CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,169 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
150,786 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-0684 EXP | change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, wh… | Patch early | 7.5 high | 3.1% | 2006-02-15 |
| CVE-2013-1453 EXP | plugins/system/highlight/highlight.php in Joomla! 3.0.x through 3.0.2 and 2.5.x through 2.5.8 allows attackers to unserialize arbitrary PHP objects to… | Patch early | 7.5 high | 3.1% | 2013-02-13 |
| CVE-2003-0004 EXP | Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter. | Patch early | 7.2 high | 3.1% | 2003-02-19 |
| CVE-2007-2094 EXP | PHP remote file inclusion vulnerability in index.php in Anthologia 0.5.2 allows remote attackers to execute arbitrary PHP code via a URL in the ads_fi… | Patch early | 7.5 high | 3.1% | 2007-04-18 |
| CVE-2007-2346 EXP | Multiple PHP remote file inclusion vulnerabilities in PHP-Generics 1.0 beta allow remote attackers to execute arbitrary PHP code via a URL in the _APP… | Patch early | 7.5 high | 3.1% | 2007-04-27 |
| CVE-2007-2743 EXP | PHP remote file inclusion vulnerability in custom_vars.php in GlossWord 1.8.1 allows remote attackers to execute arbitrary PHP code via a URL in the s… | Patch early | 7.5 high | 3.1% | 2007-05-17 |
| CVE-2007-3160 EXP | PHP remote file inclusion vulnerability in admin/header.php in PHP Real Estate Classifieds Premium Plus allows remote attackers to execute arbitrary P… | Patch early | 7.5 high | 3.1% | 2007-06-11 |
| CVE-2009-4752 EXP | PHP remote file inclusion vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 3.1% | 2010-03-26 |
| CVE-2002-1757 EXP | PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for scripts via… | Patch early | 7.5 high | 3.1% | 2002-12-31 |
| CVE-2014-8425 EXP | The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files. | Patch early | 7.8 high | 3.1% | 2014-11-28 |
| CVE-2007-2205 EXP | PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers… | Patch early | 7.5 high | 3.1% | 2007-04-24 |
| CVE-2020-8495 EXP | In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an attacker with… | Patch early | 7.5 high | 3.1% | 2020-01-30 |
| CVE-2008-0433 EXP | PHP remote file inclusion vulnerability in theme/phpAutoVideo/LightTwoOh/sidebar.php in Agares phpAutoVideo 2.21 and earlier allows remote attackers t… | Patch early | 7.5 high | 3.1% | 2008-01-23 |
| CVE-1999-0382 EXP | The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated p… | Patch early | 7.2 high | 3.1% | 1999-03-12 |
| CVE-2008-5167 EXP | PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals is enabled, allows remote att… | Patch early | 9.3 high | 3.1% | 2008-11-19 |
| CVE-2008-1000 EXP | Directory traversal vulnerability in ContentServer.py in the Wiki Server in Apple Mac OS X 10.5.2 (aka Leopard) allows remote authenticated users to w… | Patch early | 8.5 high | 3.1% | 2008-03-18 |
| CVE-2017-8926 EXP | Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte… | Patch early | 7.8 high | 3.1% | 2017-05-15 |
| CVE-2018-7746 EXP | An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/channel/modifychannel. For example,… | Patch early | 8.8 high | 3.1% | 2018-03-07 |
| CVE-2007-2420 EXP | SQL injection vulnerability in bry.asp in Burak Yilmaz Blog 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Patch early | 7.5 high | 3.1% | 2007-05-02 |
| CVE-2006-6866 EXP | STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usern… | Patch early | 7.8 high | 3.1% | 2006-12-31 |
| CVE-2001-0329 EXP | Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_… | Patch early | 7.5 high | 3.1% | 2001-06-27 |
| CVE-1999-0836 EXP | UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack. | Patch early | 10.0 high | 3.1% | 1998-12-02 |
| CVE-2007-0828 EXP | PHP remote file inclusion vulnerability in affichearticles.php3 in MySQLNewsEngine allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 3.1% | 2007-02-07 |
| CVE-2007-0508 EXP | PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitrary PHP code via a URL in the B… | Patch early | 7.5 high | 3.1% | 2007-01-26 |
| CVE-2008-7047 EXP | NatterChat 1.1 allows remote attackers to bypass authentication and gain administrator privileges to read or delete rooms and messages via a direct re… | Patch early | 7.5 high | 3.1% | 2009-08-24 |
| CVE-2015-7563 EXP | Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticate… | Patch early | 8.8 high | 3.1% | 2017-04-12 |
| CVE-2006-6377 EXP | Uploadscript 1.2 and earlier stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain the ad… | Patch early | 7.5 high | 3.1% | 2006-12-07 |
| CVE-2007-1040 EXP | Directory traversal vulnerability in archives.php in Xpression News (X-News) 1.0.1 allows remote attackers to include arbitrary files or obtain sensit… | Patch early | 7.5 high | 3.1% | 2007-02-21 |
| CVE-2008-6936 EXP | Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cau… | Patch early | 9.3 high | 3.1% | 2009-08-11 |
| CVE-2008-6939 EXP | TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adm cookie t… | Patch early | 7.5 high | 3.1% | 2009-08-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt