CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,069 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
187,819 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-7185 EXP | The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R… | Patch early | 7.8 high | 3.4% | 2016-10-14 |
| CVE-2016-4311 EXP | Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authenti… | Patch early | 8.8 high | 3.4% | 2017-02-17 |
| CVE-2007-4283 EXP | PHP remote file inclusion vulnerability in bridge/yabbse.inc.php in Coppermine Photo Gallery (CPG) 1.3.1 allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 3.4% | 2007-08-09 |
| CVE-2002-0612 EXP | FileSeek.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) head or (2) foot parameters. | Patch early | 7.5 high | 3.4% | 2002-06-18 |
| CVE-2003-1286 EXP | HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy HTTP request… | Patch early | 7.5 high | 3.4% | 2003-12-31 |
| CVE-2025-10666 EXP | A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The… | Patch early | 8.8 high | 3.4% | 2025-09-18 |
| CVE-2008-5783 EXP | admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative access by setting the admin coo… | Patch early | 7.5 high | 3.4% | 2008-12-31 |
| CVE-2006-5154 EXP | PHP remote file inclusion vulnerability in cp/sig.php in DeluxeBB 1.09 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 3.4% | 2006-10-05 |
| CVE-2007-0181 EXP | PHP remote file inclusion vulnerability in include/common_function.php in magic photo storage website allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 3.4% | 2007-01-11 |
| CVE-2007-0205 EXP | Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directo… | Patch early | 7.5 high | 3.4% | 2007-01-11 |
| CVE-2012-2109 EXP | SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attackers to execute arbitrary SQL c… | Patch early | 7.5 high | 3.4% | 2012-09-04 |
| CVE-2015-1726 EXP | Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 an… | Patch early | 7.2 high | 3.4% | 2015-06-10 |
| CVE-2011-1516 EXP | The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all creat… | Patch early | 7.6 high | 3.4% | 2011-11-15 |
| CVE-2006-5547 EXP | PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.0.0 through 1.0.3 allows remote… | Patch early | 7.5 high | 3.4% | 2006-10-26 |
| CVE-2006-5548 EXP | PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 2.0.0 through 2.1.3 allows remote… | Patch early | 7.5 high | 3.4% | 2006-10-26 |
| CVE-2020-14930 EXP | An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verif… | Patch early | 8.1 high | 3.4% | 2020-06-19 |
| CVE-2007-0682 EXP | PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allows remote attackers to execute… | Patch early | 7.5 high | 3.4% | 2007-02-03 |
| CVE-2007-1011 EXP | PHP remote file inclusion vulnerability in functions_inc.php in VS-Gastebuch 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 3.4% | 2007-02-21 |
| CVE-2006-1662 EXP | The frontpage option in Limbo CMS 1.0.4.2 and 1.0.4.1 allows remote attackers to execute arbitrary PHP commands via the Itemid parameter in index.php. | Patch early | 7.5 high | 3.4% | 2006-04-07 |
| CVE-2006-6417 EXP | PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers to execute a… | Patch early | 7.5 high | 3.4% | 2006-12-10 |
| CVE-2019-5797 EXP | Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p… | Patch early | 7.5 high | 3.4% | 2022-09-29 |
| CVE-2015-4593 EXP | eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserService.jsp which allows remote at… | Patch early | 8.8 high | 3.4% | 2017-01-10 |
| CVE-2008-6366 EXP | SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 3.4% | 2009-03-02 |
| CVE-2006-3986 EXP | PHP remote file inclusion vulnerability in index.php in Knusperleicht Newsletter 3.5 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 3.4% | 2006-08-05 |
| CVE-2006-4129 EXP | PHP remote file inclusion vulnerability in admin.webring.docs.php in the Webring Component (com_webring) 1.0 and earlier for Joomla! allows remote att… | Patch early | 7.5 high | 3.4% | 2006-08-14 |
| CVE-2006-4456 EXP | PHP remote file inclusion vulnerability in functions.php in phpECard 2.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 3.4% | 2006-08-31 |
| CVE-2006-4645 EXP | PHP remote file inclusion vulnerability in akarru.gui/main_content.php in Akarru Social BookMarking Engine 0.4.3.34 and earlier, and possibly 0.4.4.12… | Patch early | 7.5 high | 3.4% | 2006-09-08 |
| CVE-2008-5045 EXP | Heap-based buffer overflow in Network-Client FTP Now 2.6, and possibly other versions, allows remote FTP servers to cause a denial of service (crash)… | Patch early | 10.0 high | 3.4% | 2008-11-13 |
| CVE-2006-2737 EXP | utilities/register.asp in Nukedit 4.9.6 and earlier allows remote attackers to create new users as part of arbitrary groups, including the administrat… | Patch early | 7.5 high | 3.4% | 2006-06-01 |
| CVE-2008-5580 EXP | mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the sFileName argumen… | Patch early | 7.5 high | 3.4% | 2008-12-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt