CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,061 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-22833 EXP | An issue was discovered in Servisnet Tessa 0.0.2. An attacker can obtain sensitive information via a /js/app.js request. | Patch early | 7.5 high | 11.6% | 2022-02-06 |
| CVE-2015-4181 EXP | Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot)… | Patch early | 7.5 high | 11.6% | 2017-08-25 |
| CVE-2003-0263 EXP | Multiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitrary code via long (1) MAIL FRO… | Patch early | 7.5 high | 11.6% | 2003-05-27 |
| CVE-2013-7186 EXP | Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long string in a .m3u file. | Patch early | 9.3 high | 11.6% | 2013-12-20 |
| CVE-2013-2261 EXP | Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure | Patch early | 7.5 high | 11.6% | 2019-11-04 |
| CVE-2013-1605 EXP | Buffer overflow in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to execute arbitrary code via a long filename in… | Patch early | 7.5 high | 11.5% | 2014-03-25 |
| CVE-1999-0284 EXP | Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. | Patch early | 7.5 high | 11.5% | 1998-01-01 |
| CVE-2009-0544 EXP | Buffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large… | Patch early | 10.0 high | 11.5% | 2009-02-12 |
| CVE-2008-1289 EXP | Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x b… | Patch early | 7.5 high | 11.5% | 2008-03-24 |
| CVE-2002-0599 EXP | Blahz-DNS 0.2 and earlier allows remote attackers to bypass authentication and modify configuration by directly requesting CGI programs such as dostuf… | Patch early | 10.0 high | 11.5% | 2002-06-18 |
| CVE-2000-1014 EXP | Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute arbitrary command… | Patch early | 7.5 high | 11.5% | 2000-12-11 |
| CVE-2004-0816 EXP | Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service (application c… | Patch early | 7.5 high | 11.5% | 2004-12-23 |
| CVE-2000-0909 EXP | Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long Fro… | Patch early | 7.5 high | 11.5% | 2000-12-19 |
| CVE-2011-2543 EXP | Buffer overflow in the cuil component in Cisco Telepresence System Integrator C Series 4.x before TC4.2.0 allows remote authenticated users to cause a… | Patch early | 9.0 high | 11.5% | 2011-09-23 |
| CVE-2016-1610 EXP | Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows re… | Patch early | 7.5 high | 11.5% | 2016-08-01 |
| CVE-2006-2849 EXP | PHP remote file inclusion vulnerability in includes/webdav/server.php in Bytehoard 2.1 Epsilon/Delta allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 11.5% | 2006-06-06 |
| CVE-2003-1425 EXP | guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter. | Patch early | 10.0 high | 11.5% | 2003-12-31 |
| CVE-2005-3486 EXP | Multiple format string vulnerabilities in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole… | Patch early | 7.5 high | 11.5% | 2005-11-03 |
| CVE-2009-4112 EXP | Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memor… | Patch early | 9.0 high | 11.5% | 2009-11-30 |
| CVE-2018-18428 EXP | TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg URI. | Patch early | 7.5 high | 11.5% | 2018-10-19 |
| CVE-2021-3337 EXP | The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on repl… | Patch early | 7.5 high | 11.5% | 2021-01-28 |
| CVE-2019-2697 EXP | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Diffic… | Patch early | 8.1 high | 11.5% | 2019-04-23 |
| CVE-2000-0165 EXP | The Delegate application proxy has several buffer overflows which allow a remote attacker to execute commands. | Patch early | 7.5 high | 11.5% | 1999-11-13 |
| CVE-2005-2616 EXP | Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.ph… | Patch early | 7.5 high | 11.5% | 2005-08-17 |
| CVE-2006-4832 EXP | Buffer overflow in the telnet service in Verso NetPerformer FRAD ACT SDM-95xx 7.xx (R1) and earlier, SDM-93xx 10.x.x (R2) and earlier, and SDM-92xx 9.… | Patch early | 7.5 high | 11.4% | 2006-09-15 |
| CVE-2012-3574 EXP | Unrestricted file upload vulnerability in includes/doajaxfileupload.php in the MM Forms Community plugin 2.2.5 and 2.2.6 for WordPress allows remote a… | Patch early | 7.5 high | 11.4% | 2012-06-16 |
| CVE-2001-1022 EXP | Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option… | Patch early | 7.5 high | 11.4% | 2001-07-26 |
| CVE-2010-1878 EXP | Directory traversal vulnerability in the OrgChart (com_orgchart) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a ..… | Patch early | 7.5 high | 11.4% | 2010-05-12 |
| CVE-2014-9147 EXP | Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/. | Patch early | 7.5 high | 11.4% | 2017-10-16 |
| CVE-2019-9189 EXP | Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central c… | Patch early | 8.8 high | 11.4% | 2019-06-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt