CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,503 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-7285 EXP | The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by… | Patch early | 6.5 medium | 50.3% | 2014-12-17 |
| CVE-2012-4915 EXP | Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .… | Patch early | 5.0 medium | 50% | 2014-05-29 |
| CVE-2015-2994 EXP | Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators to execute arbitrary code by up… | Patch early | 6.5 medium | 49.8% | 2015-06-08 |
| CVE-2007-2447 EXP | The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters invol… | Patch early | 6.0 medium | 49.8% | 2007-05-14 |
| CVE-2011-3486 EXP | Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to UDP port 48899, which triggers… | Patch early | 5.0 medium | 49.7% | 2011-09-16 |
| CVE-2004-1135 EXP | Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2)… | Patch early | 5.0 medium | 49.6% | 2005-01-10 |
| CVE-2018-16323 EXP | ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If t… | Patch early | 6.5 medium | 49.3% | 2018-09-01 |
| CVE-2015-6967 EXP | Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to execute arbitrary code by upl… | Patch early | 6.5 medium | 49.3% | 2015-09-16 |
| CVE-2011-3230 EXP | Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers to execute arbitrary code via… | Patch early | 6.8 medium | 49.3% | 2011-10-14 |
| CVE-2006-2685 EXP | PHP remote file inclusion vulnerability in Basic Analysis and Security Engine (BASE) 1.2.4 and earlier, with register_globals enabled, allows remote a… | Patch early | 4.0 medium | 49.2% | 2006-05-31 |
| CVE-2008-1311 EXP | The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.0 and earlier allows remote attackers to cause a denial of service (daemon hang) by upload… | Patch early | 5.0 medium | 49.2% | 2008-03-12 |
| CVE-2005-3388 EXP | Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrar… | Patch early | 4.3 medium | 48.9% | 2005-11-01 |
| CVE-2011-0514 EXP | The RDS service (rds.exe) in HP Data Protector Manager 6.11 allows remote attackers to cause a denial of service (crash) via a packet with a large dat… | Patch early | 5.0 medium | 48.9% | 2011-01-20 |
| CVE-2020-11798 EXP | A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker… | Patch early | 5.3 medium | 48.8% | 2020-06-10 |
| CVE-2006-1315 EXP | The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers… | Patch early | 5.0 medium | 48.8% | 2006-07-11 |
| CVE-2004-0841 EXP | Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop… | Patch early | 5.0 medium | 48.7% | 2004-12-23 |
| CVE-2007-0015 EXP | Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI. | Patch early | 6.8 medium | 48.7% | 2007-01-01 |
| CVE-2018-14392 EXP | The New Threads plugin before 1.2 for MyBB has XSS. | Patch early | 6.1 medium | 48.6% | 2018-07-19 |
| CVE-1999-0209 EXP | The SunView (SunTools) selection_svc facility allows remote users to read files. | Patch early | 5.0 medium | 48.5% | 1990-08-14 |
| CVE-2005-1990 EXP | Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a… | Patch early | 5.1 medium | 48.5% | 2005-08-10 |
| CVE-2019-0768 EXP | A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific con… | Patch early | 4.3 medium | 48.5% | 2019-04-09 |
| CVE-2002-0648 EXP | The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML fil… | Patch early | 5.0 medium | 48.4% | 2002-09-24 |
| CVE-2011-2657 EXP | Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll in AdminStudio in N… | Patch early | 6.8 medium | 48.4% | 2012-07-26 |
| CVE-2019-17503 EXP | An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka /osm_tiles/REGI… | Patch early | 5.3 medium | 48.3% | 2019-10-11 |
| CVE-2013-2143 EXP | The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows re… | Patch early | 6.5 medium | 48.2% | 2014-04-17 |
| CVE-2006-3281 EXP | Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop events, which allows remote user-assisted attackers to execute arbitrary code v… | Patch early | 5.1 medium | 48.2% | 2006-06-28 |
| CVE-2013-5576 EXP | administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authentica… | Patch early | 6.8 medium | 48.2% | 2013-10-09 |
| CVE-2001-0986 EXP | SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attribut… | Patch early | 5.0 medium | 48.2% | 2001-09-14 |
| CVE-2008-1547 EXP | Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows re… | Patch early | 4.3 medium | 48.1% | 2008-10-21 |
| CVE-2005-0688 EXP | Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP pac… | Patch early | 5.0 medium | 47.4% | 2005-03-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt