CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,488 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-9842 EXP | CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message. | Patch early | 5.3 medium | 15.9% | 2018-04-12 |
| CVE-2017-8869 EXP | Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file. | Patch early | 7.8 high | 15.9% | 2017-07-27 |
| CVE-2009-3898 EXP | Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows rem… | Patch early | 4.9 medium | 15.9% | 2009-11-24 |
| CVE-2024-30269 EXP | DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0.… | Patch early | 5.3 medium | 15.9% | 2024-04-08 |
| CVE-2005-1524 EXP | PHP file inclusion vulnerability in top_graph_header.php in Cacti 0.8.6d and possibly earlier versions allows remote attackers to execute arbitrary PH… | Patch early | 5.0 medium | 15.9% | 2005-06-22 |
| CVE-2020-8639 EXP | An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a fi… | Patch early | 8.8 high | 15.9% | 2020-04-03 |
| CVE-2006-0189 EXP | Buffer overflow in eStara Softphone 3.0.1.14 through 3.0.1.46 allows remote attackers to execute arbitrary code via a long attribute (aka "a") field i… | Patch early | 7.5 high | 15.9% | 2006-01-13 |
| CVE-2004-1439 EXP | Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1) USER, (2) PASS, (3) RETR,(4)… | Patch early | 7.5 high | 15.8% | 2004-12-31 |
| CVE-2019-0571 EXP | An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Ser… | Patch early | 7.8 high | 15.8% | 2019-01-08 |
| CVE-2018-11412 EXP | In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circ… | Patch early | 5.9 medium | 15.8% | 2018-05-24 |
| CVE-2011-0518 EXP | Directory traversal vulnerability in core/lib/router.php in LotusCMS Fraise 3.0, when magic_quotes_gpc is disabled, allows remote attackers to include… | Patch early | 5.1 medium | 15.8% | 2011-01-20 |
| CVE-2006-5768 EXP | Multiple PHP remote file inclusion vulnerabilities in Cyberfolio 2.0 RC1 and earlier, when register_globals is enabled, allow remote attackers to exec… | Patch early | 7.5 high | 15.8% | 2006-11-06 |
| CVE-2010-2128 EXP | Directory traversal vulnerability in the JE Quotation Form (com_jequoteform) component 1.0b1 for Joomla! allows remote attackers to read arbitrary fil… | Patch early | 7.5 high | 15.8% | 2010-06-01 |
| CVE-2007-3855 EXP | Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to have… | Patch early | 6.5 medium | 15.8% | 2007-07-18 |
| CVE-2018-1821 EXP | IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data… | Patch early | 7.1 high | 15.8% | 2018-12-13 |
| CVE-2010-2033 EXP | Directory traversal vulnerability in the Percha Multicategory Article (com_perchacategoriestree) component 0.6 for Joomla! allows remote attackers to… | Patch early | 7.5 high | 15.8% | 2010-05-25 |
| CVE-2020-10230 EXP | CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parame… | Patch early | 9.8 critical | 15.8% | 2020-03-16 |
| CVE-2012-5409 EXP | AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet netwo… | Patch early | 10.0 high | 15.8% | 2012-11-01 |
| CVE-2016-7866 EXP | Adobe Animate versions 15.2.1.95 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code… | Patch early | 9.8 critical | 15.8% | 2016-12-15 |
| CVE-2017-3549 EXP | Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Supported versions that are affec… | Patch early | 9.1 critical | 15.8% | 2017-04-24 |
| CVE-2010-2035 EXP | Directory traversal vulnerability in the Percha Gallery (com_perchagallery) component 1.6 Beta for Joomla! allows remote attackers to read arbitrary f… | Patch early | 7.5 high | 15.8% | 2010-05-25 |
| CVE-2025-4094 EXP | The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightfo… | Patch early | 9.8 critical | 15.8% | 2025-05-21 |
| CVE-2009-0543 EXP | ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte c… | Patch early | 6.8 medium | 15.8% | 2009-02-12 |
| CVE-2006-6310 EXP | Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash) via an invalid src attribute value ("?")… | Patch early | 5.0 medium | 15.8% | 2006-12-06 |
| CVE-2021-46379 EXP | DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site. | Patch early | 6.1 medium | 15.8% | 2022-03-04 |
| CVE-2004-0173 EXP | Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read… | Patch early | 5.0 medium | 15.8% | 2004-04-15 |
| CVE-2002-0862 EXP | The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products includi… | Patch early | 6.8 medium | 15.8% | 2002-10-04 |
| CVE-2015-3623 EXP | XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forgery (SSRF) a… | Patch early | 6.4 medium | 15.8% | 2015-09-16 |
| CVE-2012-6429 EXP | Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7 allows remote attackers to exe… | Patch early | 10.0 high | 15.8% | 2014-04-04 |
| CVE-2006-5048 EXP | Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier for Joomla! allow remote attack… | Patch early | 6.8 medium | 15.8% | 2006-09-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt