CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,133 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-0389 EXP | Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attackers to (1) create and overwri… | Patch early | 9.3 high | 8.8% | 2009-02-02 |
| CVE-2019-12323 EXP | The HC.Server service in Hosting Controller HC10 10.14 allows an Invalid Pointer Write DoS. | Patch early | 7.5 high | 8.8% | 2019-06-24 |
| CVE-2006-1213 EXP | JiRo's Banner System Experience and Professional 1.0 and earlier allows remote attackers to bypass access restrictions and gain privileges via a direc… | Patch early | 7.5 high | 8.8% | 2006-03-14 |
| CVE-2021-31762 EXP | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse s… | Patch early | 8.8 high | 8.8% | 2021-04-25 |
| CVE-2008-1331 EXP | cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other versions, allo… | Patch early | 10.0 high | 8.8% | 2008-04-02 |
| CVE-2007-2946 EXP | Buffer overflow in a certain ActiveX control in LeadTools Raster Dialog File_D Object (LTRDFD14e.DLL) 14.5.0.44 allows remote attackers to cause a den… | Patch early | 10.0 high | 8.8% | 2007-05-31 |
| CVE-2007-1837 EXP | Multiple PHP remote file inclusion vulnerabilities in MangoBery CMS 0.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the Site_P… | Patch early | 7.5 high | 8.8% | 2007-04-03 |
| CVE-2004-0073 EXP | PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 8.8% | 2004-02-17 |
| CVE-2007-2983 EXP | Multiple buffer overflows in the British Telecommunications Consumer webhelper ActiveX control before 2.0.0.8 in btwebcontrol.dll allow remote attacke… | Patch early | 9.3 high | 8.8% | 2007-10-25 |
| CVE-2015-8258 EXP | AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script E… | Patch early | 7.5 high | 8.8% | 2017-04-10 |
| CVE-2006-2665 EXP | PHP remote file inclusion vulnerability in includes/mailaccess/pop3/core.php in V-Webmail 1.3 allows remote attackers to execute arbitrary PHP code vi… | Patch early | 7.5 high | 8.8% | 2006-05-30 |
| CVE-2018-18759 EXP | Modbus Slave 7.0.0 in modbus tools has a Buffer Overflow. | Patch early | 7.5 high | 8.8% | 2018-11-16 |
| CVE-2003-1260 EXP | Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command. | Patch early | 7.6 high | 8.7% | 2003-12-31 |
| CVE-2007-1998 EXP | Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP code via the Email field, whic… | Patch early | 7.5 high | 8.7% | 2007-04-12 |
| CVE-2009-0885 EXP | Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a denial of service (application… | Patch early | 9.3 high | 8.7% | 2009-03-12 |
| CVE-2007-0886 EXP | Heap-based buffer underflow in axigen 1.2.6 through 2.0.0b1 allows remote attackers to cause a denial of service (application crash) and possibly exec… | Patch early | 10.0 high | 8.7% | 2007-02-12 |
| CVE-2008-2684 EXP | The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via long s… | Patch early | 9.3 high | 8.7% | 2008-06-12 |
| CVE-2005-3523 EXP | Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (direction) field. | Patch early | 7.5 high | 8.7% | 2005-11-07 |
| CVE-2002-0316 EXP | Cross-site scripting vulnerability in eXtreme message board (XMB) 1.6x and earlier allows remote attackers to execute script as other XMB users by ins… | Patch early | 7.5 high | 8.7% | 2002-06-25 |
| CVE-2009-1963 EXP | Unspecified vulnerability in the Network Foundation component in Oracle Database 11.1.0.6 allows remote authenticated users to affect integrity and av… | Patch early | 7.5 high | 8.7% | 2009-07-14 |
| CVE-2018-11505 EXP | The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output. | Patch early | 7.5 high | 8.7% | 2018-05-26 |
| CVE-2013-2680 EXP | Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive information. | Patch early | 7.5 high | 8.7% | 2020-02-05 |
| CVE-2001-1199 EXP | Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to execute Javascript… | Patch early | 7.5 high | 8.7% | 2001-12-17 |
| CVE-2019-15943 EXP | vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by creating a… | Patch early | 8.8 high | 8.7% | 2019-09-19 |
| CVE-2013-5745 EXP | The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, d… | Patch early | 7.1 high | 8.7% | 2013-10-01 |
| CVE-1999-0176 EXP | The Webgais program allows a remote user to execute arbitrary commands. | Patch early | 7.5 high | 8.7% | 1997-07-10 |
| CVE-1999-0207 EXP | Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command. | Patch early | 7.5 high | 8.7% | 1994-06-09 |
| CVE-2005-2885 EXP | The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which… | Patch early | 7.5 high | 8.7% | 2005-09-14 |
| CVE-1999-0147 EXP | The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands. | Patch early | 7.5 high | 8.7% | 1997-07-01 |
| CVE-2003-0470 EXP | Buffer overflow in the "RuFSI Utility Class" ActiveX control (aka "RuFSI Registry Information Class"), as used for the Symantec Security Check service… | Patch early | 7.5 high | 8.7% | 2003-08-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt