CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,322 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
150,834 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-1633 EXP | Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include… | Patch early | 7.5 high | 2.9% | 2007-03-23 |
| CVE-2002-0244 EXP | Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument t… | Patch early | 7.5 high | 2.9% | 2002-05-29 |
| CVE-2008-6232 EXP | Pre Shopping Mall allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid coo… | Patch early | 7.5 high | 2.9% | 2009-02-20 |
| CVE-2009-1246 EXP | Multiple directory traversal vulnerabilities in Blogplus 1.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in… | Patch early | 7.5 high | 2.9% | 2009-04-06 |
| CVE-2006-1363 EXP | images.php in Justin White (aka YTZ) Free Web Publishing System (FreeWPS) 2.11 allows remote attackers to execute arbitrary PHP code by uploading a .p… | Patch early | 7.5 high | 2.9% | 2006-03-23 |
| CVE-2009-0070 EXP | Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (applic… | Patch early | 9.3 high | 2.9% | 2009-01-08 |
| CVE-2008-4499 EXP | Multiple directory traversal vulnerabilities in PHP Web Explorer 0.99b and earlier allow remote attackers to include and execute arbitrary local files… | Patch early | 9.3 high | 2.9% | 2008-10-09 |
| CVE-2018-7216 EXP | Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal allows remote authenticated user… | Patch early | 8.0 high | 2.9% | 2018-02-18 |
| CVE-2008-4244 EXP | Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the usuario and pass cookies to 1. | Patch early | 7.5 high | 2.9% | 2008-09-25 |
| CVE-2013-5917 EXP | SQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL comman… | Patch early | 7.5 high | 2.9% | 2013-09-23 |
| CVE-2007-2155 EXP | Directory traversal vulnerability in template.php in in phpFaber TopSites 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the… | Patch early | 7.8 high | 2.9% | 2007-04-19 |
| CVE-2007-0577 EXP | PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 2.9% | 2007-01-30 |
| CVE-2008-0520 EXP | Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary SQ… | Patch early | 7.5 high | 2.9% | 2008-01-31 |
| CVE-2008-0682 EXP | SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers to execute arbitrary SQL comm… | Patch early | 7.5 high | 2.8% | 2008-02-12 |
| CVE-2013-4011 EXP | Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privi… | Patch early | 7.2 high | 2.8% | 2013-07-18 |
| CVE-2008-6183 EXP | Multiple directory traversal vulnerabilities in index.php in My PHP Indexer 1.0 allow remote attackers to read arbitrary files via a .. (dot dot) in t… | Patch early | 7.8 high | 2.8% | 2009-02-19 |
| CVE-2005-3819 EXP | Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass authentication… | Patch early | 7.5 high | 2.8% | 2005-11-26 |
| CVE-2002-0117 EXP | Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitrary script an… | Patch early | 7.5 high | 2.8% | 2002-03-25 |
| CVE-2001-1086 EXP | XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote at… | Patch early | 7.5 high | 2.8% | 2001-07-04 |
| CVE-2008-6940 EXP | TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to… | Patch early | 7.5 high | 2.8% | 2009-08-12 |
| CVE-2008-6957 EXP | member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd action… | Patch early | 7.5 high | 2.8% | 2009-08-12 |
| CVE-2008-2482 EXP | Directory traversal vulnerability in install_mod.php in insanevisions OneCMS 2.5 allows remote attackers to include and execute arbitrary local files… | Patch early | 7.5 high | 2.8% | 2008-05-28 |
| CVE-2008-3179 EXP | Directory traversal vulnerability in website.php in Web 2 Business (W2B) phpDatingClub (aka Dating Club) 3.7 allows remote attackers to include and ex… | Patch early | 7.5 high | 2.8% | 2008-07-15 |
| CVE-2008-4346 EXP | Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot… | Patch early | 7.5 high | 2.8% | 2008-09-30 |
| CVE-2008-2073 EXP | Directory traversal vulnerability in include/global.inc.php in Virtual Design Studio vlbook 1.21 allows remote attackers to include and execute arbitr… | Patch early | 7.5 high | 2.8% | 2008-05-05 |
| CVE-2018-0743 EXP | Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows an elevation of privilege vul… | Patch early | 7.0 high | 2.8% | 2018-01-04 |
| CVE-2017-1000405 EXP | The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside the THP implementation. touch… | Patch early | 7.0 high | 2.8% | 2017-11-30 |
| CVE-2007-3272 EXP | Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the language para… | Patch early | 7.8 high | 2.8% | 2007-06-19 |
| CVE-2002-1211 EXP | Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE that points to code stored on… | Patch early | 7.5 high | 2.8% | 2002-11-12 |
| CVE-2005-4275 EXP | Scientific Atlanta DPX2100 Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and d… | Patch early | 7.8 high | 2.8% | 2005-12-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt