CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,367 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
187,895 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-4239 EXP | PHP remote file inclusion vulnerability in include/urights.php in Outreach Project Tool (OPT) Max 1.2.6 and earlier allows remote attackers to execute… | Patch early | 7.5 high | 2.8% | 2006-08-21 |
| CVE-2006-4644 EXP | PHP remote file inclusion vulnerability in modules/home.module.php in phpFullAnnu 5.1 and earlier allows remote attackers to execute arbitrary PHP cod… | Patch early | 7.5 high | 2.8% | 2006-09-08 |
| CVE-2006-4769 EXP | PHP remote file inclusion vulnerability in abf_js.php in p4CMS 1.05 allows remote attackers to execute arbitrary PHP code via a URL in the abs_pfad pa… | Patch early | 7.5 high | 2.8% | 2006-09-13 |
| CVE-2006-2996 EXP | PHP remote file inclusion vulnerability in inc/design.inc.php in LoveCompass aePartner 0.8.3 and earlier allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 2.8% | 2006-06-13 |
| CVE-2004-1383 EXP | Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL statements via the (1) o… | Patch early | 7.5 high | 2.8% | 2004-12-31 |
| CVE-2008-1169 EXP | Directory traversal vulnerability in the embedded HTTP server in SCI Photo Chat Server 3.4.9 and earlier allows remote attackers to read arbitrary fil… | Patch early | 7.8 high | 2.8% | 2008-03-05 |
| CVE-2006-2865 EXP | PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the page paramet… | Patch early | 7.5 high | 2.8% | 2006-06-06 |
| CVE-2002-0995 EXP | login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action parameter set to "insert," which ad… | Patch early | 7.5 high | 2.8% | 2002-10-04 |
| CVE-2002-1027 EXP | Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers… | Patch early | 7.5 high | 2.8% | 2002-10-04 |
| CVE-2001-1108 EXP | Directory traversal vulnerability in SnapStream PVS 1.2a allows remote attackers to read arbitrary files via a .. (dot dot) attack in the requested UR… | Patch early | 7.5 high | 2.8% | 2001-07-26 |
| CVE-2010-0673 EXP | SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress allows remote attackers to exe… | Patch early | 7.5 high | 2.8% | 2010-02-22 |
| CVE-2012-4997 EXP | Directory traversal vulnerability in acp/index.php in AneCMS allows remote attackers to include and execute arbitrary local files via a .. (dot dot) i… | Patch early | 7.5 high | 2.8% | 2012-09-19 |
| CVE-2009-3807 EXP | Stack-based buffer overflow in MixVibes 7.043 Pro allows remote attackers to cause a denial of service (crash) via a long string in a .vib file. | Patch early | 9.3 high | 2.8% | 2009-10-27 |
| CVE-2010-2924 EXP | SQL injection vulnerability in myLDlinker.php in the myLinksDump Plugin 1.2 for WordPress allows remote attackers to execute arbitrary SQL commands vi… | Patch early | 7.5 high | 2.8% | 2010-07-30 |
| CVE-2001-0704 EXP | tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory via a URL with a template argum… | Patch early | 7.5 high | 2.8% | 2001-09-20 |
| CVE-2002-0590 EXP | Cross-site scripting (CSS) vulnerability in IcrediBB 1.1 Beta allows remote attackers to execute arbitrary script and steal cookies as other IcrediBB… | Patch early | 7.5 high | 2.8% | 2002-06-18 |
| CVE-2002-0783 EXP | Opera 6.01, 6.0, and 5.12 allows remote attackers to execute arbitrary JavaScript in the security context of other sites by setting the location of a… | Patch early | 7.5 high | 2.8% | 2002-08-12 |
| CVE-2002-1410 EXP | Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi,… | Patch early | 7.5 high | 2.8% | 2003-04-11 |
| CVE-2006-5316 EXP | registroTL stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via… | Patch early | 7.8 high | 2.8% | 2006-10-17 |
| CVE-2002-0897 EXP | LocalWEB2000 2.1.0 web server allows remote attackers to bypass access restrictions for restricted files via a URL that contains the "/./" directory. | Patch early | 7.5 high | 2.8% | 2002-10-04 |
| CVE-2017-13253 EXP | In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalati… | Patch early | 7.8 high | 2.8% | 2018-04-04 |
| CVE-2019-16065 EXP | A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows an attacker to execute SQL comm… | Patch early | 8.8 high | 2.8% | 2020-03-19 |
| CVE-2008-5497 EXP | BandSite CMS 1.1.4 allows remote attackers to bypass authentication and gain administrative access by setting the login_auth cookie to true. | Patch early | 7.5 high | 2.8% | 2008-12-12 |
| CVE-2007-5752 EXP | adduser.php in PHP-AGTC Membership (AGTC-Membership) System 1.1a does not require authentication, which allows remote attackers to create accounts via… | Patch early | 7.5 high | 2.8% | 2007-10-31 |
| CVE-2010-2005 EXP | Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitrary PHP code via a URL in (1)… | Patch early | 7.5 high | 2.8% | 2010-05-20 |
| CVE-2007-2934 EXP | Directory traversal vulnerability in skins/common.css.php in Vistered Little 1.6a allows remote attackers to read arbitrary files via a .. (dot dot) i… | Patch early | 7.8 high | 2.8% | 2007-05-31 |
| CVE-2004-2053 EXP | PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitrary PHP code via the site param… | Patch early | 7.5 high | 2.8% | 2004-07-24 |
| CVE-2006-2818 EXP | PHP remote file inclusion vulnerability in common-menu.php in Cameron McKay Informium 0.12.0 allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 2.8% | 2006-06-05 |
| CVE-2006-2888 EXP | PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 2.8% | 2006-06-07 |
| CVE-2006-3375 EXP | PHP remote file inclusion vulnerability in includes/header.inc.php in Randshop 1.1.1 allows remote attackers to execute arbitrary PHP code via the dat… | Patch early | 7.5 high | 2.8% | 2006-07-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt