CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,146 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
150,782 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-3139 EXP | recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth parameter to a… | Patch early | 7.5 high | 3.3% | 2014-05-02 |
| CVE-2002-2176 EXP | SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profile… | Patch early | 10.0 high | 3.3% | 2002-12-31 |
| CVE-2007-0757 EXP | PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and earlier allows remote attackers t… | Patch early | 7.5 high | 3.3% | 2007-02-06 |
| CVE-2007-0762 EXP | PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Build 100 allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 3.3% | 2007-02-06 |
| CVE-2007-0837 EXP | PHP remote file inclusion vulnerability in examples/inc/top.inc.php in AgerMenu 0.03 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 3.3% | 2007-02-08 |
| CVE-2015-2554 EXP | The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain pr… | Patch early | 7.2 high | 3.3% | 2015-10-14 |
| CVE-2004-0239 EXP | SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo va… | Patch early | 10.0 high | 3.3% | 2004-11-23 |
| CVE-2018-8214 EXP | An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Brid… | Patch early | 7.0 high | 3.3% | 2018-06-14 |
| CVE-2024-51774 EXP | qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors. | Patch early | 8.1 high | 3.3% | 2024-11-02 |
| CVE-2006-6566 EXP | PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module for mxBB 0.91c allows remote a… | Patch early | 7.5 high | 3.3% | 2006-12-15 |
| CVE-2024-0566 EXP | The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQ… | Patch early | 7.2 high | 3.3% | 2024-02-12 |
| CVE-2006-1183 EXP | The Ubuntu 5.10 installer does not properly clear passwords from the installer log file (questions.dat), and leaves the log file with world-readable p… | Patch early | 7.2 high | 3.3% | 2006-03-13 |
| CVE-2007-2273 EXP | PHP remote file inclusion vulnerability in include/loading.php in Alessandro Lulli wavewoo 0.1.1 allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 3.3% | 2007-04-25 |
| CVE-2017-8852 EXP | SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file received from an untrusted re… | Patch early | 7.8 high | 3.3% | 2017-05-10 |
| CVE-2006-4368 EXP | PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows remote attackers to execute arbit… | Patch early | 7.5 high | 3.3% | 2006-08-26 |
| CVE-2015-1721 EXP | The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows… | Patch early | 7.2 high | 3.3% | 2015-06-10 |
| CVE-2006-6910 EXP | formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a denial of service (daemon cra… | Patch early | 7.8 high | 3.3% | 2006-12-31 |
| CVE-2018-8550 EXP | An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows 7, W… | Patch early | 7.8 high | 3.3% | 2018-11-14 |
| CVE-2006-3736 EXP | PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to ex… | Patch early | 7.5 high | 3.3% | 2006-07-21 |
| CVE-2007-4524 EXP | PHP remote file inclusion vulnerability in adisplay.php in PhPress 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the lang p… | Patch early | 7.5 high | 3.3% | 2007-08-25 |
| CVE-2007-1078 EXP | PHP remote file inclusion vulnerability in index.php in FlashGameScript 1.5.4 allows remote attackers to execute arbitrary PHP code via a URL in the f… | Patch early | 7.5 high | 3.3% | 2007-02-22 |
| CVE-2006-4966 EXP | PHP remote file inclusion vulnerability in inc/ifunctions.php in chumpsoft phpQuestionnaire (phpQ) 3.12 allows remote attackers to execute arbitrary P… | Patch early | 7.5 high | 3.3% | 2006-09-25 |
| CVE-2006-5259 EXP | PHP remote file inclusion vulnerability in param_editor.php in Compteur 2 allows remote attackers to execute arbitrary PHP code via a URL in the folde… | Patch early | 7.5 high | 3.3% | 2006-10-12 |
| CVE-2006-5309 EXP | PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and earlier module for phpBB allows… | Patch early | 7.5 high | 3.3% | 2006-10-17 |
| CVE-2006-5318 EXP | PHP remote file inclusion vulnerability in index.php in Nayco JASmine (aka Jasmine-Web) allows remote attackers to execute arbitrary PHP code via an F… | Patch early | 7.5 high | 3.3% | 2006-10-17 |
| CVE-2006-5385 EXP | PHP remote file inclusion vulnerability in admin/admin_spam.php in the SpamOborona 1.0b and earlier phpBB module allows remote attackers to execute ar… | Patch early | 7.5 high | 3.3% | 2006-10-18 |
| CVE-2006-5387 EXP | PHP remote file inclusion vulnerability in mods/iai/includes/constants.php in the PlusXL 20_272 and earlier phpBB module allows remote attackers to ex… | Patch early | 7.5 high | 3.3% | 2006-10-18 |
| CVE-2006-5415 EXP | PHP remote file inclusion vulnerability in includes/functions_newshr.php in the News Defilante Horizontale 4.1.1 and earlier module for phpBB allows r… | Patch early | 7.5 high | 3.3% | 2006-10-20 |
| CVE-2006-5497 EXP | PHP remote file inclusion vulnerability in themes/program/themesettings.inc.php in Segue CMS 1.5.8 and earlier, when register_globals is enabled, allo… | Patch early | 7.5 high | 3.3% | 2006-10-25 |
| CVE-2006-5795 EXP | Multiple PHP remote file inclusion vulnerabilities in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allow remote attackers to execute a… | Patch early | 7.5 high | 3.3% | 2006-11-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt