006-5893 EXP | Multiple PHP remote file inclusion vulnerabilities in iWonder Designs Storystream 0.4.0.0 allow remote attackers to execute arbitrary PHP code via a U… | Patch early | 7.5 high | 3.5% | 2006-11-14 |
| CVE-2006-6154 EXP | PHP remote file inclusion vulnerability in addcode.php in HIOX Star Rating System Script (HSRS) 1.0 and earlier allows remote attackers to execute arb… | Patch early | 7.5 high | 3.5% | 2006-11-28 |
| CVE-2006-6867 EXP | Multiple PHP remote file inclusion vulnerabilities in Vladimir Menshakov buratinable templator (aka bubla) 0.9.1 allow remote attackers to execute arb… | Patch early | 7.5 high | 3.5% | 2006-12-31 |
| CVE-2017-7447 EXP | HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code. | Patch early | 8.8 high | 3.5% | 2017-04-05 |
| CVE-2000-1186 EXP | Buffer overflow in phf CGI program allows remote attackers to execute arbitrary commands by specifying a large number of arguments and including a lon… | Patch early | 7.5 high | 3.5% | 2001-01-09 |
| CVE-2006-7148 EXP | PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to execute arb… | Patch early | 10.0 high | 3.5% | 2007-03-07 |
| CVE-2012-4335 EXP | Samsung NET-i viewer 1.37.120316 allows remote attackers to cause a denial of service (infinite loop) via a negative size value in a TCP request to (1… | Patch early | 7.8 high | 3.5% | 2012-08-14 |
| CVE-2000-0257 EXP | Buffer overflow in the NetWare remote web administration utility allows remote attackers to cause a denial of service or execute commands via a long U… | Patch early | 7.5 high | 3.5% | 2000-04-19 |
| CVE-2009-3322 EXP | The Siemens Gigaset SE361 WLAN router allows remote attackers to cause a denial of service (device reboot) via a flood of crafted TCP packets to port… | Patch early | 7.8 high | 3.5% | 2009-09-23 |
| CVE-2014-9240 EXP | SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL commands v… | Patch early | 7.5 high | 3.5% | 2014-12-03 |
| CVE-2018-18772 EXP | CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbi… | Patch early | 8.8 high | 3.5% | 2018-11-20 |
| CVE-2018-6941 EXP | A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunctio… | Patch early | 8.8 high | 3.5% | 2018-02-20 |
| CVE-2015-1722 EXP | Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 an… | Patch early | 7.2 high | 3.5% | 2015-06-10 |
| CVE-2006-6538 EXP | D-LINK DWL-2000AP+ firmware 2.11 allows remote attackers to cause (1) a denial of service (device reset) via a flood of ARP replies on the wired or wi… | Patch early | 7.8 high | 3.5% | 2006-12-14 |
| CVE-2007-2507 EXP | Directory traversal vulnerability in includes/download.php in Treble Designs 1024 CMS 0.7 allows remote attackers to read arbitrary files via a .. (do… | Patch early | 7.8 high | 3.5% | 2007-05-04 |
| CVE-2005-3363 EXP | SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to execute arbitrary SQL commands vi… | Patch early | 7.5 high | 3.5% | 2005-10-30 |
| CVE-2017-6366 EXP | Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijack… | Patch early | 8.8 high | 3.5% | 2017-03-15 |
| CVE-1999-0943 EXP | Buffer overflow in OpenLink 3.2 allows remote attackers to gain privileges via a long GET request to the web configurator. | Patch early | 10.0 high | 3.5% | 1999-10-15 |
| CVE-1999-0973 EXP | Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode. | Patch early | 10.0 high | 3.5% | 1999-12-07 |
| CVE-2006-5055 EXP | PHP remote file inclusion vulnerability in admin/testing/tests/0004_init_urls.php in syntaxCMS 1.1.1 through 1.3 allows remote attackers to execute ar… | Patch early | 7.5 high | 3.5% | 2006-09-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt