CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,146 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
150,782 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-2528 EXP | Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation lev… | Patch early | 7.2 high | 3.3% | 2015-09-09 |
| CVE-2008-4614 EXP | PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to create and delete forums, topic… | Patch early | 7.5 high | 3.3% | 2008-10-20 |
| CVE-2006-4373 EXP | PHP remote file inclusion vulnerability in modules/visitors2/include/config.inc.php in pSlash 0.70 allows remote attackers to execute arbitrary PHP co… | Patch early | 7.5 high | 3.3% | 2006-08-26 |
| CVE-2006-4713 EXP | PHP remote file inclusion vulnerability in config.php in PSYWERKS PUMA 1.0 RC2 allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 3.3% | 2006-09-12 |
| CVE-2015-1723 EXP | Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 an… | Patch early | 7.2 high | 3.3% | 2015-06-10 |
| CVE-2007-0200 EXP | PHP remote file inclusion vulnerability in template.php in Geoffrey Golliher Axiom Photo/News Gallery (axiompng) 0.8.6 allows remote attackers to exec… | Patch early | 7.5 high | 3.3% | 2007-01-11 |
| CVE-2017-7314 EXP | An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating a new role, a list of databas… | Patch early | 7.5 high | 3.3% | 2017-06-07 |
| CVE-2016-7454 EXP | CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST allows an att… | Patch early | 8.0 high | 3.3% | 2016-12-17 |
| CVE-2012-2740 EXP | SQL injection vulnerability in public_html/lists/admin in phpList before 2.10.18 allows remote attackers to execute arbitrary SQL commands via the sor… | Patch early | 7.5 high | 3.3% | 2012-09-06 |
| CVE-2025-54769 EXP | An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing.… | Patch early | 8.8 high | 3.3% | 2025-07-29 |
| CVE-2007-0972 EXP | Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload arbitrary files by modifying th… | Patch early | 7.5 high | 3.3% | 2007-02-16 |
| CVE-2008-3363 EXP | Directory traversal vulnerability in user_portal.php in the Dokeos E-Learning System 1.8.5 on Windows allows remote attackers to include and execute a… | Patch early | 7.5 high | 3.3% | 2008-07-30 |
| CVE-2008-3764 EXP | Eval injection vulnerability in globalsoff.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 3.3% | 2008-08-21 |
| CVE-2008-5967 EXP | admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote… | Patch early | 7.5 high | 3.3% | 2009-01-26 |
| CVE-2008-6581 EXP | login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter. | Patch early | 7.5 high | 3.3% | 2009-04-02 |
| CVE-2007-0573 EXP | PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 3.3% | 2007-01-30 |
| CVE-2007-0839 EXP | Multiple PHP remote file inclusion vulnerabilities in index/index_album.php in Valarsoft WebMatic 2.6 allow remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 3.3% | 2007-02-08 |
| CVE-2007-0848 EXP | PHP remote file inclusion vulnerability in classes/class_mail.inc.php in Maian Recipe 1.0 allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 3.3% | 2007-02-08 |
| CVE-2007-1233 EXP | PHP remote file inclusion vulnerability in downloadcounter.php in STWC-Counter 3.4.0.0 and earlier allows remote attackers to execute arbitrary PHP co… | Patch early | 7.5 high | 3.3% | 2007-03-03 |
| CVE-2007-4486 EXP | Multiple PHP remote file inclusion vulnerabilities in index.php in Linkliste 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 3.3% | 2007-08-22 |
| CVE-2003-0961 EXP | Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges. | Patch early | 7.2 high | 3.3% | 2003-12-15 |
| CVE-1999-0745 EXP | Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler. | Patch early | 10.0 high | 3.3% | 1999-08-18 |
| CVE-2006-4672 EXP | PHP remote file inclusion vulnerability in profitCode ppalCart 2.5 EE, possibly a component of PayProCart, allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 3.3% | 2006-09-11 |
| CVE-2006-5192 EXP | PHP remote file inclusion vulnerability in includes/footer.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 3.3% | 2006-10-10 |
| CVE-2007-4368 EXP | SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL c… | Patch early | 7.5 high | 3.3% | 2007-08-15 |
| CVE-2014-9303 EXP | EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and password via a UR… | Patch early | 7.8 high | 3.3% | 2014-12-07 |
| CVE-2007-2262 EXP | Multiple PHP remote file inclusion vulnerabilities in html/php/detail.php in Sinato jmuffin allow remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 3.3% | 2007-04-25 |
| CVE-2007-5822 EXP | Direct static code injection vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to inject arbitrary PHP code into a c… | Patch early | 7.5 high | 3.3% | 2007-11-05 |
| CVE-2015-1724 EXP | Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 an… | Patch early | 7.2 high | 3.3% | 2015-06-10 |
| CVE-2004-0348 EXP | SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId para… | Patch early | 10.0 high | 3.3% | 2004-11-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt