CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,145 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
187,819 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-7454 EXP | CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST allows an att… | Patch early | 8.0 high | 3.3% | 2016-12-17 |
| CVE-2012-2740 EXP | SQL injection vulnerability in public_html/lists/admin in phpList before 2.10.18 allows remote attackers to execute arbitrary SQL commands via the sor… | Patch early | 7.5 high | 3.3% | 2012-09-06 |
| CVE-2025-54769 EXP | An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing.… | Patch early | 8.8 high | 3.3% | 2025-07-29 |
| CVE-2007-0972 EXP | Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload arbitrary files by modifying th… | Patch early | 7.5 high | 3.3% | 2007-02-16 |
| CVE-2008-3363 EXP | Directory traversal vulnerability in user_portal.php in the Dokeos E-Learning System 1.8.5 on Windows allows remote attackers to include and execute a… | Patch early | 7.5 high | 3.3% | 2008-07-30 |
| CVE-2008-3764 EXP | Eval injection vulnerability in globalsoff.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 3.3% | 2008-08-21 |
| CVE-2008-5967 EXP | admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote… | Patch early | 7.5 high | 3.3% | 2009-01-26 |
| CVE-2008-6581 EXP | login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter. | Patch early | 7.5 high | 3.3% | 2009-04-02 |
| CVE-2007-0573 EXP | PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 3.3% | 2007-01-30 |
| CVE-2007-0839 EXP | Multiple PHP remote file inclusion vulnerabilities in index/index_album.php in Valarsoft WebMatic 2.6 allow remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 3.3% | 2007-02-08 |
| CVE-2007-0848 EXP | PHP remote file inclusion vulnerability in classes/class_mail.inc.php in Maian Recipe 1.0 allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 3.3% | 2007-02-08 |
| CVE-2007-1233 EXP | PHP remote file inclusion vulnerability in downloadcounter.php in STWC-Counter 3.4.0.0 and earlier allows remote attackers to execute arbitrary PHP co… | Patch early | 7.5 high | 3.3% | 2007-03-03 |
| CVE-2007-4486 EXP | Multiple PHP remote file inclusion vulnerabilities in index.php in Linkliste 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 3.3% | 2007-08-22 |
| CVE-2003-0961 EXP | Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges. | Patch early | 7.2 high | 3.3% | 2003-12-15 |
| CVE-1999-0745 EXP | Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler. | Patch early | 10.0 high | 3.3% | 1999-08-18 |
| CVE-2006-4672 EXP | PHP remote file inclusion vulnerability in profitCode ppalCart 2.5 EE, possibly a component of PayProCart, allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 3.3% | 2006-09-11 |
| CVE-2026-24897 EXP | Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files… | Patch early | 10.0 critical | 3.3% | 2026-01-28 |
| CVE-2006-5192 EXP | PHP remote file inclusion vulnerability in includes/footer.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 3.3% | 2006-10-10 |
| CVE-2007-4368 EXP | SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL c… | Patch early | 7.5 high | 3.3% | 2007-08-15 |
| CVE-2014-9303 EXP | EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and password via a UR… | Patch early | 7.8 high | 3.3% | 2014-12-07 |
| CVE-2007-5822 EXP | Direct static code injection vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to inject arbitrary PHP code into a c… | Patch early | 7.5 high | 3.3% | 2007-11-05 |
| CVE-2007-2262 EXP | Multiple PHP remote file inclusion vulnerabilities in html/php/detail.php in Sinato jmuffin allow remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 3.3% | 2007-04-25 |
| CVE-2015-1724 EXP | Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 an… | Patch early | 7.2 high | 3.3% | 2015-06-10 |
| CVE-2004-0348 EXP | SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId para… | Patch early | 10.0 high | 3.3% | 2004-11-23 |
| CVE-2014-3139 EXP | recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth parameter to a… | Patch early | 7.5 high | 3.3% | 2014-05-02 |
| CVE-2002-2176 EXP | SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profile… | Patch early | 10.0 high | 3.3% | 2002-12-31 |
| CVE-2007-0757 EXP | PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and earlier allows remote attackers t… | Patch early | 7.5 high | 3.3% | 2007-02-06 |
| CVE-2007-0762 EXP | PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Build 100 allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 3.3% | 2007-02-06 |
| CVE-2007-0837 EXP | PHP remote file inclusion vulnerability in examples/inc/top.inc.php in AgerMenu 0.03 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 3.3% | 2007-02-08 |
| CVE-2015-2554 EXP | The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain pr… | Patch early | 7.2 high | 3.3% | 2015-10-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt