CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,121 CVEs
1,733 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-0019 EXP | Multiple heap-based buffer overflows in rumpusd in Rumpus 5.1 and earlier (1) allow remote authenticated users to execute arbitrary code via a long LI… | Patch early | 6.5 medium | 3.8% | 2007-01-19 |
| CVE-2006-2899 EXP | Unspecified vulnerability in ESTsoft InternetDISK versions before 2006/04/20 allows remote authenticated users to execute arbitrary code, possibly by… | Patch early | 6.5 medium | 3.8% | 2006-06-07 |
| CVE-2008-5712 EXP | The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COLOR attribute in an H… | Patch early | 5.0 medium | 3.8% | 2008-12-24 |
| CVE-2020-18723 EXP | Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side wh… | Patch early | 5.4 medium | 3.8% | 2021-02-03 |
| CVE-2004-2021 EXP | Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the file… | Patch early | 5.0 medium | 3.8% | 2004-12-31 |
| CVE-2003-0495 EXP | Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote attackers to insert arbitrary web script via a news item. | Patch early | 4.3 medium | 3.8% | 2003-08-07 |
| CVE-2008-3365 EXP | Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows remote attackers to include and… | Patch early | 6.8 medium | 3.8% | 2008-07-30 |
| CVE-2017-11331 EXP | The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error)… | Patch early | 5.5 medium | 3.8% | 2017-07-31 |
| CVE-2000-0324 EXP | pcAnywhere 8.x and 9.0 allows remote attackers to cause a denial of service via a TCP SYN scan, e.g. by nmap. | Patch early | 5.0 medium | 3.8% | 2000-04-25 |
| CVE-2006-2121 EXP | PHP remote file include vulnerability in admin/config_settings.tpl.php in I-RATER Platinum allows remote attackers to execute arbitrary code via a URL… | Patch early | 5.0 medium | 3.8% | 2006-05-01 |
| CVE-2013-3304 EXP | Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in th… | Patch early | 5.0 medium | 3.8% | 2014-10-30 |
| CVE-2011-5257 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Classipress theme before 3.1.5 for WordPress allow remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 3.8% | 2013-02-12 |
| CVE-2006-2341 EXP | The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers to… | Patch early | 5.0 medium | 3.8% | 2006-05-12 |
| CVE-2014-5349 EXP | Stack-based buffer overflow in Baidu Spark Browser 26.5.9999.3511 allows remote attackers to cause a denial of service (application crash) via nested… | Patch early | 5.0 medium | 3.8% | 2014-08-19 |
| CVE-2006-2181 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Albinator 2.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 3.8% | 2006-05-04 |
| CVE-2006-4523 EXP | The web-based management interface in 2Wire, Inc. HomePortal and OfficePortal Series modems and routers allows remote attackers to cause a denial of s… | Patch early | 5.0 medium | 3.8% | 2006-09-01 |
| CVE-2008-1563 EXP | The "decode as" feature in packet-bssap.c in the SCCP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.8 allows remote attackers to caus… | Patch early | 4.3 medium | 3.8% | 2008-03-31 |
| CVE-2007-1564 EXP | The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan,… | Patch early | 6.8 medium | 3.8% | 2007-03-21 |
| CVE-2009-1203 EXP | WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 does not properly distinguish its own login scree… | Patch early | 6.0 medium | 3.8% | 2009-06-25 |
| CVE-2013-1466 EXP | Multiple cross-site scripting (XSS) vulnerabilities in glFusion before 1.2.2.pl4 allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 3.8% | 2014-02-05 |
| CVE-2000-1196 EXP | PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPag… | Patch early | 5.0 medium | 3.8% | 2001-08-31 |
| CVE-2023-4119 EXP | A vulnerability has been found in Academy LMS 6.0 and classified as problematic. This vulnerability affects unknown code of the file /academy/home/cou… | Patch early | 4.3 medium | 3.8% | 2023-08-03 |
| CVE-2010-3602 EXP | Cross-site scripting (XSS) vulnerability in ProfileView.aspx in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 3.8% | 2010-09-24 |
| CVE-2008-3101 EXP | Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the pare… | Patch early | 4.3 medium | 3.8% | 2008-09-03 |
| CVE-2022-36664 EXP | Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter. | Patch early | 6.1 medium | 3.8% | 2022-12-26 |
| CVE-2012-2156 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Plume CMS 1.2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (… | Patch early | 4.3 medium | 3.8% | 2012-04-11 |
| CVE-2012-1065 EXP | Insecure method vulnerability in TuxScripting.dll in the TuxSystem ActiveX control in 2X ApplicationServer 10.1 Build 1224 allows remote attackers to… | Patch early | 4.3 medium | 3.8% | 2012-02-14 |
| CVE-2018-5404 EXP | The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows an authenticated, remote attacker with least privileges ('User Console Only' role) t… | Patch early | 6.5 medium | 3.8% | 2019-06-03 |
| CVE-2004-1910 EXP | rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to the GetPrivateProfileString fu… | Patch early | 5.0 medium | 3.8% | 2004-12-31 |
| CVE-2008-3773 EXP | Cross-site scripting (XSS) vulnerability in vBulletin 3.7.2 PL1 and 3.6.10 PL3, when "Show New Private Message Notification Pop-Up" is enabled, allows… | Patch early | 4.3 medium | 3.8% | 2008-08-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt