CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,899 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2000-0684 EXP | BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by dir… | Patch early | 10.0 high | 12.3% | 2000-10-20 |
| CVE-2000-0685 EXP | BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML c… | Patch early | 10.0 high | 12.3% | 2000-10-20 |
| CVE-2001-0171 EXP | Buffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long GET r… | Patch early | 10.0 high | 12.3% | 2001-05-03 |
| CVE-2007-1301 EXP | Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authenticated users… | Patch early | 9.0 high | 12.3% | 2007-03-07 |
| CVE-2004-1299 EXP | Buffer overflow in the get_attr function in html.c for vilistextum 2.6.6 allows remote attackers to execute arbitrary code via a crafted web page. | Patch early | 10.0 high | 12.3% | 2005-01-10 |
| CVE-2017-7185 EXP | Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and… | Patch early | 7.5 high | 12.3% | 2017-04-10 |
| CVE-2004-0465 EXP | Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows remote attackers to read keys wit… | Patch early | 5.0 medium | 12.3% | 2004-12-31 |
| CVE-2006-0097 EXP | Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execu… | Patch early | 7.5 high | 12.2% | 2006-01-06 |
| CVE-2019-17554 EXP | The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Reque… | Patch early | 5.5 medium | 12.2% | 2019-12-04 |
| CVE-2018-15705 EXP | WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a… | Patch early | 6.5 medium | 12.2% | 2018-10-31 |
| CVE-2010-3678 EXP | Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (crash) via (1) IN or (2) CASE operations with NULL argu… | Patch early | 4.0 medium | 12.2% | 2011-01-11 |
| CVE-2010-3679 EXP | Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via certain arguments to the BINLO… | Patch early | 4.0 medium | 12.2% | 2011-01-11 |
| CVE-2010-3680 EXP | Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by creating temporary tables with… | Patch early | 4.0 medium | 12.2% | 2011-01-11 |
| CVE-2010-3681 EXP | Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using the… | Patch early | 4.0 medium | 12.2% | 2011-01-11 |
| CVE-2010-3683 EXP | Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 sends an OK packet when a LOAD DATA INFILE request generates SQL errors, which allows remote authe… | Patch early | 4.0 medium | 12.2% | 2011-01-11 |
| CVE-2009-2983 EXP | Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allow attackers to cause a denial of service (memory corrupt… | Patch early | 9.3 high | 12.2% | 2009-10-19 |
| CVE-2020-15500 EXP | An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response… | Patch early | 6.1 medium | 12.2% | 2020-07-01 |
| CVE-2009-1886 EXP | Multiple format string vulnerabilities in client/client.c in smbclient in Samba 3.2.0 through 3.2.12 might allow context-dependent attackers to execut… | Patch early | 9.3 high | 12.2% | 2009-06-25 |
| CVE-2016-10718 EXP | Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial of service. | Patch early | 7.5 high | 12.2% | 2018-04-04 |
| CVE-2010-3155 EXP | Untrusted search path vulnerability in Adobe ExtendScript Toolkit (ESTK) CS5 3.5.0.52 allows local users, and possibly remote attackers, to execute ar… | Patch early | 9.3 high | 12.2% | 2010-08-27 |
| CVE-2018-5406 EXP | The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-Origin Resource Sharing (CORS)… | Patch early | 8.8 high | 12.2% | 2019-06-03 |
| CVE-2009-1970 EXP | Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to… | Patch early | 5.0 medium | 12.2% | 2009-07-14 |
| CVE-2003-0801 EXP | Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal… | Patch early | 4.3 medium | 12.2% | 2003-10-06 |
| CVE-2017-9024 EXP | Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Traversal issue in its TFTP Serve… | Patch early | 7.5 high | 12.2% | 2017-05-21 |
| CVE-2017-11153 EXP | Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain ad… | Patch early | 9.8 critical | 12.2% | 2017-08-08 |
| CVE-2007-0908 EXP | The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a nu… | Patch early | 5.0 medium | 12.2% | 2007-02-13 |
| CVE-2008-1842 EXP | Integer signedness error in ovspmd.exe in HP OpenView Network Node Manager (OV NNM) 8.01, and 7.53 and earlier, allows remote attackers to cause a den… | Patch early | 10.0 high | 12.2% | 2008-04-16 |
| CVE-2005-2777 EXP | Looking Glass 20040427 allows remote attackers to execute arbitrary commands via shell metacharacters in the DNS lookup query field. | Patch early | 7.5 high | 12.2% | 2005-09-02 |
| CVE-2007-3289 EXP | PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 12.2% | 2007-06-20 |
| CVE-2022-24082 EXP | If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not… | Patch early | 9.8 critical | 12.2% | 2022-07-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt