CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,240 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
187,825 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-0805 EXP | The CAPTCHA functionality in php-Nuke 6.0 through 7.9 uses fixed challenge/response pairs that only vary once per day based on the User Agent (HTTP_US… | Patch early | 7.5 high | 3% | 2006-02-21 |
| CVE-2008-1534 EXP | Multiple directory traversal vulnerabilities in PowerPHPBoard 1.00b allow remote attackers to include and execute arbitrary local files via a .. (dot… | Patch early | 7.5 high | 3% | 2008-03-28 |
| CVE-2006-3734 EXP | Multiple unspecified vulnerabilities in the Command Line Interface (CLI) for Cisco Security Monitoring, Analysis and Response System (CS-MARS) before… | Patch early | 7.2 high | 3% | 2006-07-21 |
| CVE-2019-0570 EXP | An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka "Windows Runtime Elevation of Privil… | Patch early | 7.8 high | 3% | 2019-01-08 |
| CVE-2009-4082 EXP | PHP remote file inclusion vulnerability in forums/Forum_Include/index.php in Outreach Project Tool (OPT) 1.2.7 and earlier allows remote attackers to… | Patch early | 7.5 high | 3% | 2009-11-29 |
| CVE-2013-6792 EXP | Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability | Patch early | 9.8 critical | 3% | 2020-01-23 |
| CVE-2010-0975 EXP | PHP remote file inclusion vulnerability in external.php in PHPCityPortal allows remote attackers to execute arbitrary PHP code via a URL in the url pa… | Patch early | 7.5 high | 3% | 2010-03-16 |
| CVE-2010-1114 EXP | Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to execute arbitrary PHP code via a U… | Patch early | 7.5 high | 3% | 2010-03-25 |
| CVE-2008-5920 EXP | The create_anchors function in utils.inc in WebSVN 1.x allows remote attackers to execute arbitrary PHP code via a crafted username that is processed… | Patch early | 7.5 high | 3% | 2009-01-21 |
| CVE-2008-1635 EXP | Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remote attackers to include and ex… | Patch early | 7.5 high | 3% | 2008-04-02 |
| CVE-2007-2324 EXP | Directory traversal vulnerability in file.php in JulmaCMS 1.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter… | Patch early | 7.8 high | 3% | 2007-04-27 |
| CVE-2005-3005 EXP | Helpdesk Software Hesk allows remote attackers to bypass authentication for (1) admin.php and (2) admin_main.php by modifying the PHPSESSID session ID… | Patch early | 7.5 high | 3% | 2005-09-21 |
| CVE-2008-4427 EXP | changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows rem… | Patch early | 7.5 high | 3% | 2008-10-03 |
| CVE-2018-8134 EXP | An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulner… | Patch early | 7.0 high | 3% | 2018-05-09 |
| CVE-2010-4234 EXP | The web server on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to c… | Patch early | 7.8 high | 3% | 2010-11-17 |
| CVE-2017-6411 EXP | Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any pa… | Patch early | 8.8 high | 3% | 2017-03-06 |
| CVE-2007-5050 EXP | Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot d… | Patch early | 7.5 high | 3% | 2007-09-24 |
| CVE-2007-5069 EXP | Directory traversal vulnerability in data/compatible.php in the Nuke Mobile Entertainment 1 addon for PHP-Nuke allows remote attackers to include and… | Patch early | 7.5 high | 3% | 2007-09-24 |
| CVE-2004-1693 EXP | PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifying the mo… | Patch early | 7.5 high | 3% | 2004-09-18 |
| CVE-2004-1820 EXP | PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitra… | Patch early | 7.5 high | 3% | 2004-03-15 |
| CVE-2007-2326 EXP | Multiple PHP remote file inclusion vulnerabilities in HYIP Manager Pro allow remote attackers to execute arbitrary PHP code via a URL in the plugin_fi… | Patch early | 7.5 high | 3% | 2007-04-27 |
| CVE-2007-5845 EXP | Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include and execute arbitrary local file… | Patch early | 7.5 high | 3% | 2007-11-06 |
| CVE-2009-4753 EXP | Multiple buffer overflows in the FTP server on the Addonics NAS Adapter NASU2FW41 with loader 1.17 allow remote attackers to cause a denial of service… | Patch early | 7.1 high | 3% | 2010-03-29 |
| CVE-2019-6249 EXP | An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_inf… | Patch early | 8.8 high | 3% | 2019-01-13 |
| CVE-2018-6363 EXP | SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter. | Patch early | 9.8 critical | 3% | 2018-01-29 |
| CVE-2017-17570 EXP | FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17571 EXP | FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17572 EXP | FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17574 EXP | FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17575 EXP | FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt