CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,413 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
187,448 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-2474 EXP | Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 6.2% | 2007-05-02 |
| CVE-2009-1368 EXP | Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parame… | Patch early | 7.5 high | 6.2% | 2009-04-22 |
| CVE-2021-43650 EXP | WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process. | Patch early | 9.8 critical | 6.2% | 2022-03-22 |
| CVE-2004-0290 EXP | Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that contains large (1… | Patch early | 10.0 high | 6.1% | 2004-11-23 |
| CVE-2005-2367 EXP | Format string vulnerability in the proto_item_set_text function in Ethereal 0.9.4 through 0.10.11, as used in multiple dissectors, allows remote attac… | Patch early | 7.5 high | 6.1% | 2005-08-10 |
| CVE-2016-3219 EXP | The kernel-mode driver in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of… | Patch early | 7.8 high | 6.1% | 2016-06-16 |
| CVE-2020-7750 EXP | This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can… | Patch early | 9.6 critical | 6.1% | 2020-10-21 |
| CVE-2018-7466 EXP | install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES dat… | Patch early | 7.5 high | 6.1% | 2018-02-25 |
| CVE-2007-3167 EXP | Stack-based buffer overflow in the Vivotek Motion Jpeg ActiveX control (aka MjpegControl) in MjpegDecoder.dll 2.0.0.13 allows remote attackers to exec… | Patch early | 7.6 high | 6.1% | 2007-06-11 |
| CVE-2007-2761 EXP | Stack-based buffer overflow in MagicISO 5.4 build 239 and earlier allows remote attackers to execute arbitrary code via a long filename in a .cue file… | Patch early | 7.5 high | 6.1% | 2007-05-18 |
| CVE-2009-3306 EXP | PHP remote file inclusion vulnerability in include/header.php in ClearSite 4.50 allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 6.1% | 2009-09-23 |
| CVE-2008-6143 EXP | OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account name in the username cookie. | Patch early | 7.5 high | 6.1% | 2009-02-16 |
| CVE-1999-0238 EXP | php.cgi allows attackers to read any file on the system. | Patch early | 10.0 high | 6.1% | 1997-08-01 |
| CVE-2009-1610 EXP | admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator password and gain administrator priv… | Patch early | 7.5 high | 6.1% | 2009-05-11 |
| CVE-2009-0457 EXP | Multiple directory traversal vulnerabilities in AJA Portal 1.2 allow remote attackers to include and execute arbitrary local files via directory trave… | Patch early | 7.5 high | 6.1% | 2009-02-10 |
| CVE-2002-0855 EXP | Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscript… | Patch early | 7.5 high | 6.1% | 2002-09-05 |
| CVE-2000-1046 EXP | Multiple buffer overflows in the ESMTP service of Lotus Domino 5.0.2c and earlier allow remote attackers to cause a denial of service and possibly exe… | Patch early | 10.0 high | 6.1% | 2000-12-11 |
| CVE-2009-2363 EXP | Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls playlist file with a playlist… | Patch early | 9.3 high | 6.1% | 2009-07-08 |
| CVE-2009-1652 EXP | admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and add… | Patch early | 7.5 high | 6.1% | 2009-05-16 |
| CVE-2006-7068 EXP | PHP remote file inclusion vulnerability in CliServ Web Community 0.65 and earlier allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 7.5 high | 6.1% | 2007-03-02 |
| CVE-2001-0029 EXP | Buffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrary commands via a long host or… | Patch early | 10.0 high | 6.1% | 2001-02-12 |
| CVE-2018-6221 EXP | An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle attacker to tamper with an up… | Patch early | 8.1 high | 6.1% | 2018-03-15 |
| CVE-2002-2420 EXP | site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter. | Patch early | 7.5 high | 6.1% | 2002-12-31 |
| CVE-2007-4838 EXP | Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via a long string in a (1) 0x21,… | Patch early | 7.5 high | 6.1% | 2007-09-12 |
| CVE-2012-2998 EXP | SQL injection vulnerability in the ad hoc query module in Trend Micro Control Manager (TMCM) before 5.5.0.1823 and 6.0 before 6.0.0.1449 allows remote… | Patch early | 7.5 high | 6.1% | 2012-09-28 |
| CVE-2007-1992 EXP | Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote attackers to execute arbitrary… | Patch early | 7.5 high | 6.1% | 2007-04-12 |
| CVE-2007-2301 EXP | Multiple PHP remote file inclusion vulnerabilities in audioCMS arash 0.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the arash… | Patch early | 7.5 high | 6.1% | 2007-04-26 |
| CVE-2007-2313 EXP | PHP remote file inclusion vulnerability in getinfo1.php in the Shotcast 1.0 RC2 module for mxBB allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 6.1% | 2007-04-26 |
| CVE-2007-2345 EXP | PHP remote file inclusion vulnerability in include/include_stream.inc.php in CodeWand phpBrowse allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 6.1% | 2007-04-27 |
| CVE-2007-5771 EXP | Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie. | Patch early | 7.5 high | 6.1% | 2007-11-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt