CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,959 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-0985 EXP | Directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla! allows remote attackers to include and execute a… | Patch early | 7.5 high | 13.3% | 2010-03-16 |
| CVE-2002-0495 EXP | csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, whi… | Patch early | 10.0 high | 13.3% | 2002-08-12 |
| CVE-2001-0099 EXP | bsguest.cgi guestbook script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address. | Patch early | 10.0 high | 13.3% | 2001-02-12 |
| CVE-2009-0388 EXP | Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap… | Patch early | 10.0 high | 13.3% | 2009-02-04 |
| CVE-2015-3798 EXP | The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute arbitrary code or cause a deni… | Patch early | 7.5 high | 13.3% | 2015-08-17 |
| CVE-2018-8880 EXP | Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing the /deviceIP information, which… | Patch early | 7.5 high | 13.3% | 2018-04-23 |
| CVE-2002-1605 EXP | Buffer overflow in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows attackers to execute arbitrary code via a long _XKB_CHARSET environment variab… | Patch early | 7.5 high | 13.3% | 2002-09-02 |
| CVE-2007-1721 EXP | Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 10.0 high | 13.3% | 2007-03-28 |
| CVE-2019-9599 EXP | The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash) via many simultaneous sdctl/… | Patch early | 7.5 high | 13.3% | 2019-03-06 |
| CVE-2001-0008 EXP | Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures. | Patch early | 10.0 high | 13.3% | 2001-02-12 |
| CVE-2019-10266 EXP | An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the f… | Patch early | 7.5 high | 13.3% | 2019-07-26 |
| CVE-2015-7805 EXP | Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF fi… | Patch early | 9.3 high | 13.3% | 2015-11-17 |
| CVE-2009-1376 EXP | Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpu… | Patch early | 9.3 high | 13.3% | 2009-05-26 |
| CVE-2009-2195 EXP | Buffer overflow in WebKit in Apple Safari before 4.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application cra… | Patch early | 9.3 high | 13.3% | 2009-08-12 |
| CVE-2016-8022 EXP | Authentication bypass by spoofing vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated… | Patch early | 7.5 high | 13.3% | 2017-03-14 |
| CVE-2012-2027 EXP | Use-after-free vulnerability in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary cod… | Patch early | 9.3 high | 13.3% | 2012-05-09 |
| CVE-2006-2548 EXP | Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url… | Patch early | 7.5 high | 13.3% | 2006-05-23 |
| CVE-2019-12828 EXP | An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and origin2:// URI schemes, it is poss… | Patch early | 8.8 high | 13.3% | 2019-06-14 |
| CVE-2016-1879 EXP | The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, when the kernel is configured f… | Patch early | 7.5 high | 13.3% | 2016-01-29 |
| CVE-2011-2900 EXP | Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server… | Patch early | 7.5 high | 13.3% | 2011-08-05 |
| CVE-2020-5330 EXP | Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 and older and Dell EMC PowerEd… | Patch early | 8.1 high | 13.3% | 2020-04-10 |
| CVE-2004-0722 EXP | Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allow… | Patch early | 10.0 high | 13.2% | 2004-08-18 |
| CVE-2006-0146 EXP | The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) X… | Patch early | 7.5 high | 13.2% | 2006-01-09 |
| CVE-2010-4107 EXP | The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printers, Color LaserJet MFP printers… | Patch early | 7.8 high | 13.2% | 2010-11-17 |
| CVE-2009-2464 EXP | The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote atta… | Patch early | 10.0 high | 13.2% | 2009-07-22 |
| CVE-2009-0261 EXP | Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary code via a Skins\DefaultSkin\D… | Patch early | 9.3 high | 13.2% | 2009-01-23 |
| CVE-2010-2036 EXP | Directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbit… | Patch early | 7.5 high | 13.2% | 2010-05-25 |
| CVE-2007-3181 EXP | Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p… | Patch early | 10.0 high | 13.2% | 2007-06-12 |
| CVE-2004-0416 EXP | Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execu… | Patch early | 10.0 high | 13.2% | 2004-08-06 |
| CVE-2018-12604 EXP | GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log. | Patch early | 7.5 high | 13.2% | 2018-06-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt