CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,590 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-0354 EXP | The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 has a blank p… | Patch early | 10.0 high | 14% | 2011-02-03 |
| CVE-2010-1659 EXP | Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote attackers to read arbitrar… | Patch early | 5.0 medium | 14% | 2010-05-03 |
| CVE-2007-0444 EXP | Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and MetaF… | Patch early | 7.2 high | 14% | 2007-01-24 |
| CVE-2015-2098 EXP | Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspecified vectors to the (1) Conn… | Patch early | 8.8 high | 14% | 2021-07-22 |
| CVE-2000-1112 EXP | Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that c… | Patch early | 4.6 medium | 14% | 2001-01-09 |
| CVE-2018-7702 EXP | SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e-mail messages to arbitrary re… | Patch early | 9.1 critical | 14% | 2018-03-15 |
| CVE-2007-4965 EXP | Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (applicati… | Patch early | 5.8 medium | 14% | 2007-09-18 |
| CVE-2016-3473 EXP | Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 al… | Patch early | 7.7 high | 13.9% | 2016-10-25 |
| CVE-2008-3734 EXP | Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP servers to cause a denial of servi… | Patch early | 9.3 high | 13.9% | 2008-08-20 |
| CVE-2019-11080 EXP | Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user w… | Patch early | 8.8 high | 13.9% | 2019-06-06 |
| CVE-2002-0799 EXP | Buffer overflow in YoungZSoft CMailServer 3.30 allows remote attackers to execute arbitrary code via a long USER argument. | Patch early | 7.5 high | 13.9% | 2002-08-12 |
| CVE-2021-24286 EXP | The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, l… | Patch early | 6.1 medium | 13.9% | 2021-05-14 |
| CVE-2010-2682 EXP | Directory traversal vulnerability in the Realtyna Translator (com_realtyna) component 1.0.15 for Joomla! allows remote attackers to read arbitrary fil… | Patch early | 7.5 high | 13.9% | 2010-07-12 |
| CVE-2013-3526 EXP | Cross-site scripting (XSS) vulnerability in js/ta_loaded.js.php in the Traffic Analyzer plugin, possibly 3.3.2 and earlier, for WordPress allows remot… | Patch early | 4.3 medium | 13.9% | 2013-05-10 |
| CVE-2017-10246 EXP | Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: iHelp). Supported versions that are affecte… | Patch early | 8.2 high | 13.9% | 2017-08-08 |
| CVE-2021-31933 EXP | A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and i… | Patch early | 7.2 high | 13.9% | 2021-04-30 |
| CVE-2008-1933 EXP | Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to overwrite arbitrary files via the… | Patch early | 4.3 medium | 13.9% | 2008-04-25 |
| CVE-2008-2666 EXP | Multiple directory traversal vulnerabilities in PHP 5.2.6 and earlier allow context-dependent attackers to bypass safe_mode restrictions by creating a… | Patch early | 5.0 medium | 13.9% | 2008-06-20 |
| CVE-2005-1275 EXP | Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of servic… | Patch early | 5.0 medium | 13.9% | 2005-04-25 |
| CVE-2013-4659 EXP | Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on route… | Patch early | 9.8 critical | 13.9% | 2017-03-14 |
| CVE-2010-2028 EXP | Buffer overflow in k23productions TFTPUtil GUI (aka TFTPGUI) 1.4.5 allows remote attackers to cause a denial of service (crash) and possibly execute a… | Patch early | 10.0 high | 13.9% | 2010-05-24 |
| CVE-2024-28999 EXP | The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console. | Patch early | 6.4 medium | 13.9% | 2024-06-04 |
| CVE-2005-1598 EXP | SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted co… | Patch early | 7.5 high | 13.9% | 2005-05-16 |
| CVE-2006-1985 EXP | Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to exe… | Patch early | 5.1 medium | 13.9% | 2006-04-21 |
| CVE-2019-1149 EXP | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who succes… | Patch early | 8.8 high | 13.9% | 2019-08-14 |
| CVE-2019-3810 EXP | A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did n… | Patch early | 6.1 medium | 13.9% | 2019-03-25 |
| CVE-2001-0129 EXP | Buffer overflow in Tinyproxy HTTP proxy 1.3.3 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands… | Patch early | 10.0 high | 13.9% | 2001-03-12 |
| CVE-2000-0260 EXP | Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the "Link Vi… | Patch early | 7.5 high | 13.9% | 2000-04-14 |
| CVE-2002-0187 EXP | Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root pa… | Patch early | 7.5 high | 13.9% | 2002-07-03 |
| CVE-2004-1364 EXP | Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bi… | Patch early | 8.5 high | 13.9% | 2004-08-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt