CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,200 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-7090 EXP | Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existence of arbitrary files via a .… | Patch early | 7.8 high | 8.3% | 2009-08-26 |
| CVE-2019-9600 EXP | The Olive Tree FTP Server (aka com.theolivetree.ftpserver) application through 1.32 for Android allows remote attackers to cause a denial of service v… | Patch early | 7.5 high | 8.3% | 2019-03-06 |
| CVE-2019-9601 EXP | The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many simultaneous /?Key=PhoneRequestA… | Patch early | 7.5 high | 8.3% | 2019-03-06 |
| CVE-2006-2995 EXP | Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 8.3% | 2006-06-13 |
| CVE-2006-4051 EXP | PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 8.3% | 2006-08-10 |
| CVE-2006-4440 EXP | PHP remote file inclusion vulnerability in main.php in Ay System Solutions CMS 2.6 and earlier allows remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 8.3% | 2006-08-29 |
| CVE-2010-2126 EXP | Multiple PHP remote file inclusion vulnerabilities in Snipe Gallery 3.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the cfg_ad… | Patch early | 7.5 high | 8.3% | 2010-06-01 |
| CVE-2007-0820 EXP | Multiple PHP remote file inclusion vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 8.3% | 2007-02-07 |
| CVE-2016-3861 EXP | LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles conversions… | Patch early | 7.8 high | 8.3% | 2016-09-11 |
| CVE-2019-8622 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watc… | Patch early | 8.8 high | 8.3% | 2019-12-18 |
| CVE-2019-8623 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watc… | Patch early | 8.8 high | 8.3% | 2019-12-18 |
| CVE-2006-5571 EXP | Stack-based buffer overflow in /scripts/cruise/cws.exe in CruiseWorks 1.09c and 1.09d allows remote attackers to execute arbitrary code via a long str… | Patch early | 7.5 high | 8.3% | 2006-10-27 |
| CVE-2013-3430 EXP | Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspec… | Patch early | 9.0 high | 8.3% | 2013-07-25 |
| CVE-2010-1180 EXP | Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… | Patch early | 9.3 high | 8.3% | 2010-03-29 |
| CVE-2007-0485 EXP | PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP code via a URL in the WEBCHATP… | Patch early | 7.5 high | 8.3% | 2007-01-25 |
| CVE-2017-2446 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 8.3% | 2017-04-02 |
| CVE-2006-5925 EXP | Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an… | Patch early | 7.5 high | 8.3% | 2006-11-15 |
| CVE-2007-1948 EXP | Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoff… | Patch early | 9.3 high | 8.3% | 2007-04-11 |
| CVE-2008-1277 EXP | The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause a denial of… | Patch early | 9.0 high | 8.3% | 2008-03-10 |
| CVE-2014-8835 EXP | The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes key has the xpc_data data type,… | Patch early | 9.3 high | 8.3% | 2015-01-30 |
| CVE-2008-6703 EXP | Stack-based buffer overflow in the IPureServer::_Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to… | Patch early | 10.0 high | 8.3% | 2009-04-10 |
| CVE-2008-7031 EXP | Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of service (crash)… | Patch early | 10.0 high | 8.3% | 2009-08-24 |
| CVE-2006-2834 EXP | PHP remote file inclusion vulnerability in includes/common.php in gnopaste 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 8.2% | 2006-06-06 |
| CVE-2010-3135 EXP | Untrusted search path vulnerability in Cisco Packet Tracer 5.2 allows local users, and possibly remote attackers, to execute arbitrary code and conduc… | Patch early | 9.3 high | 8.2% | 2010-08-26 |
| CVE-2016-9332 EXP | An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate input. An attacker could prov… | Patch early | 7.5 high | 8.2% | 2017-02-13 |
| CVE-2005-0316 EXP | WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which co… | Patch early | 7.5 high | 8.2% | 2005-01-28 |
| CVE-2009-4251 EXP | Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers to execute arbitrary code via… | Patch early | 9.3 high | 8.2% | 2009-12-10 |
| CVE-2007-4907 EXP | Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a URL in the xcart_dir parameter… | Patch early | 7.5 high | 8.2% | 2007-09-17 |
| CVE-2019-17080 EXP | mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickl… | Patch early | 7.8 high | 8.2% | 2019-10-02 |
| CVE-2007-2274 EXP | The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and application crash) via a malforme… | Patch early | 7.8 high | 8.2% | 2007-04-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt