CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,367 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
150,841 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-1635 EXP | Static code injection vulnerability in admin/settings.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote authenticated users to in… | Patch early | 9.0 high | 2.8% | 2007-03-23 |
| CVE-2008-0612 EXP | Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary local files via… | Patch early | 7.5 high | 2.8% | 2008-02-06 |
| CVE-2003-1143 EXP | Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05 allow remote attackers to caus… | Patch early | 7.5 high | 2.8% | 2003-10-30 |
| CVE-2002-1070 EXP | Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename p… | Patch early | 7.5 high | 2.8% | 2002-10-04 |
| CVE-2008-4919 EXP | Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remote attackers to overwrite arbi… | Patch early | 8.8 high | 2.8% | 2008-11-04 |
| CVE-2018-0748 EXP | The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 16… | Patch early | 7.8 high | 2.8% | 2018-01-04 |
| CVE-2018-0752 EXP | The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Wind… | Patch early | 7.8 high | 2.8% | 2018-01-04 |
| CVE-2008-4708 EXP | BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admin_session cookie to 1. | Patch early | 7.5 high | 2.8% | 2008-10-23 |
| CVE-2008-4721 EXP | PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie t… | Patch early | 7.5 high | 2.8% | 2008-10-23 |
| CVE-2008-4783 EXP | tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login cookie to "admin." | Patch early | 7.5 high | 2.8% | 2008-10-29 |
| CVE-2008-4784 EXP | aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a cookie to "A" or "O" in (1) edi… | Patch early | 7.5 high | 2.8% | 2008-10-29 |
| CVE-2008-5576 EXP | admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large val… | Patch early | 7.5 high | 2.8% | 2008-12-15 |
| CVE-2008-7041 EXP | AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php. | Patch early | 7.5 high | 2.8% | 2009-08-24 |
| CVE-2009-1739 EXP | PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including administrative privileges, by sett… | Patch early | 7.5 high | 2.8% | 2009-05-20 |
| CVE-2003-1213 EXP | The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote… | Patch early | 7.5 high | 2.8% | 2003-12-31 |
| CVE-2004-1783 EXP | Directory traversal vulnerability in Net2Soft Flash FTP Server 1.0 allows remote attackers to read and create arbitrary files via a /.. (slash dot dot… | Patch early | 7.5 high | 2.8% | 2004-12-31 |
| CVE-2008-3494 EXP | 8e6 R3000 Internet Filter 2.0.12.10 allows remote attackers to bypass intended restrictions via an extra HTTP Host header with additional leading text… | Patch early | 7.8 high | 2.8% | 2008-08-06 |
| CVE-2006-5155 EXP | PHP remote file inclusion vulnerability in core/pdf.php in VideoDB 2.2.1 and earlier allows remote attackers to execute arbitrary PHP code via the con… | Patch early | 7.5 high | 2.8% | 2006-10-05 |
| CVE-2006-5182 EXP | PHP remote file inclusion vulnerability in frontpage.php in Dan Jensen Travelsized CMS 0.4 and earlier allows remote attackers to execute arbitrary PH… | Patch early | 7.5 high | 2.8% | 2006-10-10 |
| CVE-2006-5187 EXP | PHP remote file inclusion vulnerability in includes/functions.php in Bulletin Board Ace (BBaCE) 3.5 and earlier allows remote attackers to execute arb… | Patch early | 7.5 high | 2.8% | 2006-10-10 |
| CVE-2006-5222 EXP | Multiple PHP remote file inclusion vulnerabilities in Dimension of phpBB 0.2.6 and earlier allow remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 2.8% | 2006-10-10 |
| CVE-2006-5224 EXP | PHP remote file inclusion vulnerability in includes/logger_engine.php in Dimitri Seitz Security Suite IP Logger 1.0.0 in dwingmods for phpBB allows re… | Patch early | 7.5 high | 2.8% | 2006-10-10 |
| CVE-2006-5384 EXP | PHP remote file inclusion vulnerability in modification/SendAlertEmail.php in CDS Software Consortium CDS Agenda 4.2.9 and earlier allows remote attac… | Patch early | 7.5 high | 2.8% | 2006-10-18 |
| CVE-2006-5419 EXP | PHP remote file inclusion vulnerability in client.php in University of Glasgow Specimen Image Database (SID), when register_globals is enabled, allows… | Patch early | 7.5 high | 2.8% | 2006-10-20 |
| CVE-2006-5429 EXP | Multiple PHP remote file inclusion vulnerabilities in Barry Nauta BRIM 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 2.8% | 2006-10-20 |
| CVE-2006-5531 EXP | PHP remote file inclusion vulnerability in embedded.php in Ascended Guestbook 1.0.0 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 2.8% | 2006-10-26 |
| CVE-2007-3346 EXP | Directory traversal vulnerability in index.php in PHPAccounts 0.5 allows remote attackers to include arbitrary local files via unspecified manipulatio… | Patch early | 7.8 high | 2.8% | 2007-06-22 |
| CVE-2006-5234 EXP | Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPWS_SO… | Patch early | 7.5 high | 2.8% | 2006-10-11 |
| CVE-2009-0280 EXP | Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1. | Patch early | 7.5 high | 2.8% | 2009-01-27 |
| CVE-2009-0864 EXP | S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for the login cookie. | Patch early | 7.5 high | 2.8% | 2009-03-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt