CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,295 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2000-0689 EXP | Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges fo… | Patch early | 7.5 high | 7.8% | 2000-10-20 |
| CVE-2008-3360 EXP | Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code via a long URL in the HREF att… | Patch early | 9.3 high | 7.8% | 2008-07-29 |
| CVE-2012-3549 EXP | The SCTP implementation in FreeBSD 8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted… | Patch early | 7.8 high | 7.8% | 2012-10-09 |
| CVE-2019-11446 EXP | An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files se… | Patch early | 8.8 high | 7.8% | 2019-04-22 |
| CVE-2021-27825 EXP | A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL. | Patch early | 7.5 high | 7.8% | 2023-05-29 |
| CVE-2013-3956 EXP | The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2 on Windows Vista and Windows… | Patch early | 7.2 high | 7.8% | 2013-07-31 |
| CVE-2006-5196 EXP | The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with… | Patch early | 7.8 high | 7.8% | 2006-10-10 |
| CVE-2012-6470 EXP | Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a denial of serv… | Patch early | 9.3 high | 7.8% | 2013-01-02 |
| CVE-2007-1568 EXP | Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via a yEnc (yEncode) encoded arti… | Patch early | 10.0 high | 7.8% | 2007-03-21 |
| CVE-2018-19277 EXP | securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file | Patch early | 8.8 high | 7.8% | 2018-11-14 |
| CVE-2017-2468 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 7.8% | 2017-04-02 |
| CVE-2019-15104 EXP | An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via… | Patch early | 8.8 high | 7.8% | 2019-08-16 |
| CVE-2019-15105 EXP | An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration… | Patch early | 8.8 high | 7.8% | 2019-08-16 |
| CVE-2017-17538 EXP | MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets. | Patch early | 7.5 high | 7.8% | 2017-12-13 |
| CVE-2007-6179 EXP | Multiple PHP remote file inclusion vulnerabilities in Charray's CMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the ccms_l… | Patch early | 7.5 high | 7.8% | 2007-11-30 |
| CVE-2007-2594 EXP | PHP remote file inclusion vulnerability in inc/articles.inc.php in phpMyPortal 3.0.0 RC3 allows remote attackers to execute arbitrary PHP code via a U… | Patch early | 7.5 high | 7.8% | 2007-05-11 |
| CVE-2002-0335 EXP | Buffer overflow in Galacticomm Worldgroup web server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbit… | Patch early | 10.0 high | 7.8% | 2002-06-25 |
| CVE-2017-15012 EXP | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILE RPC-comma… | Patch early | 8.8 high | 7.8% | 2017-10-13 |
| CVE-2007-4596 EXP | The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eval… | Patch early | 7.5 high | 7.8% | 2007-08-30 |
| CVE-2003-0595 EXP | Buffer overflow in WiTango Application Server and Tango 2000 allows remote attackers to execute arbitrary code via a long cookie to Witango_UserRefere… | Patch early | 7.5 high | 7.8% | 2003-08-27 |
| CVE-2003-0762 EXP | Buffer overflow in (1) foxweb.dll and (2) foxweb.exe of Foxweb 2.5 allows remote attackers to execute arbitrary code via a long URL (PATH_INFO value). | Patch early | 7.5 high | 7.8% | 2003-09-17 |
| CVE-2009-4117 EXP | Multiple stack-based buffer overflows in pdf_shade4.c in MuPDF before commit 20091125231942, as used in SumatraPDF before 1.0.1, allow remote attacker… | Patch early | 9.3 high | 7.8% | 2009-12-01 |
| CVE-2005-0575 EXP | Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via… | Patch early | 7.5 high | 7.8% | 2005-05-02 |
| CVE-2008-3319 EXP | admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary… | Patch early | 7.5 high | 7.8% | 2008-07-25 |
| CVE-2008-3321 EXP | admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitr… | Patch early | 7.5 high | 7.8% | 2008-07-25 |
| CVE-2016-5840 EXP | hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitr… | Patch early | 7.2 high | 7.8% | 2016-06-30 |
| CVE-2005-4468 EXP | PHP remote file include vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to execute arbitrary code via a UR… | Patch early | 7.5 high | 7.8% | 2005-12-22 |
| CVE-2007-6548 EXP | Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary PHP code vi… | Patch early | 7.5 high | 7.8% | 2007-12-28 |
| CVE-2018-12519 EXP | An issue was discovered in ShopNx through 2017-11-17. The vulnerability allows a remote attacker to upload any malicious file to a Node.js application… | Patch early | 8.8 high | 7.8% | 2018-06-19 |
| CVE-2007-1596 EXP | Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote atta… | Patch early | 9.3 high | 7.8% | 2007-03-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt