CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,058 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-4086 EXP | CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response sp… | Patch early | 5.0 medium | 4.8% | 2009-11-29 |
| CVE-2006-3325 EXP | client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious servers t… | Patch early | 5.0 medium | 4.8% | 2006-06-30 |
| CVE-2008-2542 EXP | Stack-based buffer overflow in the getline function in Ppm/ppm.C in NASA Ames Research Center BigView 1.8 allows user-assisted remote attackers to exe… | Patch early | 6.8 medium | 4.8% | 2008-06-05 |
| CVE-2003-0038 EXP | Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) ema… | Patch early | 4.3 medium | 4.8% | 2003-02-07 |
| CVE-2007-4980 EXP | The readRequest method in org/gcaldaemon/core/http/HTTPListener.java in GCALDaemon 1.0-beta13 allows remote attackers to cause a denial of service via… | Patch early | 4.3 medium | 4.8% | 2007-09-19 |
| CVE-2006-4956 EXP | Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote attackers to inject arbitrary we… | Patch early | 6.8 medium | 4.8% | 2006-09-23 |
| CVE-2018-18774 EXP | CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter. | Patch early | 6.1 medium | 4.8% | 2018-11-20 |
| CVE-2006-1654 EXP | Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows re… | Patch early | 5.0 medium | 4.8% | 2006-04-06 |
| CVE-2009-1063 EXP | Buffer overflow in eXeScope 6.50 allows user-assisted remote attackers to execute arbitrary code via a crafted executable (.exe) file. | Patch early | 6.8 medium | 4.7% | 2009-03-26 |
| CVE-2017-9978 EXP | On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on… | Patch early | 5.3 medium | 4.7% | 2017-08-28 |
| CVE-2009-2654 EXP | Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a… | Patch early | 5.8 medium | 4.7% | 2009-08-03 |
| CVE-2007-1264 EXP | Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail from visually distinguishing b… | Patch early | 5.0 medium | 4.7% | 2007-03-06 |
| CVE-2013-5220 EXP | goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted HTTP POST d… | Patch early | 6.1 medium | 4.7% | 2013-12-30 |
| CVE-2010-0440 EXP | Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA… | Patch early | 4.3 medium | 4.7% | 2010-02-03 |
| CVE-2010-4821 EXP | Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to… | Patch early | 4.3 medium | 4.7% | 2012-10-22 |
| CVE-2010-1947 EXP | Directory traversal vulnerability in scr/soustab.php in openMairie Openregistrecil 1.02, when register_globals is enabled, allows remote attackers to… | Patch early | 6.8 medium | 4.7% | 2010-05-19 |
| CVE-2006-3103 EXP | Cross-site scripting (XSS) vulnerability in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error parameter i… | Patch early | 4.3 medium | 4.7% | 2006-06-21 |
| CVE-2017-13869 EXP | An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchO… | Patch early | 5.5 medium | 4.7% | 2017-12-25 |
| CVE-2005-4467 EXP | Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrary files vi… | Patch early | 5.0 medium | 4.7% | 2005-12-22 |
| CVE-2012-1904 EXP | mp4fformat.dll in the QuickTime File Format plugin in RealNetworks RealPlayer 15 and earlier, and RealPlayer SP 1.1.4 Build 12.0.0.756 and earlier, al… | Patch early | 4.3 medium | 4.7% | 2012-03-28 |
| CVE-2004-1569 EXP | Buffer overflow in (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe in dBpowerAMP Audio Player 2.0 and dbPowerAmp Music Converter 10.0 allows… | Patch early | 4.0 medium | 4.7% | 2004-12-31 |
| CVE-2004-2564 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, allow remote attacke… | Patch early | 4.3 medium | 4.7% | 2004-12-31 |
| CVE-2008-6806 EXP | Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and earlier allows remote attackers to execute arbitrary code by uploa… | Patch early | 6.8 medium | 4.7% | 2009-05-12 |
| CVE-2015-8728 EXP | The Mobile Identity parser in (1) epan/dissectors/packet-ansi_a.c in the ANSI A dissector and (2) epan/dissectors/packet-gsm_a_common.c in the GSM A d… | Patch early | 5.5 medium | 4.7% | 2016-01-04 |
| CVE-2006-0660 EXP | Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary files or trigger an error mess… | Patch early | 6.4 medium | 4.7% | 2006-02-13 |
| CVE-2010-1186 EXP | Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inje… | Patch early | 4.3 medium | 4.7% | 2010-04-07 |
| CVE-2023-33383 EXP | Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a device reload… | Patch early | 5.3 medium | 4.7% | 2023-08-02 |
| CVE-2002-1079 EXP | Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in a… | Patch early | 5.0 medium | 4.7% | 2002-10-04 |
| CVE-2005-0253 EXP | Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to delete arbitrary files via… | Patch early | 4.0 medium | 4.7% | 2005-05-02 |
| CVE-2008-4584 EXP | Insecure method vulnerability in Chilkat Mail 7.8 ActiveX control (ChilkatCert.dll) allows remote attackers to overwrite arbitrary files via a full pa… | Patch early | 6.8 medium | 4.7% | 2008-10-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt