CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,240 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
150,786 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-6844 EXP | The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and 4.0.1, allows remote att… | Patch early | 7.5 high | 3% | 2009-07-02 |
| CVE-2006-5596 EXP | Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary files via ..\ (dot dot backsla… | Patch early | 7.5 high | 3% | 2006-10-28 |
| CVE-2016-6664 EXP | mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5… | Patch early | 7.0 high | 3% | 2016-12-13 |
| CVE-2004-2746 EXP | SQL injection vulnerability in adminlogin.asp in XTREME ASP Photo Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) us… | Patch early | 7.5 high | 3% | 2004-12-31 |
| CVE-2008-6734 EXP | Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to include and execute arbitrary local… | Patch early | 9.3 high | 3% | 2009-04-21 |
| CVE-2018-19135 EXP | ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions fo… | Patch early | 8.8 high | 3% | 2018-11-11 |
| CVE-2007-6497 EXP | Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp… | Patch early | 7.5 high | 3% | 2007-12-20 |
| CVE-2005-1360 EXP | PHP remote file inclusion vulnerability in error.php in GrayCMS 1.1 allows remote attackers to execute arbitrary PHP code by modifying the path_prefix… | Patch early | 7.5 high | 3% | 2005-05-02 |
| CVE-2010-1894 EXP | The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly handle unspecified exc… | Patch early | 7.2 high | 3% | 2010-08-11 |
| CVE-2009-3042 EXP | SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL co… | Patch early | 7.5 high | 3% | 2009-09-01 |
| CVE-2008-6157 EXP | SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent attackers to obtain sensitive in… | Patch early | 7.5 high | 3% | 2009-02-17 |
| CVE-2005-0800 EXP | PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying th… | Patch early | 7.5 high | 3% | 2005-05-02 |
| CVE-2004-0070 EXP | PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link param… | Patch early | 7.5 high | 3% | 2004-02-17 |
| CVE-2009-3362 EXP | PHP remote file inclusion vulnerability in printnews.php3 in SZNews 2.7 allows remote attackers to execute arbitrary PHP code via a URL in the id para… | Patch early | 7.5 high | 3% | 2009-09-24 |
| CVE-2007-1636 EXP | Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in… | Patch early | 7.5 high | 3% | 2007-03-23 |
| CVE-2006-4779 EXP | PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attackers to exe… | Patch early | 7.5 high | 2.9% | 2006-09-14 |
| CVE-2006-5032 EXP | PHP remote file inclusion vulnerability in dix.php3 in PHPartenaire 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the url_php… | Patch early | 7.5 high | 2.9% | 2006-09-27 |
| CVE-2006-5181 EXP | Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 2.9% | 2006-10-10 |
| CVE-2006-5283 EXP | PHP remote file inclusion vulnerability in ftag.php in Minichat 6.0 allows remote attackers to execute arbitrary PHP code via a URL in the mostrar par… | Patch early | 7.5 high | 2.9% | 2006-10-13 |
| CVE-2006-5421 EXP | WSN Forum 1.3.4 and earlier allows remote attackers to execute arbitrary PHP code via a modified pathname in the pathtoconfig parameter that points to… | Patch early | 7.5 high | 2.9% | 2006-10-20 |
| CVE-2006-5471 EXP | PHP remote file inclusion vulnerability in example/lib/grid3.lib.php in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to ex… | Patch early | 7.5 high | 2.9% | 2006-10-24 |
| CVE-2006-5526 EXP | Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40 and earlier, allow remo… | Patch early | 7.5 high | 2.9% | 2006-10-26 |
| CVE-2007-3547 EXP | Directory traversal vulnerability in qti_checkname.php in QuickTicket 1.2 allows remote attackers to include and execute arbitrary local files a .. (d… | Patch early | 7.8 high | 2.9% | 2007-07-03 |
| CVE-2007-4210 EXP | Multiple SQL injection vulnerabilities in module.php in LANAI (la-nai) CMS 1.2.14 allow remote attackers to execute arbitrary SQL commands via (1) the… | Patch early | 7.5 high | 2.9% | 2007-08-08 |
| CVE-2007-6086 EXP | Directory traversal vulnerability in index.php in VigileCMS 1.4 allows remote attackers to include and execute arbitrary local files via directory tra… | Patch early | 9.3 high | 2.9% | 2007-11-22 |
| CVE-2006-4505 EXP | CRLF injection vulnerability in links.php in NX5Linx 1.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting… | Patch early | 7.5 high | 2.9% | 2006-08-31 |
| CVE-2017-0103 EXP | The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 mishandles registry objects… | Patch early | 7.0 high | 2.9% | 2017-03-17 |
| CVE-2014-4938 EXP | SQL injection vulnerability in the WP Rss Poster (wp-rss-poster) plugin 1.0.0 for WordPress allows remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 2.9% | 2014-07-11 |
| CVE-2011-5286 EXP | SQL injection vulnerability in social-slider-2/ajax.php in the Social Slider plugin before 7.4.2 for WordPress allows remote attackers to execute arbi… | Patch early | 7.5 high | 2.9% | 2015-01-01 |
| CVE-2007-1928 EXP | Directory traversal vulnerability in index.php in witshare 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot)… | Patch early | 7.5 high | 2.9% | 2007-04-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt