CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,746 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
187,619 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-3464 EXP | afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly val… | Patch early | 7.2 high | 4% | 2008-10-15 |
| CVE-2024-33896 EXP | Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blackli… | Patch early | 7.2 high | 4% | 2024-08-02 |
| CVE-2004-0323 EXP | Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp paramet… | Patch early | 7.5 high | 4% | 2004-12-31 |
| CVE-2006-7070 EXP | Unrestricted file upload vulnerability in manager/media/ibrowser/scripts/rfiles.php in Etomite CMS 0.6.1 and earlier allows remote attackers to upload… | Patch early | 7.5 high | 4% | 2007-03-02 |
| CVE-2008-4878 EXP | Unrestricted file upload vulnerability in the "Add Image Macro" feature in WebCards 1.3 allows remote authenticated administrators to execute arbitrar… | Patch early | 8.5 high | 4% | 2008-11-01 |
| CVE-2017-7178 EXP | CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitra… | Patch early | 8.8 high | 4% | 2017-03-18 |
| CVE-2006-0359 EXP | Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device crash) via SIP INVITE commands w… | Patch early | 7.5 high | 4% | 2006-01-22 |
| CVE-2006-1212 EXP | Unspecified vulnerability in index.php in Core CoreNews 2.0.1 allows remote attackers to execute arbitrary commands via the page parameter, possibly d… | Patch early | 7.5 high | 4% | 2006-03-14 |
| CVE-2008-4592 EXP | Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and execute arbitrary local files vi… | Patch early | 10.0 high | 4% | 2008-10-16 |
| CVE-2008-6677 EXP | Unrestricted file upload vulnerability in fckeditor251/editor/filemanager/connectors/asp/upload.asp in QuickerSite 1.8.5 allows remote attackers to ex… | Patch early | 7.5 high | 4% | 2009-04-08 |
| CVE-2015-2370 EXP | The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and… | Patch early | 7.2 high | 4% | 2015-07-14 |
| CVE-2016-0006 EXP | The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2… | Patch early | 7.3 high | 4% | 2016-01-13 |
| CVE-2001-0818 EXP | A buffer overflow the '\s' console command in MDBMS 0.99b9 and earlier allows remote attackers to execute arbitrary commands by sending the command a… | Patch early | 7.5 high | 4% | 2001-12-06 |
| CVE-2009-1443 EXP | Multiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and attack vectors. | Patch early | 10.0 high | 4% | 2009-04-27 |
| CVE-2019-18418 EXP | clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session mana… | Patch early | 9.8 critical | 4% | 2019-10-24 |
| CVE-2018-19459 EXP | Adult Filter 1.0 has a Buffer Overflow via a crafted Black Domain List file. | Patch early | 7.8 high | 4% | 2018-11-22 |
| CVE-2013-7179 EXP | The ping functionality in cgi-bin/diagnostic.cgi on Seowon Intech SWC-9100 routers allows remote attackers to execute arbitrary commands via shell met… | Patch early | 8.3 high | 4% | 2014-02-04 |
| CVE-2023-30868 EXP | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jon Christopher CMS Tree Page View plugin <= 1.6.7 versions. | Patch early | 7.1 high | 4% | 2023-05-18 |
| CVE-2005-1503 EXP | Multiple SQL injection vulnerabilities in MidiCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) searchstring… | Patch early | 7.5 high | 4% | 2005-05-11 |
| CVE-2006-4993 EXP | Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.4.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 4% | 2006-09-26 |
| CVE-2007-1225 EXP | The connection log file implementation in Grok Developments NetProxy 4.03 does not record requests that omit http:// in a URL, which might allow remot… | Patch early | 10.0 high | 4% | 2007-03-02 |
| CVE-2018-6180 EXP | A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password for other accounts. | Patch early | 9.8 critical | 4% | 2018-02-08 |
| CVE-2007-3251 EXP | Multiple directory traversal vulnerabilities in e-Vision CMS 2.02 and earlier allow remote attackers to (1) include and execute arbitrary local files… | Patch early | 7.8 high | 4% | 2007-06-18 |
| CVE-2006-1747 EXP | PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root p… | Patch early | 7.5 high | 4% | 2006-04-12 |
| CVE-2006-0688 EXP | PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 4% | 2006-02-15 |
| CVE-2007-6188 EXP | Multiple directory traversal vulnerabilities in TuMusika Evolution 1.7R5 allow remote attackers to include and execute arbitrary local files via a ..… | Patch early | 7.5 high | 4% | 2007-11-30 |
| CVE-2015-6098 EXP | Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and… | Patch early | 7.2 high | 4% | 2015-11-11 |
| CVE-2018-8410 EXP | An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory, aka "Windows Registry Elevat… | Patch early | 7.8 high | 4% | 2018-09-13 |
| CVE-2003-1405 EXP | DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3. | Patch early | 7.5 high | 4% | 2003-12-31 |
| CVE-2005-4065 EXP | SQL injection vulnerability in the search module in Edgewall Trac before 0.9.2 allows remote attackers to execute arbitrary SQL commands via unknown v… | Patch early | 7.5 high | 4% | 2005-12-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt