CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,973 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-2586 EXP | XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-site scripti… | Patch early | 4.3 medium | 5.2% | 2014-09-29 |
| CVE-2007-1266 EXP | Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing… | Patch early | 5.0 medium | 5.2% | 2007-03-06 |
| CVE-2004-1003 EXP | Trend ScanMail allows remote attackers to obtain potentially sensitive information or disable the anti-virus capability via the smency.nsf file. | Patch early | 5.0 medium | 5.2% | 2005-03-01 |
| CVE-2005-2175 EXP | The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it eas… | Patch early | 5.0 medium | 5.2% | 2005-07-09 |
| CVE-1999-0904 EXP | Buffer overflow in BFTelnet allows remote attackers to cause a denial of service via a long username. | Patch early | 5.0 medium | 5.2% | 1999-11-03 |
| CVE-1999-0928 EXP | Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL. | Patch early | 5.0 medium | 5.2% | 1999-05-23 |
| CVE-2005-0256 EXP | The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion)… | Patch early | 5.0 medium | 5.2% | 2005-05-02 |
| CVE-2011-0900 EXP | Stack-based buffer overflow in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150, and possibly other versions,… | Patch early | 6.8 medium | 5.2% | 2011-02-07 |
| CVE-2008-2045 EXP | Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full p… | Patch early | 5.0 medium | 5.2% | 2008-05-01 |
| CVE-2008-1178 EXP | Directory traversal vulnerability in include/doc/index.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (d… | Patch early | 4.3 medium | 5.2% | 2008-03-06 |
| CVE-2004-1587 EXP | Buffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier, (3) No one lives forever 1.0… | Patch early | 5.0 medium | 5.2% | 2004-12-31 |
| CVE-2018-6191 EXP | The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent validation. | Patch early | 5.5 medium | 5.2% | 2018-01-24 |
| CVE-2014-3427 EXP | CRLF injection vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP… | Patch early | 5.0 medium | 5.2% | 2014-07-16 |
| CVE-2006-1146 EXP | Stack-based buffer overflow in the Cmd_Say_f function in g_cmds.c in Alien Arena 2006 Gold Edition 5.00 allows remote attackers (possibly authenticate… | Patch early | 6.5 medium | 5.2% | 2006-03-10 |
| CVE-2014-1684 EXP | The ASF_ReadObject_file_properties function in modules/demux/asf/libasf.c in the ASF Demuxer in VideoLAN VLC Media Player before 2.1.3 allows remote a… | Patch early | 4.3 medium | 5.2% | 2014-03-03 |
| CVE-2013-1727 EXP | Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and consequently conduct cross-site scripting (XSS) attacks… | Patch early | 4.0 medium | 5.2% | 2013-09-18 |
| CVE-2007-4781 EXP | administrator/index.php in the installer component (com_installer) in Joomla! 1.5 Beta1, Beta2, and RC1 allows remote authenticated administrators to… | Patch early | 6.6 medium | 5.2% | 2007-09-10 |
| CVE-2021-24966 EXP | The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitr… | Patch early | 4.9 medium | 5.2% | 2022-03-14 |
| CVE-2022-41441 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts or HTML via a crafted payload i… | Patch early | 6.1 medium | 5.2% | 2023-01-20 |
| CVE-2010-1945 EXP | Multiple PHP remote file inclusion vulnerabilities in openMairie Openfoncier 2.00, when register_globals is enabled, allow remote attackers to execute… | Patch early | 6.8 medium | 5.2% | 2010-05-19 |
| CVE-2019-16223 EXP | WordPress before 5.2.3 allows XSS in post previews by authenticated users. | Patch early | 5.4 medium | 5.2% | 2019-09-11 |
| CVE-2002-0454 EXP | Qpopper (aka in.qpopper or popper) 4.0.3 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a very large string, w… | Patch early | 5.0 medium | 5.2% | 2002-08-12 |
| CVE-2007-4535 EXP | The VStr::Resize function in str.cpp in Vavoom 1.24 and earlier allows remote attackers to cause a denial of service (daemon crash) via a string with… | Patch early | 4.3 medium | 5.2% | 2007-08-25 |
| CVE-2018-12981 EXP | An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability can be exploited by authenti… | Patch early | 5.4 medium | 5.2% | 2018-07-12 |
| CVE-2018-16517 EXP | asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted fi… | Patch early | 5.5 medium | 5.2% | 2018-09-06 |
| CVE-2007-2753 EXP | RunawaySoft Haber portal 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo… | Patch early | 5.0 medium | 5.2% | 2007-05-17 |
| CVE-2008-5562 EXP | ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database fil… | Patch early | 5.0 medium | 5.2% | 2008-12-15 |
| CVE-2009-2022 EXP | fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the data… | Patch early | 5.0 medium | 5.2% | 2009-06-09 |
| CVE-2007-5508 EXP | Multiple SQL injection vulnerabilities in the CTXSYS Intermedia application for the Oracle Text component (CTX_DOC) in Oracle Database 10.1.0.5 and 10… | Patch early | 6.5 medium | 5.2% | 2007-10-17 |
| CVE-2011-2165 EXP | The STARTTLS implementation in WatchGuard XCS 9.0 and 9.1 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert… | Patch early | 6.8 medium | 5.2% | 2011-05-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt