CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,528 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2000-0673 EXP | The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoof… | Patch early | 5.0 medium | 33.4% | 2000-07-27 |
| CVE-2005-1980 EXP | Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transact… | Patch early | 5.0 medium | 33.3% | 2005-10-12 |
| CVE-2015-1376 EXP | pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write… | Patch early | 4.0 medium | 33.1% | 2015-01-28 |
| CVE-2007-3068 EXP | Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF playlist containing a long fi… | Patch early | 6.8 medium | 32.9% | 2007-06-06 |
| CVE-2015-3337 EXP | Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read… | Patch early | 4.3 medium | 32.9% | 2015-05-01 |
| CVE-2012-1007 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the… | Patch early | 4.3 medium | 32.9% | 2012-02-07 |
| CVE-2005-1979 EXP | Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "… | Patch early | 5.0 medium | 32.8% | 2005-10-12 |
| CVE-2008-0871 EXP | Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute arbitrary code via a (1) long pa… | Patch early | 6.8 medium | 32.8% | 2008-02-21 |
| CVE-2004-2434 EXP | Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace… | Patch early | 5.0 medium | 32.8% | 2004-12-31 |
| CVE-2005-1184 EXP | The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the correc… | Patch early | 5.0 medium | 32.7% | 2005-05-02 |
| CVE-2009-3830 EXP | The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP… | Patch early | 5.0 medium | 32.6% | 2009-10-30 |
| CVE-2015-5471 EXP | Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allows remote attackers to read ar… | Patch early | 5.3 medium | 32.5% | 2016-01-12 |
| CVE-2013-3827 EXP | Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2; the Oracle JDeveloper componen… | Patch early | 5.0 medium | 32.4% | 2013-10-16 |
| CVE-2008-3979 EXP | Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authenticated users to affect confide… | Patch early | 5.5 medium | 32.4% | 2009-01-14 |
| CVE-2012-1153 EXP | Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers to execute arbitrary… | Patch early | 6.8 medium | 32.4% | 2012-10-06 |
| CVE-2000-0495 EXP | Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "Malformed Windows Media Encoder… | Patch early | 5.0 medium | 32.3% | 2000-05-30 |
| CVE-2000-0567 EXP | Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email heade… | Patch early | 5.0 medium | 32.3% | 2000-07-18 |
| CVE-2013-4468 EXP | VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary commands via shell… | Patch early | 6.5 medium | 32.3% | 2014-05-14 |
| CVE-2013-2160 EXP | The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of se… | Patch early | 5.0 medium | 32.3% | 2013-08-19 |
| CVE-2006-0254 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) t… | Patch early | 4.3 medium | 32.2% | 2006-01-18 |
| CVE-2023-4548 EXP | A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3. The impacted element is an unknown function of the file /search of the component GET… | Patch early | 6.3 medium | 32.2% | 2023-08-26 |
| CVE-2001-0149 EXP | Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and… | Patch early | 5.0 medium | 32.2% | 2001-06-02 |
| CVE-2009-4498 EXP | The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request. | Patch early | 6.8 medium | 31.9% | 2009-12-31 |
| CVE-2007-5511 EXP | SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 allows attackers to exec… | Patch early | 6.5 medium | 31.8% | 2007-10-17 |
| CVE-2012-5613 EXP | MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who s… | Patch early | 6.0 medium | 31.7% | 2012-12-03 |
| CVE-2013-4467 EXP | Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier a… | Patch early | 6.5 medium | 31.6% | 2014-03-11 |
| CVE-2001-0663 EXP | Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol… | Patch early | 5.0 medium | 31.6% | 2001-12-06 |
| CVE-2006-1191 EXP | Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote… | Patch early | 4.0 medium | 31.6% | 2006-04-11 |
| CVE-2009-0880 EXP | Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and exec… | Patch early | 6.8 medium | 31.6% | 2009-03-12 |
| CVE-2007-3764 EXP | The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, A… | Patch early | 5.0 medium | 31.5% | 2007-07-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt