CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,061 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-3607 EXP | Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_set… | Patch early | 4.4 medium | 4.7% | 2011-11-08 |
| CVE-2006-7080 EXP | Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".."… | Patch early | 4.3 medium | 4.7% | 2007-03-02 |
| CVE-2007-4537 EXP | Heap-based buffer overflow in the Huffman decompression algorithm implemented in Skulltag 0.97d-beta4.1 and earlier allows remote attackers to execute… | Patch early | 6.8 medium | 4.7% | 2007-08-27 |
| CVE-2007-2980 EXP | Heap-based buffer overflow in a certain ActiveX control in LEADTOOLS LEAD Raster ISIS Object (LTRIS14e.DLL) 14.5.0.44 allows remote attackers to cause… | Patch early | 6.8 medium | 4.7% | 2007-06-01 |
| CVE-2017-13868 EXP | An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchO… | Patch early | 5.5 medium | 4.7% | 2017-12-25 |
| CVE-2014-4962 EXP | Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantity parame… | Patch early | 6.4 medium | 4.7% | 2014-07-15 |
| CVE-2006-1102 EXP | Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (client exit) by forcing the server to c… | Patch early | 5.0 medium | 4.7% | 2006-03-09 |
| CVE-2019-10226 EXP | HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI. NOTE: the ven… | Patch early | 5.4 medium | 4.7% | 2019-06-10 |
| CVE-2008-7026 EXP | Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary co… | Patch early | 6.8 medium | 4.7% | 2009-08-21 |
| CVE-2009-1873 EXP | Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4 Updater 7 allows remote authen… | Patch early | 4.0 medium | 4.7% | 2009-08-18 |
| CVE-2009-1294 EXP | Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remo… | Patch early | 4.3 medium | 4.7% | 2009-04-16 |
| CVE-2022-34140 EXP | A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts… | Patch early | 5.4 medium | 4.7% | 2022-07-28 |
| CVE-2002-2195 EXP | Buffer overflow in the version update check for Winamp 2.80 and earlier allows remote attackers who can spoof www.winamp.com to execute arbitrary code… | Patch early | 5.0 medium | 4.7% | 2002-12-31 |
| CVE-2015-4010 EXP | Cross-site request forgery (CSRF) vulnerability in the Encrypted Contact Form plugin before 1.1 for WordPress allows remote attackers to hijack the au… | Patch early | 6.8 medium | 4.7% | 2015-06-09 |
| CVE-2010-2314 EXP | PHP remote file inclusion vulnerability in nucleus/plugins/NP_Twitter.php in the NP_Twitter Plugin 0.8 and 0.9 for Nucleus, when register_globals is e… | Patch early | 6.8 medium | 4.7% | 2010-06-17 |
| CVE-2002-1334 EXP | Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other use… | Patch early | 6.8 medium | 4.7% | 2002-12-11 |
| CVE-2000-0740 EXP | Buffer overflow in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary commands via a long… | Patch early | 5.0 medium | 4.7% | 2000-10-20 |
| CVE-2015-8723 EXP | The AirPDcapPacketProcess function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not… | Patch early | 5.5 medium | 4.7% | 2016-01-04 |
| CVE-2006-1593 EXP | The (1) ZD_MissingPlayer, (2) ZD_UseItem, and (3) ZD_LoadNewClientLevel functions in sv_main.cpp for (a) Zdaemon 1.08.01 and (b) X-Doom allows remote… | Patch early | 5.0 medium | 4.7% | 2006-04-03 |
| CVE-2021-24247 EXP | The Contact Form Check Tester WordPress plugin through 1.0.2 settings are visible to all registered users in the dashboard and are lacking any sanitis… | Patch early | 5.4 medium | 4.7% | 2021-05-06 |
| CVE-2013-2618 EXP | Cross-site scripting (XSS) vulnerability in editor.php in Network Weathermap before 0.97b allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 4.7% | 2014-06-05 |
| CVE-2012-2331 EXP | Cross-site scripting (XSS) vulnerability in serendipity/serendipity_admin_image_selector.php in Serendipity before 1.6.1 allows remote attackers to in… | Patch early | 4.3 medium | 4.7% | 2012-08-13 |
| CVE-2010-1458 EXP | Stack-based buffer overflow in Create and Extract Zips TweakFS Zip Utility 1.0 for Flight Simulator X (FSX) allows remote attackers to execute arbitra… | Patch early | 6.8 medium | 4.7% | 2010-04-20 |
| CVE-2011-0887 EXP | The web management portal on the SMC SMCD3G-CCR (aka Comcast Business Gateway) with firmware before 1.4.0.49.2 uses predictable session IDs based on t… | Patch early | 4.3 medium | 4.7% | 2011-02-08 |
| CVE-2014-1843 EXP | Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to obtain the property info… | Patch early | 5.0 medium | 4.7% | 2014-04-29 |
| CVE-2009-1030 EXP | Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allow… | Patch early | 4.3 medium | 4.7% | 2009-03-20 |
| CVE-2019-10846 EXP | Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via the usernam… | Patch early | 6.1 medium | 4.7% | 2019-05-23 |
| CVE-2011-0740 EXP | Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in RSS Feed Reader 0.1 for WordPress allows remote attackers to inject… | Patch early | 4.3 medium | 4.7% | 2011-02-02 |
| CVE-2005-2295 EXP | NetPanzer 0.8 and earlier allows remote attackers to cause a denial of service (infinite loop) via a packet with a zero datablock size. | Patch early | 5.0 medium | 4.7% | 2005-07-18 |
| CVE-2006-1046 EXP | server.cpp in Monopd 0.9.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a string containing a large number of… | Patch early | 5.0 medium | 4.7% | 2006-03-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt