CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,164 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
187,824 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-18803 EXP | Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb. | Patch early | 9.8 critical | 3.2% | 2018-11-16 |
| CVE-2018-18804 EXP | Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb. | Patch early | 9.8 critical | 3.2% | 2018-11-16 |
| CVE-2018-18923 EXP | AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and description in action/addproje… | Patch early | 9.8 critical | 3.2% | 2018-12-13 |
| CVE-2025-24076 EXP | Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | Patch early | 7.3 high | 3.2% | 2025-03-11 |
| CVE-2008-6937 EXP | Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cau… | Patch early | 10.0 high | 3.2% | 2009-08-11 |
| CVE-2007-1493 EXP | nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, which allows remote attackers to e… | Patch early | 7.5 high | 3.2% | 2007-03-16 |
| CVE-2009-1516 EXP | Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependent… | Patch early | 7.5 high | 3.2% | 2009-05-04 |
| CVE-2021-27885 EXP | usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism. | Patch early | 8.8 high | 3.2% | 2021-03-02 |
| CVE-2006-1031 EXP | config/config_inc.php in iGENUS Webmail 2.02 and earlier allows remote attackers to include arbitrary local files via the SG_HOME parameter. | Patch early | 7.5 high | 3.2% | 2006-03-07 |
| CVE-2018-0749 EXP | The Microsoft Server Message Block (SMB) Server in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and… | Patch early | 7.8 high | 3.2% | 2018-01-04 |
| CVE-2018-17182 EXP | An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An… | Patch early | 7.8 high | 3.2% | 2018-09-19 |
| CVE-2006-3777 EXP | PHP remote file inclusion vulnerability in index.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 3.2% | 2006-07-24 |
| CVE-2007-6378 EXP | Directory traversal vulnerability in upload.dll in BadBlue 2.72b and earlier allows remote attackers to create or overwrite arbitrary files via a .. (… | Patch early | 7.5 high | 3.2% | 2007-12-15 |
| CVE-2007-0633 EXP | PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attackers to execute arbitrary PHP c… | Patch early | 7.5 high | 3.2% | 2007-01-31 |
| CVE-2007-0662 EXP | PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 3.2% | 2007-02-01 |
| CVE-2007-0701 EXP | PHP remote file inclusion vulnerability in inc/common.inc.php in Epistemon 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 3.2% | 2007-02-04 |
| CVE-2005-1203 EXP | Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands via the (1… | Patch early | 7.5 high | 3.2% | 2005-05-02 |
| CVE-2006-4285 EXP | PHP remote file inclusion vulnerability in news.php in Fantastic News 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 3.2% | 2006-08-22 |
| CVE-2015-7381 EXP | Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to exec… | Patch early | 7.5 high | 3.2% | 2015-09-28 |
| CVE-2007-2722 EXP | Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instability) via certain invalid string… | Patch early | 7.8 high | 3.2% | 2007-05-16 |
| CVE-2007-2671 EXP | Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in an HREF attribute in an A elem… | Patch early | 7.1 high | 3.2% | 2007-05-14 |
| CVE-2025-7795 EXP | A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the function fromP2pListFilter of… | Patch early | 8.8 high | 3.2% | 2025-07-18 |
| CVE-1999-0968 EXP | Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges. | Patch early | 7.5 high | 3.2% | 1998-12-26 |
| CVE-2008-7064 EXP | Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5,… | Patch early | 7.5 high | 3.2% | 2009-08-25 |
| CVE-2023-0905 EXP | A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the fi… | Patch early | 7.3 high | 3.2% | 2023-02-18 |
| CVE-2001-0365 EXP | Eudora before 5.1 allows a remote attacker to execute arbitrary code, when the 'Use Microsoft Viewer' and 'allow executables in HTML content' options… | Patch early | 7.5 high | 3.2% | 2001-06-27 |
| CVE-2006-5053 EXP | PHP remote file inclusion vulnerability in webnews/template.php in Web-News 1.6.3 and earlier allows remote attackers to execute arbitrary PHP code vi… | Patch early | 7.5 high | 3.2% | 2006-09-28 |
| CVE-2006-5061 EXP | PHP remote file inclusion vulnerability in mcf.php in Advanced-Clan-Script (AVCX) 3.4 and earlier allows remote attackers to execute arbitrary PHP cod… | Patch early | 7.5 high | 3.2% | 2006-09-28 |
| CVE-2006-5304 EXP | PHP remote file inclusion vulnerability in inc/settings.php in IncCMS Core 1.0.0 and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 3.2% | 2006-10-17 |
| CVE-2006-5413 EXP | Multiple PHP remote file inclusion vulnerabilities in SuperMod 3.0.0 for YABB (YaBBSM) allow remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 3.2% | 2006-10-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt