CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,145 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
187,819 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2000-0442 EXP | Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command. | Patch early | 7.5 high | 3.3% | 2000-05-24 |
| CVE-2000-1037 EXP | Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows… | Patch early | 7.5 high | 3.3% | 2000-12-11 |
| CVE-2008-6365 EXP | SQL injection vulnerability in logon.jsp in Ad Server Solutions Ad Management Software Java allows remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 3.3% | 2009-03-02 |
| CVE-2012-4908 EXP | Google Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Policy and obtain access to local files via vectors inv… | Patch early | 7.5 high | 3.3% | 2012-09-13 |
| CVE-2006-6462 EXP | PHP remote file inclusion vulnerability in engine/oldnews.inc.php in CM68 News 12.02.06 allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 3.3% | 2006-12-11 |
| CVE-2006-2527 EXP | Admin/admin.php in phpBazar 2.1.0 and earlier allows remote attackers to bypass the authentication process and gain unauthorized access to the adminis… | Patch early | 7.5 high | 3.3% | 2006-05-22 |
| CVE-1999-1405 EXP | snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when sn… | Patch early | 10.0 high | 3.3% | 1999-02-17 |
| CVE-2015-4592 EXP | eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allows remote authenticated users t… | Patch early | 8.8 high | 3.3% | 2017-01-10 |
| CVE-2018-0877 EXP | The Desktop Bridge Virtual File System (VFS) in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevat… | Patch early | 7.8 high | 3.3% | 2018-03-14 |
| CVE-2007-4804 EXP | Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) hal.php,… | Patch early | 7.5 high | 3.3% | 2007-09-11 |
| CVE-2008-5659 EXP | The gnu.java.security.util.PRNG class in GNU Classpath 0.97.2 and earlier uses a predictable seed based on the system time, which makes it easier for… | Patch early | 7.5 high | 3.3% | 2008-12-17 |
| CVE-2006-0940 EXP | Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 3.3% | 2006-03-01 |
| CVE-2017-17999 EXP | SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter to… | Patch early | 9.8 critical | 3.3% | 2018-01-23 |
| CVE-2007-1647 EXP | Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allo… | Patch early | 7.8 high | 3.3% | 2007-03-24 |
| CVE-2007-0232 EXP | PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 3.3% | 2007-01-13 |
| CVE-2007-0360 EXP | PHP remote file inclusion vulnerability in lang/index.php in Oreon 1.2.3 RC4 and earlier allows remote attackers to execute arbitrary PHP code via a U… | Patch early | 7.5 high | 3.3% | 2007-01-19 |
| CVE-2007-0571 EXP | PHP remote file inclusion vulnerability in include/lib/lib_head.php in phpMyReports 3.0.11 and earlier allows remote attackers to execute arbitrary PH… | Patch early | 7.5 high | 3.3% | 2007-01-30 |
| CVE-2007-0761 EXP | PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 3.3% | 2007-02-06 |
| CVE-2007-0797 EXP | PHP remote file inclusion vulnerability in theme/settings.php in bluevirus-design SMA-DB 0.3.9 and earlier allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 3.3% | 2007-02-06 |
| CVE-2007-0809 EXP | PHP remote file inclusion vulnerability in includes/class_template.php in Categories hierarchy (aka CH or mod-CH) 2.1.2 in ptirhiikmods allows remote… | Patch early | 7.5 high | 3.3% | 2007-02-07 |
| CVE-2018-14057 EXP | Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token… | Patch early | 8.8 high | 3.3% | 2018-08-17 |
| CVE-2017-0165 EXP | An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1, Windows RT 8.1, and Windows… | Patch early | 7.8 high | 3.3% | 2017-04-12 |
| CVE-2007-2521 EXP | PHP remote file inclusion vulnerability in common.php in E-GADS! before 2.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the l… | Patch early | 7.5 high | 3.3% | 2007-05-08 |
| CVE-2015-2528 EXP | Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation lev… | Patch early | 7.2 high | 3.3% | 2015-09-09 |
| CVE-2008-4614 EXP | PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to create and delete forums, topic… | Patch early | 7.5 high | 3.3% | 2008-10-20 |
| CVE-2006-4373 EXP | PHP remote file inclusion vulnerability in modules/visitors2/include/config.inc.php in pSlash 0.70 allows remote attackers to execute arbitrary PHP co… | Patch early | 7.5 high | 3.3% | 2006-08-26 |
| CVE-2006-4713 EXP | PHP remote file inclusion vulnerability in config.php in PSYWERKS PUMA 1.0 RC2 allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 3.3% | 2006-09-12 |
| CVE-2015-1723 EXP | Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 an… | Patch early | 7.2 high | 3.3% | 2015-06-10 |
| CVE-2007-0200 EXP | PHP remote file inclusion vulnerability in template.php in Geoffrey Golliher Axiom Photo/News Gallery (axiompng) 0.8.6 allows remote attackers to exec… | Patch early | 7.5 high | 3.3% | 2007-01-11 |
| CVE-2017-7314 EXP | An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating a new role, a list of databas… | Patch early | 7.5 high | 3.3% | 2017-06-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt