CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,879 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
208,007 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-3685 EXP | PHP remote file inclusion vulnerability in CzarNews 1.12 through 1.14 allows remote attackers to execute arbitrary PHP code via a URL in the tpath par… | Patch early | 5.1 medium | 2.8% | 2006-07-21 |
| CVE-2003-1427 EXP | Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as th… | Patch early | 6.4 medium | 2.8% | 2003-12-31 |
| CVE-2009-5093 EXP | Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in t… | Patch early | 5.0 medium | 2.8% | 2011-09-12 |
| CVE-2008-4181 EXP | Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Registe… | Patch early | 6.8 medium | 2.8% | 2008-09-23 |
| CVE-2006-4068 EXP | The pswd.js script relies on the client to calculate whether a username and password match hard-coded hashed values for a server, and uses a hashing s… | Patch early | 5.0 medium | 2.8% | 2006-08-10 |
| CVE-2006-0687 EXP | process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote attackers to include arb… | Patch early | 5.0 medium | 2.8% | 2006-02-15 |
| CVE-2012-1664 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 2.8% | 2015-05-20 |
| CVE-2014-4717 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote attackers to… | Patch early | 6.8 medium | 2.8% | 2014-07-03 |
| CVE-2009-1514 EXP | Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a throw statement w… | Patch early | 5.0 medium | 2.8% | 2009-05-04 |
| CVE-2010-5240 EXP | Multiple untrusted search path vulnerabilities in Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 allow local users to gain privileges via a Trojan hors… | Patch early | 6.9 medium | 2.8% | 2012-09-07 |
| CVE-2007-2900 EXP | Multiple PHP remote file inclusion vulnerabilities in Scallywag 2005-04-25 allow remote attackers to execute arbitrary PHP code via a URL in the path… | Patch early | 6.8 medium | 2.8% | 2007-05-30 |
| CVE-2007-6585 EXP | PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to execute arbitrary PHP code via… | Patch early | 6.8 medium | 2.8% | 2007-12-28 |
| CVE-2005-1423 EXP | Directory traversal vulnerability in the mail program in 602LAN SUITE 2004.0.05.0413 allows remote attackers to cause a denial of service and determin… | Patch early | 6.4 medium | 2.8% | 2005-05-03 |
| CVE-2006-4671 EXP | PHP remote file inclusion vulnerability in headlines.php in Fantastic News 2.1.4, and possibly earlier, allows remote attackers to execute arbitrary P… | Patch early | 6.8 medium | 2.8% | 2006-09-11 |
| CVE-2014-9001 EXP | reminders/index.php in Incredible PBX 11 2.0.6.5.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1)… | Patch early | 6.5 medium | 2.8% | 2014-11-20 |
| CVE-2014-5090 EXP | admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location f… | Patch early | 6.5 medium | 2.8% | 2014-08-06 |
| CVE-2003-1430 EXP | Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an… | Patch early | 5.0 medium | 2.8% | 2003-12-31 |
| CVE-2006-5428 EXP | rpc.php in Cerberus Helpdesk 3.2.1 does not verify a client's privileges for a display_get_requesters operation, which allows remote attackers to bypa… | Patch early | 5.0 medium | 2.8% | 2006-10-20 |
| CVE-2007-4330 EXP | PHP remote file inclusion vulnerability in shoutbox.php in Shoutbox 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the root pa… | Patch early | 6.8 medium | 2.8% | 2007-08-14 |
| CVE-2017-9516 EXP | Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file. | Patch early | 5.4 medium | 2.8% | 2017-06-08 |
| CVE-2001-0163 EXP | Cisco AP340 base station produces predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections. | Patch early | 4.6 medium | 2.8% | 2001-01-01 |
| CVE-2012-0031 EXP | scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possi… | Patch early | 4.6 medium | 2.8% | 2012-01-18 |
| CVE-2022-45297 EXP | EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter. | Patch early | 9.8 critical | 2.8% | 2023-01-31 |
| CVE-2007-5173 EXP | PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote attackers to execute arbitrary… | Patch early | 6.8 medium | 2.8% | 2007-10-03 |
| CVE-2007-6397 EXP | Multiple directory traversal vulnerabilities in index.php in Flat PHP Board 1.2 and earlier allow remote attackers to (1) create arbitrary files via a… | Patch early | 5.0 medium | 2.8% | 2007-12-17 |
| CVE-2006-2947 EXP | Dmx Forum 2.1a allows remote attackers to obtain username and password information via a direct request to pops/edit.php with a modified membre parame… | Patch early | 5.0 medium | 2.8% | 2006-06-12 |
| CVE-2009-4088 EXP | Multiple directory traversal vulnerabilities in telepark.wiki 2.4.23 and earlier allow remote attackers to read arbitrary files via directory traversa… | Patch early | 6.8 medium | 2.8% | 2009-11-29 |
| CVE-2009-3561 EXP | Directory traversal vulnerability in Xerver HTTP Server 4.32 allows remote attackers to read arbitrary files via a full pathname with a drive letter i… | Patch early | 5.0 medium | 2.8% | 2009-10-05 |
| CVE-2007-0311 EXP | Texas Imperial Software WFTPD and WFTPD Pro Server 3.25 and earlier allow remote attackers to cause a denial of service (application crash) via a long… | Patch early | 5.0 medium | 2.8% | 2007-01-18 |
| CVE-2006-6045 EXP | Multiple PHP remote file inclusion vulnerabilities in Comdev One Admin Pro 4.1 allow remote attackers to execute arbitrary PHP code via a URL in the p… | Patch early | 6.8 medium | 2.8% | 2006-11-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt