CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,573 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2003-1091 EXP | Integer overflow in MP3Broadcaster for Apple QuickTime/Darwin Streaming Server 4.1.3 allows remote attackers to cause a denial of service (crash) and… | Patch early | 7.5 high | 6.4% | 2003-12-31 |
| CVE-2006-7052 EXP | Multiple PHP remote file inclusion vulnerabilities in DotWidget For Articles (dotwidgeta) 0.2 allow remote attackers to execute arbitrary code via a U… | Patch early | 10.0 high | 6.4% | 2007-02-24 |
| CVE-2017-15643 EXP | An active network attacker (MiTM) can achieve remote code execution on a machine that runs IKARUS Anti Virus 2.16.7. IKARUS AV for Windows uses cleart… | Patch early | 7.4 high | 6.4% | 2017-10-19 |
| CVE-2007-1851 EXP | Multiple directory traversal vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 allow remote attackers to include and execute arbitrary l… | Patch early | 7.5 high | 6.4% | 2007-04-03 |
| CVE-2023-36348 EXP | POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter. | Patch early | 8.8 high | 6.4% | 2023-06-23 |
| CVE-2011-5172 EXP | Stack-based buffer overflow in StoryBoard Quick 6 Build 3786, and possibly StoryBoard Artist and StoryBoard Studio, allows remote attackers to execute… | Patch early | 9.3 high | 6.4% | 2012-09-15 |
| CVE-2008-0632 EXP | Unrestricted file upload vulnerability in cp_upload_image.php in LightBlog 9.5 allows remote attackers to execute arbitrary code by uploading a file w… | Patch early | 9.3 high | 6.4% | 2008-02-06 |
| CVE-2008-2338 EXP | Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified scripts i… | Patch early | 7.5 high | 6.4% | 2008-05-19 |
| CVE-2008-6955 EXP | mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configurati… | Patch early | 7.5 high | 6.4% | 2009-08-12 |
| CVE-2008-5897 EXP | CodeAvalanche FreeWallpaper stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa… | Patch early | 7.5 high | 6.4% | 2009-01-12 |
| CVE-2008-5898 EXP | CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download th… | Patch early | 7.5 high | 6.4% | 2009-01-12 |
| CVE-2008-5899 EXP | CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download t… | Patch early | 7.5 high | 6.4% | 2009-01-12 |
| CVE-2008-5900 EXP | CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… | Patch early | 7.5 high | 6.4% | 2009-01-12 |
| CVE-2007-6668 EXP | admin/uploadgames.php in MySpace Content Zone (MCZ) 3.x does not require administrative privileges, which allows remote attackers to perform unrestric… | Patch early | 7.5 high | 6.4% | 2008-01-08 |
| CVE-2008-6752 EXP | adminlogin/password.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging does not verify the original password before changing passwords,… | Patch early | 7.5 high | 6.3% | 2009-04-24 |
| CVE-2010-5194 EXP | Stack-based buffer overflow in the Image2PDF function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageViewer2.ocx) in Viscom Image Viewer CP Pro… | Patch early | 9.3 high | 6.3% | 2012-08-31 |
| CVE-2015-8612 EXP | The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users to gain privileges via the dh… | Patch early | 8.4 high | 6.3% | 2016-01-08 |
| CVE-2008-7240 EXP | Directory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows remote attackers to include and e… | Patch early | 7.5 high | 6.3% | 2009-09-17 |
| CVE-2005-3010 EXP | Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers… | Patch early | 7.5 high | 6.3% | 2005-09-21 |
| CVE-2002-1910 EXP | Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtai… | Patch early | 7.5 high | 6.3% | 2002-12-31 |
| CVE-2008-6535 EXP | admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the administrative password via a direc… | Patch early | 7.5 high | 6.3% | 2009-03-26 |
| CVE-2007-3932 EXP | uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to… | Patch early | 7.5 high | 6.3% | 2007-07-21 |
| CVE-2007-1933 EXP | Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a… | Patch early | 7.5 high | 6.3% | 2007-04-10 |
| CVE-2004-1535 EXP | PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by m… | Patch early | 7.5 high | 6.3% | 2004-12-31 |
| CVE-2005-0513 EXP | PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions includi… | Patch early | 7.5 high | 6.3% | 2005-02-19 |
| CVE-2006-6690 EXP | rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote auth… | Patch early | 7.5 high | 6.3% | 2006-12-21 |
| CVE-2007-6041 EXP | Buffer overflow in the Sequencer::queueMessage function in sequencer.cpp in the server in Rigs of Rods (RoR) before 0.33d SP1 allows remote attackers… | Patch early | 7.5 high | 6.3% | 2007-11-20 |
| CVE-2007-2777 EXP | Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execut… | Patch early | 7.5 high | 6.3% | 2007-05-21 |
| CVE-2008-6761 EXP | Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject arbitrary PHP code into const.in… | Patch early | 10.0 high | 6.3% | 2009-04-28 |
| CVE-2012-4057 EXP | Buffer overflow in the Player in Remote-Anything 5.60.15 allows remote attackers to execute arbitrary code via a crafted flm file. | Patch early | 9.3 high | 6.3% | 2012-07-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt