CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,212 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-2372 EXP | admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentia… | Patch early | 10.0 high | 8.2% | 2007-04-30 |
| CVE-2017-11398 EXP | A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthe… | Patch early | 8.8 high | 8.2% | 2018-01-19 |
| CVE-2018-14336 EXP | TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets with random MAC addresses. | Patch early | 7.5 high | 8.2% | 2018-07-19 |
| CVE-2009-3625 EXP | Directory traversal vulnerability in www/index.php in Sahana 0.6.2.2 allows remote attackers to include and execute arbitrary local files via a .. (do… | Patch early | 7.5 high | 8.2% | 2009-10-26 |
| CVE-2012-4354 EXP | TCPIPS_Story.dll in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allows remote attackers to execute arbitrary c… | Patch early | 9.3 high | 8.2% | 2012-08-19 |
| CVE-2012-4355 EXP | TCPIPS_Story.dll in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 allows remote attackers to execute arbitrary c… | Patch early | 9.3 high | 8.2% | 2012-08-19 |
| CVE-2004-1118 EXP | Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.… | Patch early | 10.0 high | 8.2% | 2005-01-10 |
| CVE-2019-16645 EXP | An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostnam… | Patch early | 8.6 high | 8.2% | 2019-09-20 |
| CVE-2007-2608 EXP | PHP remote file inclusion vulnerability in lib/smarty/SmartyFU.class.php in Miplex2 Alpha 1 allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 8.2% | 2007-05-11 |
| CVE-2007-3432 EXP | Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jpg… | Patch early | 7.5 high | 8.2% | 2007-06-27 |
| CVE-2003-0339 EXP | Multiple heap-based buffer overflows in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allow remote attackers to execute arbitrary code via long HTTP reques… | Patch early | 7.5 high | 8.2% | 2003-05-22 |
| CVE-2008-6604 EXP | Directory traversal vulnerability in index.php in PicoFlat CMS 0.5.9 allows remote attackers to include and execute arbitrary local files via a .. (do… | Patch early | 10.0 high | 8.2% | 2009-04-04 |
| CVE-2006-3475 EXP | Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the qb_path pa… | Patch early | 7.5 high | 8.2% | 2006-07-10 |
| CVE-2007-2570 EXP | PHP remote file inclusion vulnerability in handlers/page/show.php in Wikivi5 allows remote attackers to execute arbitrary PHP code via a URL in the so… | Patch early | 7.5 high | 8.2% | 2007-05-09 |
| CVE-2008-4748 EXP | Format string vulnerability in the URI handler in KVirc 3.4.0, when set as the default application for processing IRC URIs, allows remote attackers to… | Patch early | 7.6 high | 8.2% | 2008-10-27 |
| CVE-2007-3621 EXP | Multiple CRLF injection vulnerabilities in callboth.php in AsteriDex 3.0 and earlier allow remote attackers to inject arbitrary shell commands via the… | Patch early | 7.5 high | 8.2% | 2007-07-09 |
| CVE-2017-5881 EXP | GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafte… | Patch early | 7.8 high | 8.2% | 2017-02-21 |
| CVE-2017-9614 EXP | The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and ap… | Patch early | 8.8 high | 8.2% | 2017-07-27 |
| CVE-2019-11369 EXP | An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensiti… | Patch early | 8.8 high | 8.1% | 2019-06-03 |
| CVE-2006-4849 EXP | PHP remote file inclusion vulnerability in header.php in MobilePublisherPHP 1.5 RC2 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 8.1% | 2006-09-19 |
| CVE-2003-0118 EXP | SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attacker… | Patch early | 7.5 high | 8.1% | 2003-05-12 |
| CVE-2007-3956 EXP | TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which allows remote attackers to cause… | Patch early | 7.8 high | 8.1% | 2007-07-24 |
| CVE-2006-4204 EXP | Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 8.1% | 2006-08-17 |
| CVE-2006-4477 EXP | Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute arbitrary PHP code via an empt… | Patch early | 7.5 high | 8.1% | 2006-08-31 |
| CVE-2013-4984 EXP | The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain… | Patch early | 7.2 high | 8.1% | 2013-09-10 |
| CVE-2007-1043 EXP | Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config… | Patch early | 7.5 high | 8.1% | 2007-02-21 |
| CVE-2006-6853 EXP | Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary code via a long string in a cra… | Patch early | 10.0 high | 8.1% | 2006-12-31 |
| CVE-2018-4241 EXP | An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchO… | Patch early | 7.8 high | 8.1% | 2018-06-08 |
| CVE-1999-1533 EXP | Eicon Technology Diva LAN ISDN modem allows a remote attacker to cause a denial of service (hang) via a long password argument to the login.htm file i… | Patch early | 7.5 high | 8.1% | 1999-11-07 |
| CVE-2014-7288 EXP | Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell c… | Patch early | 9.0 high | 8.1% | 2015-02-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt