CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,355 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
187,891 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-1469 EXP | scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass… | Patch early | 7.5 high | 2.9% | 2003-04-22 |
| CVE-2006-1838 EXP | edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie. | Patch early | 7.5 high | 2.9% | 2006-04-19 |
| CVE-2008-2216 EXP | Unrestricted file upload vulnerability in src/yopy_upload.php in Project-Based Calendaring System (PBCS) 0.7.1 allows remote authenticated users to up… | Patch early | 9.0 high | 2.9% | 2008-05-14 |
| CVE-2007-6311 EXP | SQL injection vulnerability in (1) index.php, and possibly (2) admin/index.php, in Falt4Extreme RC4 10.9.2007 allows remote attackers to execute arbit… | Patch early | 7.5 high | 2.9% | 2007-12-11 |
| CVE-2007-1633 EXP | Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include… | Patch early | 7.5 high | 2.9% | 2007-03-23 |
| CVE-2002-0244 EXP | Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument t… | Patch early | 7.5 high | 2.9% | 2002-05-29 |
| CVE-2008-6232 EXP | Pre Shopping Mall allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid coo… | Patch early | 7.5 high | 2.9% | 2009-02-20 |
| CVE-2009-1246 EXP | Multiple directory traversal vulnerabilities in Blogplus 1.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in… | Patch early | 7.5 high | 2.9% | 2009-04-06 |
| CVE-2006-1363 EXP | images.php in Justin White (aka YTZ) Free Web Publishing System (FreeWPS) 2.11 allows remote attackers to execute arbitrary PHP code by uploading a .p… | Patch early | 7.5 high | 2.9% | 2006-03-23 |
| CVE-2009-0070 EXP | Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (applic… | Patch early | 9.3 high | 2.9% | 2009-01-08 |
| CVE-2017-15972 EXP | SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /… | Patch early | 9.8 critical | 2.9% | 2017-10-29 |
| CVE-2017-15973 EXP | Sokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php. | Patch early | 9.8 critical | 2.9% | 2017-10-29 |
| CVE-2008-4499 EXP | Multiple directory traversal vulnerabilities in PHP Web Explorer 0.99b and earlier allow remote attackers to include and execute arbitrary local files… | Patch early | 9.3 high | 2.9% | 2008-10-09 |
| CVE-2018-7216 EXP | Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal allows remote authenticated user… | Patch early | 8.0 high | 2.9% | 2018-02-18 |
| CVE-2008-4244 EXP | Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the usuario and pass cookies to 1. | Patch early | 7.5 high | 2.9% | 2008-09-25 |
| CVE-2013-5917 EXP | SQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL comman… | Patch early | 7.5 high | 2.9% | 2013-09-23 |
| CVE-2007-2155 EXP | Directory traversal vulnerability in template.php in in phpFaber TopSites 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the… | Patch early | 7.8 high | 2.9% | 2007-04-19 |
| CVE-2007-0577 EXP | PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 2.9% | 2007-01-30 |
| CVE-2008-0520 EXP | Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary SQ… | Patch early | 7.5 high | 2.9% | 2008-01-31 |
| CVE-2008-0682 EXP | SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers to execute arbitrary SQL comm… | Patch early | 7.5 high | 2.8% | 2008-02-12 |
| CVE-2013-4011 EXP | Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privi… | Patch early | 7.2 high | 2.8% | 2013-07-18 |
| CVE-2008-6183 EXP | Multiple directory traversal vulnerabilities in index.php in My PHP Indexer 1.0 allow remote attackers to read arbitrary files via a .. (dot dot) in t… | Patch early | 7.8 high | 2.8% | 2009-02-19 |
| CVE-2005-3819 EXP | Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass authentication… | Patch early | 7.5 high | 2.8% | 2005-11-26 |
| CVE-2002-0117 EXP | Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitrary script an… | Patch early | 7.5 high | 2.8% | 2002-03-25 |
| CVE-2001-1086 EXP | XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote at… | Patch early | 7.5 high | 2.8% | 2001-07-04 |
| CVE-2008-6940 EXP | TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to… | Patch early | 7.5 high | 2.8% | 2009-08-12 |
| CVE-2008-6957 EXP | member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd action… | Patch early | 7.5 high | 2.8% | 2009-08-12 |
| CVE-2008-2482 EXP | Directory traversal vulnerability in install_mod.php in insanevisions OneCMS 2.5 allows remote attackers to include and execute arbitrary local files… | Patch early | 7.5 high | 2.8% | 2008-05-28 |
| CVE-2008-3179 EXP | Directory traversal vulnerability in website.php in Web 2 Business (W2B) phpDatingClub (aka Dating Club) 3.7 allows remote attackers to include and ex… | Patch early | 7.5 high | 2.8% | 2008-07-15 |
| CVE-2008-4346 EXP | Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot… | Patch early | 7.5 high | 2.8% | 2008-09-30 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt