CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,999 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-9812 EXP | The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Ma… | Patch early | 7.5 high | 11.3% | 2017-07-17 |
| CVE-2017-16953 EXP | connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration o… | Patch early | 7.5 high | 11.3% | 2017-12-01 |
| CVE-2002-0613 EXP | dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user_logged_in or… | Patch early | 10.0 high | 11.3% | 2002-06-18 |
| CVE-2020-15261 EXP | On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally authenticated users with administr… | Patch early | 8.0 high | 11.3% | 2020-10-19 |
| CVE-2007-4005 EXP | Stack-based buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 allows remote attackers to execute arbitrary code via a long string to the sh… | Patch early | 5.0 medium | 11.2% | 2007-07-26 |
| CVE-2004-1789 EXP | Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 11.2% | 2004-12-31 |
| CVE-2021-24488 EXP | The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being out… | Patch early | 6.1 medium | 11.2% | 2021-08-02 |
| CVE-2019-6274 EXP | Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified impa… | Patch early | 8.8 high | 11.2% | 2019-03-21 |
| CVE-2025-2126 EXP | A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the fi… | Patch early | 6.3 medium | 11.2% | 2025-03-09 |
| CVE-2004-1584 EXP | CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HT… | Patch early | 5.0 medium | 11.2% | 2004-12-31 |
| CVE-2009-4880 EXP | Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attacker… | Patch early | 5.0 medium | 11.2% | 2010-06-01 |
| CVE-1999-1453 EXP | Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX o… | Patch early | 2.6 low | 11.2% | 1999-02-02 |
| CVE-2013-5660 EXP | Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file. | Patch early | 9.3 high | 11.2% | 2014-04-25 |
| CVE-2013-7246 EXP | Buffer overflow in the IconCreate method in an ActiveX control in the DaumGame ActiveX plugin 1.1.0.4 and 1.1.0.5 allows remote attackers to execute a… | Patch early | 9.3 high | 11.2% | 2014-01-30 |
| CVE-2001-1163 EXP | Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500. | Patch early | 10.0 high | 11.2% | 2001-06-16 |
| CVE-2014-4927 EXP | Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to c… | Patch early | 7.8 high | 11.2% | 2014-07-24 |
| CVE-2004-2652 EXP | The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attacke… | Patch early | 7.8 high | 11.2% | 2004-12-31 |
| CVE-2004-1260 EXP | Multiple buffer overflows in the (1) write_heading function in subs.cpp or (2) trim_title function in parse.cpp for abctab2ps 1.6.3 allow remote attac… | Patch early | 10.0 high | 11.2% | 2005-01-10 |
| CVE-2009-1608 EXP | Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrary code via… | Patch early | 9.3 high | 11.2% | 2009-05-11 |
| CVE-2016-9651 EXP | A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arb… | Patch early | 8.8 high | 11.2% | 2019-01-09 |
| CVE-2015-2196 EXP | SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id para… | Patch early | 7.5 high | 11.2% | 2015-03-03 |
| CVE-2012-1008 EXP | OfficeSIP Server 3.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted To header in a SIP INVITE message. | Patch early | 5.0 medium | 11.2% | 2012-02-08 |
| CVE-2004-1992 EXP | Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which trigge… | Patch early | 5.0 medium | 11.2% | 2004-04-20 |
| CVE-2007-4061 EXP | Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to create or overwrite ar… | Patch early | 9.3 high | 11.2% | 2007-07-30 |
| CVE-2012-3450 EXP | pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during pars… | Patch early | 2.6 low | 11.2% | 2012-08-06 |
| CVE-2008-1996 EXP | licq before 1.3.6 allows remote attackers to cause a denial of service (file-descriptor exhaustion and application crash) via a large number of connec… | Patch early | 5.0 medium | 11.2% | 2008-04-28 |
| CVE-2009-3111 EXP | The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Passwor… | Patch early | 5.0 medium | 11.2% | 2009-09-09 |
| CVE-2008-4096 EXP | libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server… | Patch early | 8.5 high | 11.2% | 2008-09-18 |
| CVE-2002-1549 EXP | Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request. | Patch early | 7.5 high | 11.2% | 2003-03-31 |
| CVE-2012-1593 EXP | epan/dissectors/packet-ansi_a.c in the ANSI A dissector in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a den… | Patch early | 3.3 low | 11.2% | 2012-04-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt