CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,922 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
187,695 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-4026 EXP | PHP remote file inclusion vulnerability in SAPID CMS 123 rc3 allows remote attackers to execute arbitrary PHP code via a URL in the (1) root_path para… | Patch early | 7.5 high | 3.6% | 2006-08-09 |
| CVE-2006-1799 EXP | censtore.cgi in Censtore 7.3.002 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter. | Patch early | 7.5 high | 3.6% | 2006-04-18 |
| CVE-2008-6824 EXP | The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin account, which makes it easier for… | Patch early | 10.0 high | 3.6% | 2009-06-04 |
| CVE-2006-6581 EXP | PHP remote file inclusion vulnerability in tests/debug_test.php in Vernet Loic PHP_Debug 1.1.0 allows remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 3.6% | 2006-12-15 |
| CVE-2012-0699 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the a… | Patch early | 8.8 high | 3.6% | 2018-01-11 |
| CVE-2006-1032 EXP | Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other progr… | Patch early | 7.5 high | 3.6% | 2006-03-07 |
| CVE-2006-2982 EXP | Multiple PHP remote file inclusion vulnerabilities in Enterprise Timesheet and Payroll Systems (EPS) 1.1 and earlier allow remote attackers to execute… | Patch early | 7.5 high | 3.6% | 2006-06-13 |
| CVE-2006-3922 EXP | PHP remote file inclusion vulnerability in mod_membre/inscription.php in PortailPHP 1.7 allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 3.6% | 2006-07-28 |
| CVE-2006-6041 EXP | Multiple PHP remote file inclusion vulnerabilities in Laurent Van den Reysen WORK system e-commerce 3.0.2, and other versions before 3.0.4, allow remo… | Patch early | 7.5 high | 3.6% | 2006-11-22 |
| CVE-2006-2666 EXP | PHP remote file inclusion vulnerability in includes/mailaccess/pop3.php in V-Webmail 1.5 through 1.6.4 allows remote attackers to execute arbitrary PH… | Patch early | 7.5 high | 3.6% | 2006-05-30 |
| CVE-2006-3028 EXP | PHP remote file inclusion vulnerability in stat_modules/users_age/module.php in Minerva 2.0.8a Build 237 and earlier allows remote attackers to execut… | Patch early | 7.5 high | 3.6% | 2006-06-15 |
| CVE-2026-36356 EXP | The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via t… | Patch early | 9.1 critical | 3.6% | 2026-05-05 |
| CVE-2016-6253 EXP | mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary file… | Patch early | 7.8 high | 3.6% | 2017-01-20 |
| CVE-2013-3365 EXP | TRENDnet TEW-812DRU router allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) wan network prefix to i… | Patch early | 8.5 high | 3.6% | 2014-02-04 |
| CVE-2006-5087 EXP | Multiple PHP remote file inclusion vulnerabilities in evoBB 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path… | Patch early | 7.5 high | 3.6% | 2006-09-29 |
| CVE-2013-6041 EXP | index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cooki… | Patch early | 7.5 high | 3.6% | 2014-12-27 |
| CVE-2008-3375 EXP | The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrativ… | Patch early | 7.5 high | 3.6% | 2008-07-30 |
| CVE-2007-0677 EXP | PHP remote file inclusion vulnerability in fw/class.Quick_Config_Browser.php in Cadre PHP Framework 20020724 allows remote attackers to execute arbitr… | Patch early | 7.5 high | 3.6% | 2007-02-03 |
| CVE-2007-3192 EXP | admin/setup.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to read and modify configuration settings via a direc… | Patch early | 9.4 high | 3.6% | 2007-06-12 |
| CVE-2008-4624 EXP | PHP remote file inclusion vulnerability in init.php in Fast Click SQL Lite 1.1.7, when register_globals is enabled, allows remote attackers to execute… | Patch early | 9.3 high | 3.6% | 2008-10-21 |
| CVE-2024-33559 EXP | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue af… | Patch early | 9.3 critical | 3.6% | 2024-04-29 |
| CVE-2005-0959 EXP | Buffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a long path. | Patch early | 7.5 high | 3.6% | 2005-05-02 |
| CVE-2007-5117 EXP | Multiple PHP remote file inclusion vulnerabilities in FrontAccounting (FA) 1.13, when register_globals is enabled, allow remote attackers to execute a… | Patch early | 9.3 high | 3.6% | 2007-09-27 |
| CVE-2006-6341 EXP | Multiple PHP remote file inclusion vulnerabilities in mg.applanix 1.3.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 3.6% | 2006-12-07 |
| CVE-2015-8261 EXP | The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows rem… | Patch early | 9.8 critical | 3.6% | 2016-01-08 |
| CVE-2009-0120 EXP | The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by se… | Patch early | 7.8 high | 3.6% | 2009-01-15 |
| CVE-2008-7001 EXP | Unrestricted file upload vulnerability in the file manager in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary code via unkn… | Patch early | 7.5 high | 3.6% | 2009-08-19 |
| CVE-2002-2425 EXP | Sun AnswerBook2 1.2 through 1.4.2 allows remote attackers to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a dir… | Patch early | 10.0 high | 3.5% | 2002-12-31 |
| CVE-2008-3455 EXP | PHP remote file inclusion vulnerability in include/admin.php in JnSHosts PHP Hosting Directory 2.0 allows remote attackers to execute arbitrary PHP co… | Patch early | 10.0 high | 3.5% | 2008-08-04 |
| CVE-2008-4704 EXP | PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 10.0 high | 3.5% | 2008-10-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt