CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,322 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
187,888 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-3558 EXP | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5… | Patch early | 8.5 high | 2.9% | 2017-04-24 |
| CVE-1999-1024 EXP | ip_print procedure in Tcpdump 3.4a allows remote attackers to cause a denial of service via a packet with a zero length header, which causes an infini… | Patch early | 7.5 high | 2.9% | 2001-11-28 |
| CVE-2006-6757 EXP | Directory traversal vulnerability in index.php in cwmExplorer 1.0 allows remote attackers to read arbitrary files and source code, and obtain sensitiv… | Patch early | 7.8 high | 2.9% | 2006-12-27 |
| CVE-2009-1653 EXP | Directory traversal vulnerability in examples/tbs_us_examples_0view.php in TinyButStrong 3.4.0 allows remote attackers to read arbitrary files via a .… | Patch early | 7.8 high | 2.9% | 2009-05-16 |
| CVE-2013-3727 EXP | SQL injection vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users to execute arbitrary SQL commands via the groups[] parame… | Patch early | 7.5 high | 2.9% | 2014-03-13 |
| CVE-2008-6934 EXP | Static code injection vulnerability in Sanus|artificium (aka Sanusart) Free simple guestbook PHP script, when downloaded before 20081111, allows remot… | Patch early | 7.5 high | 2.9% | 2009-08-11 |
| CVE-2008-6231 EXP | Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) ad… | Patch early | 7.5 high | 2.9% | 2009-02-20 |
| CVE-2006-2306 EXP | Cross-site scripting (XSS) vulnerability in moreinfo.asp in EPublisherPro allows remote attackers to inject arbitrary web script or HTML via the title… | Patch early | 9.3 high | 2.9% | 2006-05-11 |
| CVE-2014-2533 EXP | /sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a comma… | Patch early | 7.2 high | 2.9% | 2014-03-18 |
| CVE-2007-3138 EXP | Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to include and execute arbitrary lo… | Patch early | 7.5 high | 2.9% | 2007-06-08 |
| CVE-2007-4008 EXP | Directory traversal vulnerability in custom.php in Entertainment Media Sharing CMS allows remote attackers to include and execute arbitrary local file… | Patch early | 7.5 high | 2.9% | 2007-07-26 |
| CVE-2007-4585 EXP | Directory traversal vulnerability in activateuser.php in 2532|Gigs 1.2.1 allows remote attackers to include and execute arbitrary local files via a ..… | Patch early | 7.5 high | 2.9% | 2007-08-29 |
| CVE-2008-6592 EXP | thumbsup.php in Thumbs-Up 1.12, as used in LightNEasy "no database" (aka flat) and SQLite 1.2.2 and earlier, allows remote attackers to copy, rename,… | Patch early | 7.5 high | 2.9% | 2009-04-03 |
| CVE-2017-6529 EXP | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to session hijacking by guessing the UID parameter. | Patch early | 8.8 high | 2.9% | 2017-03-09 |
| CVE-2008-3568 EXP | Absolute path traversal vulnerability in fckeditor/editor/filemanager/browser/default/connectors/php/connector.php in UNAK-CMS 1.5.5 allows remote att… | Patch early | 7.5 high | 2.9% | 2008-08-10 |
| CVE-2011-4671 EXP | SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote at… | Patch early | 7.5 high | 2.9% | 2011-12-02 |
| CVE-2008-1725 EXP | The IBizEBank.FIProfile.1 ActiveX control in fiprofile20.ocx in IBiz E-Banking Integrator (formerly IBiz OFX Integrator) 2.0.2932 exposes the unsafe W… | Patch early | 9.0 high | 2.9% | 2008-04-11 |
| CVE-2008-6421 EXP | PHP remote file inclusion vulnerability in social_game_play.php in Social Site Generator (SSG) 2.0 allows remote attackers to execute arbitrary PHP co… | Patch early | 7.5 high | 2.9% | 2009-03-06 |
| CVE-2005-2633 EXP | Multiple PHP file inclusion vulnerabilities in (1) admin_o.php, (2) board_o.php, (3) dev_o.php, (4) file_o.php or (5) tech_o.php in PHPTB Topic Board… | Patch early | 7.5 high | 2.9% | 2005-08-23 |
| CVE-2007-5452 EXP | Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote attackers to execute arbitrary SQL commands via the (1… | Patch early | 10.0 high | 2.9% | 2007-10-14 |
| CVE-2006-7130 EXP | PHP remote file inclusion vulnerability in backend/primitives/cache/media.php in Jinzora 2.1 and earlier allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 2.9% | 2007-03-06 |
| CVE-2004-1661 EXP | MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains "auth=1" and "uId=1." | Patch early | 7.5 high | 2.9% | 2004-09-02 |
| CVE-2002-0994 EXP | SunPCi II VNC uses a weak authentication scheme, which allows remote attackers to obtain the VNC password by sniffing the random byte challenge, which… | Patch early | 7.5 high | 2.9% | 2002-10-04 |
| CVE-2014-3136 EXP | Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authent… | Patch early | 8.8 high | 2.9% | 2019-12-27 |
| CVE-2008-6118 EXP | win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cooki… | Patch early | 7.5 high | 2.9% | 2009-02-11 |
| CVE-2006-3314 EXP | PHP remote file inclusion vulnerability in page.php in an unspecified RahnemaCo.com product, possibly eShop, allows remote attackers to execute arbitr… | Patch early | 7.5 high | 2.9% | 2006-06-29 |
| CVE-2006-4349 EXP | PHP remote file inclusion vulnerability in ToendaCMS 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tcms_adm… | Patch early | 7.5 high | 2.9% | 2006-08-24 |
| CVE-2006-4722 EXP | PHP remote file inclusion vulnerability in Open Bulletin Board (OpenBB) 1.0.8 and earlier allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 2.9% | 2006-09-12 |
| CVE-2006-3053 EXP | PHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 2.9% | 2006-06-16 |
| CVE-2007-6650 EXP | Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbitrary files by using the image/… | Patch early | 7.5 high | 2.9% | 2008-01-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt