CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,813 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
187,634 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-5802 EXP | Directory traversal vulnerability in index.php in Firewolf Technologies Synergiser 1.2 RC1 and earlier allows remote attackers to include and execute… | Patch early | 7.5 high | 3.9% | 2007-11-03 |
| CVE-2006-7183 EXP | PHP remote file inclusion vulnerability in styles.php in Exhibit Engine (EE) 1.22 and earlier allows remote attackers to execute arbitrary PHP code vi… | Patch early | 10.0 high | 3.9% | 2007-03-30 |
| CVE-2006-4055 EXP | Multiple PHP remote file inclusion vulnerabilities in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allow remote attackers to execu… | Patch early | 7.5 high | 3.9% | 2006-08-10 |
| CVE-2006-4605 EXP | PHP remote file inclusion vulnerability in index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to execute arbitrary PHP code via the… | Patch early | 7.5 high | 3.9% | 2006-09-07 |
| CVE-2017-6989 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. Th… | Patch early | 7.8 high | 3.9% | 2017-05-22 |
| CVE-2025-49741 EXP | No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | Patch early | 7.4 high | 3.9% | 2025-07-01 |
| CVE-2006-2668 EXP | Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 2.05 allow remote attackers to execute arbitrary PHP code via a URL in the lang param… | Patch early | 7.5 high | 3.9% | 2006-05-30 |
| CVE-2007-5453 EXP | Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing PHP sequen… | Patch early | 8.5 high | 3.9% | 2007-10-14 |
| CVE-2009-1361 EXP | dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter. NOTE: the prov… | Patch early | 10.0 high | 3.9% | 2009-04-22 |
| CVE-2025-60690 EXP | A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.t… | Patch early | 8.8 high | 3.9% | 2025-11-13 |
| CVE-2013-4630 EXP | Stack-based buffer overflow on Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 debugging is enabled, allows remote attackers to execute… | Patch early | 7.6 high | 3.9% | 2013-06-20 |
| CVE-2009-4790 EXP | Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modify arbitrary files via crafted… | Patch early | 9.0 high | 3.9% | 2010-04-22 |
| CVE-2018-9245 EXP | The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the logi… | Patch early | 9.8 critical | 3.9% | 2018-04-22 |
| CVE-2003-0723 EXP | Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code. | Patch early | 7.5 high | 3.9% | 2003-10-20 |
| CVE-2019-5722 EXP | An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handling, it has various SQL inject… | Patch early | 9.8 critical | 3.9% | 2019-03-21 |
| CVE-2019-8923 EXP | XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued. | Patch early | 9.8 critical | 3.9% | 2019-05-14 |
| CVE-2013-3691 EXP | AirLive POE-2600HD allows remote attackers to cause a denial of service (device reset) via a long URL. | Patch early | 7.5 high | 3.9% | 2019-12-11 |
| CVE-2009-4146 EXP | The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the LD_PRELOAD environmen… | Patch early | 7.2 high | 3.9% | 2009-12-02 |
| CVE-2009-1416 EXP | lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might… | Patch early | 7.5 high | 3.9% | 2009-04-30 |
| CVE-2002-1616 EXP | Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to gain root privileges via (1) su, (2) chsh, (3) passwd,… | Patch early | 7.2 high | 3.9% | 2002-08-01 |
| CVE-2025-10162 EXP | The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloade… | Patch early | 7.5 high | 3.9% | 2025-10-07 |
| CVE-2007-3548 EXP | Stack-based buffer overflow in W3Filer 2.1.3 allows remote FTP servers to cause a denial of service (application hang or crash) and possibly execute a… | Patch early | 7.1 high | 3.9% | 2007-07-03 |
| CVE-2019-11416 EXP | A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user. | Patch early | 8.8 high | 3.9% | 2019-04-22 |
| CVE-2019-13494 EXP | nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long variable string in a Map Objects… | Patch early | 7.8 high | 3.9% | 2019-07-12 |
| CVE-2005-0994 EXP | Multiple SQL injection vulnerabilities in ProductCart 2.7 allow remote attackers to execute arbitrary SQL commands via (1) the Category or resultCnt p… | Patch early | 7.5 high | 3.9% | 2005-05-02 |
| CVE-2005-3302 EXP | Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file… | Patch early | 7.3 high | 3.9% | 2005-10-24 |
| CVE-2000-0836 EXP | Buffer overflow in CamShot WebCam Trial2.6 allows remote attackers to execute arbitrary commands via a long Authorization header. | Patch early | 7.5 high | 3.9% | 2000-11-14 |
| CVE-2000-0846 EXP | Buffer overflow in Darxite 0.4 and earlier allows a remote attacker to execute arbitrary commands via a long username or password. | Patch early | 7.5 high | 3.9% | 2000-11-14 |
| CVE-2018-7178 EXP | SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter. | Patch early | 9.8 critical | 3.9% | 2018-02-17 |
| CVE-2006-1919 EXP | PHP remote file inclusion vulnerability in index.php in Internet Photoshow 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 3.9% | 2006-04-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt