CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,502 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-8831 EXP | A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of t… | Patch early | 6.1 medium | 52.7% | 2018-04-18 |
| CVE-2008-2549 EXP | Adobe Acrobat Reader 8.1.2 and earlier, and before 7.1.1, allows remote attackers to cause a denial of service (application crash) and possibly execut… | Patch early | 4.3 medium | 52.6% | 2008-06-04 |
| CVE-2012-5192 EXP | Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to read arbitrary files via "''%2F"… | Patch early | 5.0 medium | 52.5% | 2014-01-28 |
| CVE-2007-3898 EXP | The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, wh… | Patch early | 6.4 medium | 52.3% | 2007-11-14 |
| CVE-2015-1397 EXP | SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1.0 and Ent… | Patch early | 6.5 medium | 52.3% | 2015-04-29 |
| CVE-2012-4031 EXP | Multiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote attackers to read arbitrary files via… | Patch early | 5.0 medium | 52.3% | 2012-07-17 |
| CVE-2019-8953 EXP | The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php… | Patch early | 6.1 medium | 52.2% | 2019-02-20 |
| CVE-2012-0897 EXP | Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (… | Patch early | 6.8 medium | 52.2% | 2012-01-20 |
| CVE-2010-1622 EXP | SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary c… | Patch early | 6.0 medium | 52% | 2010-06-21 |
| CVE-2015-1487 EXP | The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrary… | Patch early | 5.5 medium | 52% | 2015-08-01 |
| CVE-2019-13068 EXP | public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field). | Patch early | 5.4 medium | 51.9% | 2019-06-30 |
| CVE-2007-4232 EXP | PHP remote file inclusion vulnerability in admin/inc/change_action.php in Andreas Robertz PHPNews 0.93 allows remote attackers to execute arbitrary PH… | Patch early | 6.8 medium | 51.7% | 2007-08-08 |
| CVE-2011-0522 EXP | The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text decoder (modules/codec/subtitles/subsusf.c) in Vide… | Patch early | 6.8 medium | 51.5% | 2011-02-07 |
| CVE-2013-1847 EXP | The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of ser… | Patch early | 5.0 medium | 51.4% | 2013-05-02 |
| CVE-2010-4052 EXP | Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, all… | Patch early | 5.0 medium | 51.3% | 2011-01-13 |
| CVE-2008-1365 EXP | Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, al… | Patch early | 6.4 medium | 51.1% | 2008-03-17 |
| CVE-2000-0665 EXP | GAMSoft TelSrv telnet server 1.5 and earlier allows remote attackers to cause a denial of service via a long username. | Patch early | 5.0 medium | 51% | 2000-07-17 |
| CVE-2000-0869 EXP | The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPF… | Patch early | 5.0 medium | 51% | 2000-11-14 |
| CVE-2017-3548 EXP | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions… | Patch early | 6.5 medium | 50.8% | 2017-04-24 |
| CVE-2015-8256 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras. | Patch early | 6.1 medium | 50.8% | 2017-04-17 |
| CVE-2007-4336 EXP | Buffer overflow in the Live Picture Corporation DXSurface.LivePicture.FlashPix.1 (DirectTransform FlashPix) ActiveX control in DXTLIPI.DLL 6.0.2.827,… | Patch early | 4.3 medium | 50.7% | 2007-08-14 |
| CVE-2008-1562 EXP | The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via… | Patch early | 5.0 medium | 50.7% | 2008-03-31 |
| CVE-2004-0120 EXP | The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a den… | Patch early | 5.0 medium | 50.7% | 2004-06-01 |
| CVE-2010-0904 EXP | Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect integrity via unknown vectors. | Patch early | 5.0 medium | 50.6% | 2010-07-13 |
| CVE-2005-0553 EXP | Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers… | Patch early | 5.1 medium | 50.6% | 2005-05-02 |
| CVE-2011-3639 EXP | The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not pro… | Patch early | 4.3 medium | 50.6% | 2011-11-30 |
| CVE-2014-9308 EXP | Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping Cart) plugin b… | Patch early | 6.5 medium | 50.6% | 2015-01-15 |
| CVE-2001-1410 EXP | Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createPopup method, which could allow… | Patch early | 5.0 medium | 50.5% | 2003-08-18 |
| CVE-2013-1884 EXP | The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault… | Patch early | 5.0 medium | 50.5% | 2013-05-02 |
| CVE-2012-2336 EXP | sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings… | Patch early | 5.0 medium | 50.3% | 2012-05-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt