CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,164 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
150,785 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-3980 EXP | SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attackers to execute arbitrary SQL comm… | Patch early | 7.5 high | 3.3% | 2005-12-04 |
| CVE-2012-1199 EXP | Multiple PHP remote file inclusion vulnerabilities in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 3.3% | 2012-02-18 |
| CVE-2026-22241 EXP | The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an arbitrary file upload vulne… | Patch early | 7.2 high | 3.3% | 2026-01-08 |
| CVE-2007-0825 EXP | FlashFXP 3.4.0 build 1145 allows remote servers to cause a denial of service (CPU consumption) via a response to a PWD command that contains a long st… | Patch early | 7.8 high | 3.3% | 2007-02-07 |
| CVE-2005-3518 EXP | SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL commands via the old_searches para… | Patch early | 7.5 high | 3.3% | 2005-11-06 |
| CVE-2015-6171 EXP | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2,… | Patch early | 7.2 high | 3.3% | 2015-12-09 |
| CVE-2006-2005 EXP | Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as… | Patch early | 7.5 high | 3.3% | 2006-04-25 |
| CVE-2008-3211 EXP | Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrative access by setting the cooki… | Patch early | 7.5 high | 3.3% | 2008-07-18 |
| CVE-2008-5042 EXP | Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks via a direct request to admin… | Patch early | 7.5 high | 3.3% | 2008-11-12 |
| CVE-2007-2826 EXP | PHP remote file inclusion vulnerability in lib/addressbook.php in Madirish Webmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 3.3% | 2007-05-22 |
| CVE-2014-8596 EXP | Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) submit_id… | Patch early | 7.5 high | 3.3% | 2014-11-17 |
| CVE-2006-5920 EXP | PHP remote file inclusion vulnerability in common.php in Yuuki Yoshizawa Exporia 0.3.0 allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 3.3% | 2006-11-15 |
| CVE-2006-5951 EXP | PHP remote file inclusion vulnerability in pipe.php in Exophpdesk 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file… | Patch early | 7.5 high | 3.3% | 2006-11-17 |
| CVE-2003-0454 EXP | Multiple buffer overflows in xgalaga 2.0.34 and earlier allow local users to gain privileges via a long HOME environment variable. | Patch early | 7.2 high | 3.3% | 2003-08-07 |
| CVE-2008-5171 EXP | Multiple directory traversal vulnerabilities in admin/minibb/index.php in phpBLASTER CMS 1.0 RC1, when register_globals is enabled, allow remote attac… | Patch early | 9.3 high | 3.3% | 2008-11-19 |
| CVE-2006-6232 EXP | PHP remote file inclusion vulnerability in admin/index.php in DreamAccount 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 3.3% | 2006-12-02 |
| CVE-2006-6789 EXP | PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in Phpbbxtra 2.0 allows remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 3.3% | 2006-12-28 |
| CVE-2006-3928 EXP | PHP remote file inclusion vulnerability in index.php in WMNews 0.2a and earlier allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 3.2% | 2006-07-31 |
| CVE-2006-3969 EXP | PHP remote file inclusion vulnerability in administrator/components/com_colophon/admin.colophon.php in Colophon 1.2 and earlier for Joomla! allows rem… | Patch early | 7.5 high | 3.2% | 2006-08-01 |
| CVE-2006-3984 EXP | PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later versions, with phpAdsNew 2.0.5, al… | Patch early | 7.5 high | 3.2% | 2006-08-05 |
| CVE-2006-4240 EXP | PHP remote file inclusion vulnerability in index.php in Fusion News 3.7 allows remote attackers to execute arbitrary PHP code via a URL in the fpath p… | Patch early | 7.5 high | 3.2% | 2006-08-21 |
| CVE-2006-4276 EXP | PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR… | Patch early | 7.5 high | 3.2% | 2006-08-21 |
| CVE-2006-4321 EXP | PHP remote file inclusion vulnerability in cpg.php in the Coppermine Photo Gallery component (com_cpg) 1.0 and earlier for Mambo allows remote attacke… | Patch early | 7.5 high | 3.2% | 2006-08-24 |
| CVE-2006-4354 EXP | PHP remote file inclusion vulnerability in e/class/CheckLevel.php in Phome Empire CMS 3.7 and earlier allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 3.2% | 2006-08-27 |
| CVE-2006-4452 EXP | PHP remote file inclusion vulnerability in security/include/_class.security.php in Web3news 0.95 and earlier, when register_globals is enabled, allows… | Patch early | 7.5 high | 3.2% | 2006-08-30 |
| CVE-2006-4589 EXP | PHP remote file inclusion vulnerability in 0_admin/modules/Wochenkarte/frontend/index.php in DynCMS 6 and earlier allows remote attackers to execute a… | Patch early | 7.5 high | 3.2% | 2006-09-06 |
| CVE-2006-4647 EXP | PHP remote file inclusion vulnerability in news.php in Sponge News 2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 3.2% | 2006-09-08 |
| CVE-2006-2261 EXP | PHP remote file inclusion vulnerability in day.php in ACal 2.2.6 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter… | Patch early | 7.5 high | 3.2% | 2006-05-09 |
| CVE-2006-2361 EXP | PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote a… | Patch early | 7.5 high | 3.2% | 2006-05-15 |
| CVE-2006-5147 EXP | PHP remote file inclusion vulnerability in wamp_dir/setup/yesno.phtml in VAMP Webmail 2.0beta1 and earlier allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 3.2% | 2006-10-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt