CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,098 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-3249 EXP | Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot… | Patch early | 7.5 high | 9.6% | 2009-09-18 |
| CVE-2002-0229 EXP | Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and… | Patch early | 7.5 high | 9.6% | 2002-05-16 |
| CVE-2001-0476 EXP | Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a lo… | Patch early | 7.5 high | 9.6% | 2001-06-27 |
| CVE-2009-3099 EXP | Unspecified vulnerability in HP OpenView Operations Manager 8.1 on Windows Server 2003 SP2 allows remote attackers to have an unknown impact, related… | Patch early | 10.0 high | 9.6% | 2009-09-08 |
| CVE-2013-7282 EXP | The management web interface on the Nisuta NS-WIR150NE router with firmware 5.07.41 and Nisuta NS-WIR300N router with firmware 5.07.36_NIS01 allows re… | Patch early | 10.0 high | 9.6% | 2014-01-10 |
| CVE-2007-2935 EXP | core/spellcheck/spellcheck.php in Fundanemt before 2.2.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the dict… | Patch early | 7.5 high | 9.6% | 2007-05-31 |
| CVE-2002-2315 EXP | Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a denial of service (memory consumpt… | Patch early | 7.8 high | 9.6% | 2002-12-31 |
| CVE-2021-43339 EXP | In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functional… | Patch early | 8.8 high | 9.6% | 2021-11-03 |
| CVE-2002-0231 EXP | Buffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickname. | Patch early | 7.5 high | 9.6% | 2002-05-16 |
| CVE-2002-0177 EXP | Buffer overflows in icecast 1.3.11 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request from an MP3 client. | Patch early | 7.5 high | 9.5% | 2002-04-22 |
| CVE-2019-8820 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.… | Patch early | 8.8 high | 9.5% | 2019-12-18 |
| CVE-2017-17876 EXP | Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a user=download request with a pa… | Patch early | 7.5 high | 9.5% | 2017-12-27 |
| CVE-2020-14461 EXP | Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI. | Patch early | 8.6 high | 9.5% | 2020-06-22 |
| CVE-2006-4826 EXP | PHP remote file inclusion vulnerability in bottom.php in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 9.5% | 2006-09-15 |
| CVE-2006-3531 EXP | includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers t… | Patch early | 7.5 high | 9.5% | 2006-07-12 |
| CVE-2025-2594 EXP | The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enable… | Patch early | 8.1 high | 9.5% | 2025-04-22 |
| CVE-2016-2087 EXP | Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a .. (dot dot) in th… | Patch early | 7.4 high | 9.5% | 2017-01-18 |
| CVE-2009-0687 EXP | The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and Midnight… | Patch early | 7.8 high | 9.5% | 2009-08-11 |
| CVE-2013-5948 EXP | The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows rem… | Patch early | 8.5 high | 9.5% | 2014-04-22 |
| CVE-2007-1453 EXP | Buffer underflow in the PHP_FILTER_TRIM_DEFAULT macro in the filtering extension (ext/filter) in PHP 5.2.0 allows context-dependent attackers to execu… | Patch early | 7.5 high | 9.5% | 2007-03-14 |
| CVE-2007-2677 EXP | Multiple PHP remote file inclusion vulnerabilities in phpChess Community Edition 2.0 allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 9.5% | 2007-05-14 |
| CVE-2014-1982 EXP | The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmwar… | Patch early | 10.0 high | 9.5% | 2014-03-31 |
| CVE-2006-6740 EXP | Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 9.5% | 2006-12-26 |
| CVE-2017-7041 EXP | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… | Patch early | 8.8 high | 9.5% | 2017-07-20 |
| CVE-2009-0955 EXP | Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image desc… | Patch early | 9.3 high | 9.5% | 2009-06-02 |
| CVE-2017-15276 EXP | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticat… | Patch early | 8.8 high | 9.5% | 2017-10-13 |
| CVE-2002-2015 EXP | PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the ca… | Patch early | 7.5 high | 9.5% | 2002-12-31 |
| CVE-2018-18924 EXP | The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" because reje… | Patch early | 8.8 high | 9.5% | 2018-11-04 |
| CVE-2000-0639 EXP | The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbit… | Patch early | 7.5 high | 9.5% | 2000-06-11 |
| CVE-2005-1532 EXP | Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, whi… | Patch early | 7.5 high | 9.5% | 2005-05-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt