CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,237 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
187,825 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-16894 EXP | download.php in inoERP 4.15 allows SQL injection through insecure deserialization. | Patch early | 9.8 critical | 3% | 2019-09-26 |
| CVE-2016-9314 EXP | Sensitive Information Disclosure in com.trend.iwss.gui.servlet.ConfigBackup in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.… | Patch early | 7.8 high | 3% | 2017-02-21 |
| CVE-2008-5840 EXP | PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1. | Patch early | 7.5 high | 3% | 2009-01-05 |
| CVE-2009-3962 EXP | The management interface on the 2wire Gateway 1700HG, 1701HG, 1800HW, 2071, 2700HG, and 2701HG-T with software before 5.29.52 allows remote attackers… | Patch early | 7.8 high | 3% | 2009-11-17 |
| CVE-2007-4551 EXP | PHP remote file inclusion vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 7.5 high | 3% | 2007-08-28 |
| CVE-2008-3033 EXP | RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin fu… | Patch early | 9.3 high | 3% | 2008-07-07 |
| CVE-2015-6541 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attacker… | Patch early | 8.8 high | 3% | 2016-04-08 |
| CVE-2013-2645 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities on the TP-LINK WR1043N router with firmware TL-WR1043ND_V1_120405 allow remote attackers to… | Patch early | 9.3 high | 3% | 2014-10-06 |
| CVE-2023-28285 EXP | Microsoft Office Remote Code Execution Vulnerability | Patch early | 7.8 high | 3% | 2023-04-11 |
| CVE-2007-1720 EXP | Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitra… | Patch early | 7.5 high | 3% | 2007-03-28 |
| CVE-2017-8927 EXP | Buffer overflow in Larson VizEx Reader 9.7.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .ti… | Patch early | 7.8 high | 3% | 2017-05-15 |
| CVE-2006-5733 EXP | Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via… | Patch early | 7.5 high | 3% | 2006-11-06 |
| CVE-2008-4141 EXP | Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 3% | 2008-09-24 |
| CVE-2008-4206 EXP | PHP remote file inclusion vulnerability in config.php in Attachmax Dolphin 2.1.0 and earlier, when register_globals is enabled, allows remote attacker… | Patch early | 7.5 high | 3% | 2008-09-24 |
| CVE-2002-1887 EXP | PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l pa… | Patch early | 7.5 high | 3% | 2002-12-31 |
| CVE-2017-7398 EXP | D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted actio… | Patch early | 8.8 high | 3% | 2017-04-04 |
| CVE-2007-1604 EXP | Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute arbitrary PHP code (1) via a for… | Patch early | 7.5 high | 3% | 2007-03-22 |
| CVE-2008-4720 EXP | Multiple PHP remote file inclusion vulnerabilities in The Gemini Portal 4.7 allow remote attackers to execute arbitrary PHP code via a URL in the lang… | Patch early | 9.3 high | 3% | 2008-10-23 |
| CVE-2006-4498 EXP | PHP remote file inclusion vulnerability in sommaire_admin.php in PhpAlbum (mod_phpalbum) 2.15 for PortailPHP allows remote attackers to execute arbitr… | Patch early | 7.5 high | 3% | 2006-08-31 |
| CVE-2006-2523 EXP | PHP remote file inclusion vulnerability in config.php in phpListPro 2.0.1 and earlier, with magic_quotes_gpc disabled, allows remote attackers to exec… | Patch early | 7.5 high | 3% | 2006-05-22 |
| CVE-2018-12602 EXP | A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily. | Patch early | 8.8 high | 3% | 2018-06-25 |
| CVE-2007-0871 EXP | Unrestricted file upload vulnerability in eXtremePow eXtreme File Hosting allows remote attackers to upload arbitrary PHP code via a filename with a d… | Patch early | 7.5 high | 3% | 2007-02-12 |
| CVE-2023-40278 EXP | An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp componen… | Patch early | 7.5 high | 3% | 2024-03-19 |
| CVE-2001-0006 EXP | The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the p… | Patch early | 7.1 high | 3% | 2001-02-12 |
| CVE-2017-17870 EXP | The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action. | Patch early | 9.8 critical | 3% | 2017-12-27 |
| CVE-2005-1547 EXP | Heap-based buffer overflow in the demo version of Bakbone Netvault, and possibly other versions, allows remote attackers to execute arbitrary commands… | Patch early | 7.5 high | 3% | 2005-05-14 |
| CVE-2007-3199 EXP | Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP code by uploading a file with… | Patch early | 7.5 high | 3% | 2007-06-12 |
| CVE-2008-4155 EXP | Multiple directory traversal vulnerabilities in EasySite 2.3 allow remote attackers to read arbitrary files or list directories via a .. (dot dot) in… | Patch early | 7.8 high | 3% | 2008-09-19 |
| CVE-2008-4361 EXP | Directory traversal vulnerability in PowerPortal 2.0.13 allows remote attackers to list and possibly read arbitrary files via a .. (dot dot) in the pa… | Patch early | 7.8 high | 3% | 2008-09-30 |
| CVE-2002-0833 EXP | Buffer overflow in Eudora 5.1.1 and 5.0-J for Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a multi-part… | Patch early | 7.5 high | 3% | 2002-08-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt