CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,370 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
150,842 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-2226 EXP | Multiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands via the (1) users_id_assign para… | Patch early | 7.5 high | 2.8% | 2014-05-14 |
| CVE-2017-7004 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "Security"… | Patch early | 7.0 high | 2.8% | 2018-04-03 |
| CVE-2006-7017 EXP | Multiple PHP remote file inclusion vulnerabilities in Indexu 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the admin_templat… | Patch early | 7.5 high | 2.8% | 2007-02-15 |
| CVE-2006-5422 EXP | PHP remote file inclusion vulnerability in calcul-page.php in Lodel (patchlodel) 0.7.3 allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 2.8% | 2006-10-20 |
| CVE-2006-5485 EXP | Multiple PHP remote file inclusion vulnerabilities in SpeedBerg 1.2beta1 allow remote attackers to execute arbitrary PHP code via a URL in the SPEEDBE… | Patch early | 7.5 high | 2.8% | 2006-10-24 |
| CVE-2006-5505 EXP | Multiple PHP file inclusion vulnerabilities in 2BGal 3.0 allow remote attackers to execute arbitrary PHP code via the lang parameter to (1) admin/conf… | Patch early | 7.5 high | 2.8% | 2006-10-25 |
| CVE-2009-4808 EXP | admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the g_admi… | Patch early | 7.5 high | 2.8% | 2010-04-23 |
| CVE-2006-6648 EXP | PHP remote file inclusion vulnerability in main.inc.php in planetluc.com RateMe 1.3.2 and earlier allows remote attackers to execute arbitrary PHP cod… | Patch early | 7.5 high | 2.8% | 2006-12-20 |
| CVE-2018-0751 EXP | The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Wind… | Patch early | 7.1 high | 2.8% | 2018-01-04 |
| CVE-2018-4384 EXP | A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1, watchOS 5.1. | Patch early | 7.8 high | 2.8% | 2019-04-03 |
| CVE-2008-6288 EXP | Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and earlier allows remote attackers to read arbitrary files via a ..… | Patch early | 7.8 high | 2.8% | 2009-02-25 |
| CVE-2008-6334 EXP | Directory traversal vulnerability in download.php in eMetrix Extract Website allows remote attackers to read arbitrary files via a .. (dot dot) in the… | Patch early | 7.8 high | 2.8% | 2009-02-27 |
| CVE-2008-6335 EXP | Directory traversal vulnerability in download.php in eMetrix Online Keyword Research Tool allows remote attackers to read arbitrary files via a .. (do… | Patch early | 7.8 high | 2.8% | 2009-02-27 |
| CVE-2004-2368 EXP | PHP remote file inclusion vulnerability in header.php in Opt-X 0.7.2 allows remote attackers to execute arbitrary PHP code via the systempath paramete… | Patch early | 7.5 high | 2.8% | 2004-12-31 |
| CVE-2005-0678 EXP | PHP remote file inclusion vulnerability in formmail.inc.php for Form Mail Script 2.3 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 2.8% | 2005-05-02 |
| CVE-2005-1375 EXP | Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbi… | Patch early | 7.5 high | 2.8% | 2005-05-03 |
| CVE-2007-4978 EXP | Multiple PHP remote file inclusion vulnerabilities in phpSyncML 0.1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in th… | Patch early | 7.5 high | 2.8% | 2007-09-19 |
| CVE-2007-5313 EXP | PHP remote file inclusion vulnerability in install/config.php in Picturesolution 2.1 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 2.8% | 2007-10-09 |
| CVE-2007-6655 EXP | PHP remote file inclusion vulnerability in includes/function.php in Kontakt Formular 1.4 allows remote attackers to execute arbitrary PHP code via a U… | Patch early | 7.5 high | 2.8% | 2008-01-04 |
| CVE-2009-4645 EXP | Directory traversal vulnerability in web_client_user_guide.html in Accellion Secure File Transfer Appliance before 8_0_105 allows remote attackers to… | Patch early | 7.8 high | 2.8% | 2010-02-19 |
| CVE-2018-10619 EXP | An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.90.00 and prior may allow an a… | Patch early | 7.8 high | 2.8% | 2018-06-07 |
| CVE-2006-4970 EXP | PHP remote file inclusion vulnerability in enc/content.php in WAHM E-Commerce Pie Cart Pro allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 2.8% | 2006-09-25 |
| CVE-2006-5062 EXP | PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows remote attackers to execute arbi… | Patch early | 7.5 high | 2.8% | 2006-09-28 |
| CVE-2006-5226 EXP | PHP remote file inclusion vulnerability in moteur/moteur.php in Prologin.fr Freenews 1.1 and earlier allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 2.8% | 2006-10-10 |
| CVE-2006-5261 EXP | Multiple PHP remote file inclusion vulnerabilities in PHPMyNews 1.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 2.8% | 2006-10-12 |
| CVE-2006-5426 EXP | PHP remote file inclusion vulnerability in lib/lcUser.php in LoCal Calendar System 1.1 remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 2.8% | 2006-10-20 |
| CVE-2006-5588 EXP | Multiple PHP remote file inclusion vulnerabilities in CMS Faethon 2.0 Ultimate and earlier, when register_globals and magic_quotes_gpc are enabled, al… | Patch early | 7.5 high | 2.8% | 2006-10-27 |
| CVE-2002-0732 EXP | Cross-site scripting vulnerability in MyGuestbook 1.0 allows remote attackers to execute arbitrary script or inject HTML via fields such as (1) user n… | Patch early | 7.5 high | 2.8% | 2002-08-12 |
| CVE-2006-0522 EXP | SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier allows remote… | Patch early | 7.5 high | 2.8% | 2006-02-02 |
| CVE-2013-7185 EXP | PotPlayer 1.5.40688: .avi File Memory Corruption | Patch early | 7.8 high | 2.8% | 2020-01-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt