CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,879 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
187,676 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-3301 EXP | The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not z… | Patch early | 7.2 high | 3.8% | 2010-09-22 |
| CVE-2005-4213 EXP | SQL injection vulnerability in mod.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary SQL commands via the phpcoinsessid cookie. | Patch early | 7.5 high | 3.8% | 2005-12-14 |
| CVE-2024-23346 EXP | Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFa… | Patch early | 9.3 critical | 3.8% | 2024-02-21 |
| CVE-2005-3938 EXP | SQL injection vulnerability in Softbiz FAQ Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the id parameter in (1)… | Patch early | 7.5 high | 3.8% | 2005-12-01 |
| CVE-2014-2046 EXP | cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allows remote attackers to (1) obta… | Patch early | 9.7 high | 3.8% | 2014-05-14 |
| CVE-2013-4631 EXP | Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 is enabled, allow remote attackers to cause a denial of service (device crash) via malfo… | Patch early | 7.8 high | 3.8% | 2013-06-20 |
| CVE-2017-11176 EXP | The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space c… | Patch early | 7.8 high | 3.8% | 2017-07-11 |
| CVE-2015-8088 EXP | Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7-TL10 before MT7-TL10C00B354,… | Patch early | 7.8 high | 3.8% | 2016-01-12 |
| CVE-2000-0751 EXP | mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format strings, which allows remote attackers to execute… | Patch early | 7.5 high | 3.8% | 2000-10-20 |
| CVE-2006-7007 EXP | Buffer overflow in Tiny FTPd 1.4 and earlier allows remote attackers to cause a denial of service (daemon crash) via a long USER command, a different… | Patch early | 7.8 high | 3.8% | 2007-02-12 |
| CVE-2006-3994 EXP | SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha and earlier allows remote atta… | Patch early | 7.5 high | 3.8% | 2006-08-05 |
| CVE-2006-5399 EXP | PHP remote file inclusion vulnerability in classes/Import_MM.class.php in PHPRecipeBook 2.36, when register_globals is enabled, allows remote attacker… | Patch early | 7.5 high | 3.8% | 2006-10-18 |
| CVE-2000-1021 EXP | Heap overflow in WebConfig in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands v… | Patch early | 7.5 high | 3.8% | 2000-12-11 |
| CVE-2013-7248 EXP | Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password for the roleDiag account, which… | Patch early | 10.0 high | 3.8% | 2014-01-26 |
| CVE-2010-1431 EXP | SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the expo… | Patch early | 7.5 high | 3.8% | 2010-05-04 |
| CVE-2006-5865 EXP | PHP remote file inclusion vulnerability in language.inc.php in MyAlbum 3.02 and earlier allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 3.8% | 2006-11-11 |
| CVE-2018-5980 EXP | SQL Injection exists in the Solidres 2.5.1 component for Joomla! via the direction parameter in a hub.search action. | Patch early | 9.8 critical | 3.8% | 2018-02-17 |
| CVE-2018-6578 EXP | SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions req… | Patch early | 9.8 critical | 3.8% | 2018-02-02 |
| CVE-2018-6579 EXP | SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request. | Patch early | 9.8 critical | 3.8% | 2018-02-02 |
| CVE-2018-6584 EXP | SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request. | Patch early | 9.8 critical | 3.8% | 2018-02-17 |
| CVE-2017-17648 EXP | Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter. | Patch early | 9.8 critical | 3.8% | 2017-12-13 |
| CVE-2016-0171 EXP | The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R… | Patch early | 7.8 high | 3.8% | 2016-05-11 |
| CVE-2014-5093 EXP | Status2k does not remove the install directory allowing credential reset. | Patch early | 9.8 critical | 3.8% | 2020-01-10 |
| CVE-2015-1471 EXP | SQL injection vulnerability in userprofile.lib.php in Pragyan CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the user parameter… | Patch early | 7.5 high | 3.8% | 2015-02-12 |
| CVE-2006-4583 EXP | Multiple PHP remote file inclusion vulnerabilities in FlashChat before 4.6.2 allow remote attackers to execute arbitrary PHP code via a URL in the dir… | Patch early | 7.5 high | 3.8% | 2006-09-06 |
| CVE-2020-28091 EXP | cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php. | Patch early | 7.5 high | 3.8% | 2020-11-18 |
| CVE-2014-1636 EXP | Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to execute arbitrary SQL commands vi… | Patch early | 7.5 high | 3.8% | 2014-01-22 |
| CVE-2011-0045 EXP | The Trace Events functionality in the kernel in Microsoft Windows XP SP3 does not properly perform type conversion, which causes integer truncation an… | Patch early | 7.2 high | 3.8% | 2011-02-09 |
| CVE-2007-1213 EXP | The TrueType Fonts rasterizer in Microsoft Windows 2000 SP4 allows local users to gain privileges via crafted TrueType fonts, which result in an unini… | Patch early | 7.2 high | 3.8% | 2007-04-04 |
| CVE-2008-5060 EXP | Multiple PHP remote file inclusion vulnerabilities in ModernBill 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 10.0 high | 3.8% | 2008-11-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt