CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,488 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-20166 EXP | A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image, and mishand… | Patch early | 8.8 high | 7.1% | 2019-01-02 |
| CVE-2000-0470 EXP | Allegro RomPager HTTP server allows remote attackers to cause a denial of service via a malformed authentication request. | Patch early | 7.5 high | 7.1% | 2000-06-01 |
| CVE-2008-4645 EXP | plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PH… | Patch early | 9.0 high | 7.1% | 2008-10-22 |
| CVE-2005-1461 EXP | Multiple buffer overflows in the (1) SIP, (2) CMIP, (3) CMP, (4) CMS, (5) CRMF, (6) ESS, (7) OCSP, (8) X.509, (9) ISIS, (10) DISTCC, (11) FCELS, (12)… | Patch early | 7.5 high | 7.1% | 2005-05-05 |
| CVE-2010-4333 EXP | Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary val… | Patch early | 7.5 high | 7.1% | 2010-12-22 |
| CVE-2017-6351 EXP | The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password. Once the device is set to DE… | Patch early | 8.1 high | 7.1% | 2017-03-06 |
| CVE-2017-13258 EXP | In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosu… | Patch early | 7.5 high | 7.1% | 2018-04-04 |
| CVE-2017-16886 EXP | The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized… | Patch early | 8.8 high | 7.1% | 2018-01-12 |
| CVE-2007-0448 EXP | The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictio… | Patch early | 10.0 high | 7.1% | 2007-05-24 |
| CVE-2014-5092 EXP | Status2k allows Remote Command Execution in admin/options/editpl.php. | Patch early | 8.8 high | 7.1% | 2020-01-10 |
| CVE-2020-11804 EXP | An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection ca… | Patch early | 8.8 high | 7.1% | 2020-09-17 |
| CVE-2006-2998 EXP | PHP remote file inclusion vulnerability in board/post.php in free QBoard 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a U… | Patch early | 7.5 high | 7.1% | 2006-06-13 |
| CVE-2000-1022 EXP | The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows remote attacker… | Patch early | 7.5 high | 7.1% | 2000-12-11 |
| CVE-2001-0991 EXP | Cross-site scripting vulnerability in Proxomitron Naoko-4 BetaFour and earlier allows remote attackers to execute arbitrary script on other clients vi… | Patch early | 7.5 high | 7.1% | 2001-07-24 |
| CVE-2002-0118 EXP | Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.2.0 Beta Release 1.0 allows remote attackers to execute arbitrary script… | Patch early | 7.5 high | 7.1% | 2002-03-25 |
| CVE-2001-0319 EXP | orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the… | Patch early | 7.5 high | 7.1% | 2001-05-03 |
| CVE-2002-1008 EXP | Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web s… | Patch early | 7.5 high | 7.1% | 2002-10-04 |
| CVE-2009-1592 EXP | Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long banner. NOTE: this might… | Patch early | 10.0 high | 7.1% | 2009-05-08 |
| CVE-2006-1291 EXP | publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write access to the calendars directory,… | Patch early | 7.5 high | 7.1% | 2006-03-19 |
| CVE-2009-1645 EXP | Multiple stack-based buffer overflows in Mini-stream Easy RM-MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rts… | Patch early | 9.3 high | 7.1% | 2009-05-15 |
| CVE-2008-1276 EXP | Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allow remote au… | Patch early | 9.0 high | 7.1% | 2008-03-10 |
| CVE-2007-1648 EXP | 0irc 1345 build 20060823 allows remote attackers to cause a denial of service (application crash) by operating an IRC server that sends a long string… | Patch early | 7.8 high | 7.1% | 2007-03-24 |
| CVE-2007-2497 EXP | RealNetworks RealPlayer 10 Gold allows remote attackers to cause a denial of service (memory consumption) via a certain .ra file. NOTE: this issue wa… | Patch early | 7.8 high | 7.1% | 2007-05-04 |
| CVE-2009-1057 EXP | MicroSmarts Enterprise ZipItFast! 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file that triggers memory corruption, relat… | Patch early | 10.0 high | 7.1% | 2009-03-24 |
| CVE-2013-3314 EXP | The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2) firmware versions (ui and sys… | Patch early | 7.5 high | 7.1% | 2019-11-21 |
| CVE-2018-4087 EXP | An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. Th… | Patch early | 7.8 high | 7.1% | 2018-04-03 |
| CVE-2002-1238 EXP | Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request with a sequenc… | Patch early | 7.5 high | 7.1% | 2002-11-12 |
| CVE-2007-5256 EXP | Multiple stack-based buffer overflows in FSD 2.052 d9 and earlier, and FSFDT FSD 3.000 d9 and earlier, allow (1) remote attackers to execute arbitrary… | Patch early | 7.5 high | 7.1% | 2007-10-06 |
| CVE-2008-4926 EXP | Multiple insecure method vulnerabilities in MW6 Technologies PDF417 ActiveX control (MW6PDF417Lib.PDF417, MW6PDF417.dll) 3.0.0.1 allow remote attacker… | Patch early | 9.0 high | 7.1% | 2008-11-04 |
| CVE-2011-0403 EXP | Untrusted search path vulnerability in ImgBurn.exe in ImgBurn 2.4.0.0, 2.5.4.0, and other versions allows local users, and possibly remote attackers,… | Patch early | 9.3 high | 7.1% | 2011-01-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt