CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,166 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
150,786 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-2722 EXP | Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instability) via certain invalid string… | Patch early | 7.8 high | 3.2% | 2007-05-16 |
| CVE-2007-2671 EXP | Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in an HREF attribute in an A elem… | Patch early | 7.1 high | 3.2% | 2007-05-14 |
| CVE-2025-7795 EXP | A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the function fromP2pListFilter of… | Patch early | 8.8 high | 3.2% | 2025-07-18 |
| CVE-1999-0968 EXP | Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges. | Patch early | 7.5 high | 3.2% | 1998-12-26 |
| CVE-2008-7064 EXP | Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5,… | Patch early | 7.5 high | 3.2% | 2009-08-25 |
| CVE-2023-0905 EXP | A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the fi… | Patch early | 7.3 high | 3.2% | 2023-02-18 |
| CVE-2001-0365 EXP | Eudora before 5.1 allows a remote attacker to execute arbitrary code, when the 'Use Microsoft Viewer' and 'allow executables in HTML content' options… | Patch early | 7.5 high | 3.2% | 2001-06-27 |
| CVE-2006-5053 EXP | PHP remote file inclusion vulnerability in webnews/template.php in Web-News 1.6.3 and earlier allows remote attackers to execute arbitrary PHP code vi… | Patch early | 7.5 high | 3.2% | 2006-09-28 |
| CVE-2006-5061 EXP | PHP remote file inclusion vulnerability in mcf.php in Advanced-Clan-Script (AVCX) 3.4 and earlier allows remote attackers to execute arbitrary PHP cod… | Patch early | 7.5 high | 3.2% | 2006-09-28 |
| CVE-2006-5304 EXP | PHP remote file inclusion vulnerability in inc/settings.php in IncCMS Core 1.0.0 and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 3.2% | 2006-10-17 |
| CVE-2006-5413 EXP | Multiple PHP remote file inclusion vulnerabilities in SuperMod 3.0.0 for YABB (YaBBSM) allow remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 3.2% | 2006-10-20 |
| CVE-2006-5555 EXP | PHP remote file inclusion vulnerability in constantes.inc.php in EPNadmin 0.7 and 0.7.1 allows remote attackers to execute arbitrary PHP code via the… | Patch early | 7.5 high | 3.2% | 2006-10-26 |
| CVE-2006-5670 EXP | PHP remote file inclusion vulnerability in forgot_pass.php in Free Image Hosting 1.0 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 3.2% | 2006-11-03 |
| CVE-2006-5841 EXP | Multiple PHP remote file inclusion vulnerabilities in dodosmail.php in DodosMail 2.0.1 and earlier, and possibly 2.1, allow remote attackers to execut… | Patch early | 7.5 high | 3.2% | 2006-11-10 |
| CVE-2024-6244 EXP | The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users pe… | Patch early | 8.8 high | 3.2% | 2024-07-22 |
| CVE-2008-1245 EXP | cgi-bin/setup_virtualserver.exe on the Belkin F5D7230-4 router with firmware 9.01.10 allows remote attackers to cause a denial of service (control cen… | Patch early | 7.8 high | 3.2% | 2008-03-10 |
| CVE-2008-6122 EXP | The web management interface in Netgear WGR614v9 allows remote attackers to cause a denial of service (crash) via a request that contains a question m… | Patch early | 7.8 high | 3.2% | 2009-02-11 |
| CVE-2007-2416 EXP | SQL injection vulnerability in home.php in E-Annu allows remote attackers to execute arbitrary SQL commands via the a parameter. | Patch early | 7.5 high | 3.2% | 2007-05-01 |
| CVE-2006-3158 EXP | index.php in Eduha Meeting does not properly restrict file extensions before permitting a file upload, which allows remote attackers to bypass securit… | Patch early | 7.5 high | 3.2% | 2006-06-22 |
| CVE-2006-5948 EXP | PHP remote file inclusion vulnerability in pntUnit/Inspect.php in phpPeanuts 1.1 and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 3.2% | 2006-11-17 |
| CVE-2006-6516 EXP | Multiple PHP remote file inclusion vulnerabilities in KDPics 1.16 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1… | Patch early | 7.5 high | 3.2% | 2006-12-14 |
| CVE-2006-5249 EXP | PHP remote file inclusion vulnerability in tagmin/delTagUser.php in TagIt! Tagboard 2.1.B Build 2 (tagit2b) allows remote attackers to execute arbitra… | Patch early | 7.5 high | 3.2% | 2006-10-12 |
| CVE-2021-29460 EXP | Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful content like `<script>` tags.… | Patch early | 7.6 high | 3.2% | 2021-04-27 |
| CVE-2006-4122 EXP | Simple one-file guestbook 1.0 and earlier allows remote attackers to bypass authentication and delete guestbook entries via a modified id parameter to… | Patch early | 7.5 high | 3.2% | 2006-08-14 |
| CVE-2007-2019 EXP | PHP remote file inclusion vulnerability in init.gallery.php in phpGalleryScript 1.0 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 3.2% | 2007-04-12 |
| CVE-2007-4925 EXP | The ewirePC_Decrypt function in ewirepcfunctions.php in eWire Payment Client (ePC) 1.60 and 1.70 allows remote attackers to execute arbitrary commands… | Patch early | 7.5 high | 3.2% | 2007-09-18 |
| CVE-2007-1165 EXP | Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the dbs_base_p… | Patch early | 7.5 high | 3.2% | 2007-03-02 |
| CVE-2003-0560 EXP | SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter. | Patch early | 10.0 high | 3.2% | 2003-08-18 |
| CVE-2006-4733 EXP | PHP remote file inclusion vulnerability in sipssys/code/box.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) 0.3.1 and earlier all… | Patch early | 7.5 high | 3.2% | 2006-09-13 |
| CVE-2006-5314 EXP | PHP remote file inclusion vulnerability in ftag.php in TribunaLibre 3.12 Beta allows remote attackers to execute arbitrary PHP code via a URL in the m… | Patch early | 7.5 high | 3.2% | 2006-10-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt