CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,660 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-1058 EXP | Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin… | Patch early | 10.0 high | 4.4% | 2002-10-04 |
| CVE-2007-2755 EXP | The PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll, when Internet Explorer 6 is used, allows remote attackers to overwrite arbitra… | Patch early | 10.0 high | 4.4% | 2007-05-17 |
| CVE-2025-44177 EXP | A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ endpoint. An u… | Patch early | 8.2 high | 4.4% | 2025-07-09 |
| CVE-2009-4549 EXP | Stack-based buffer overflow in A2 Media Player Pro 2.51 allows remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .m3l… | Patch early | 9.3 high | 4.4% | 2010-01-04 |
| CVE-2014-5200 EXP | SQL injection vulnerability in game_play.php in the FB Gorilla plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the… | Patch early | 7.5 high | 4.4% | 2014-08-12 |
| CVE-2007-5094 EXP | Heap-based buffer overflow in iaspam.dll in the SMTP Server in Ipswitch IMail Server 8.01 through 8.11 allows remote attackers to execute arbitrary co… | Patch early | 7.5 high | 4.4% | 2007-09-26 |
| CVE-2012-5347 EXP | TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunctions.inc… | Patch early | 7.5 high | 4.4% | 2012-10-09 |
| CVE-2018-1002000 EXP | There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exp… | Patch early | 7.2 high | 4.4% | 2018-12-03 |
| CVE-2019-0730 EXP | An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privil… | Patch early | 7.8 high | 4.4% | 2019-04-09 |
| CVE-2019-0731 EXP | An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privil… | Patch early | 7.8 high | 4.4% | 2019-04-09 |
| CVE-2017-6803 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 al… | Patch early | 8.8 high | 4.4% | 2017-03-20 |
| CVE-2001-0032 EXP | Format string vulnerability in ssldump possibly allows remote attackers to cause a denial of service and possibly gain root privileges via malicious f… | Patch early | 10.0 high | 4.3% | 2001-02-16 |
| CVE-2002-1034 EXP | none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via an absolute pathname in the argument. | Patch early | 10.0 high | 4.3% | 2002-10-04 |
| CVE-2006-6785 EXP | The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote att… | Patch early | 7.5 high | 4.3% | 2006-12-28 |
| CVE-2017-8665 EXP | The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin.iOS Elevation Of Privilege Vu… | Patch early | 7.8 high | 4.3% | 2017-08-15 |
| CVE-2007-2623 EXP | Multiple buffer overflows in RControl.dll in Remote Display Dev kit 1.2.1.0 allow remote attackers to cause a denial of service (Internet Explorer 7 c… | Patch early | 7.8 high | 4.3% | 2007-05-11 |
| CVE-2007-2658 EXP | Unspecified vulnerability in the ID Automation Linear Barcode 1.6.0.5 ActiveX control in IDAutomationLinear6.dll allows remote attackers to cause a de… | Patch early | 7.8 high | 4.3% | 2007-05-14 |
| CVE-2008-6822 EXP | Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader) 1.0 allows remote attackers… | Patch early | 7.5 high | 4.3% | 2009-06-04 |
| CVE-2024-25736 EXP | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET request. | Patch early | 7.5 high | 4.3% | 2024-03-27 |
| CVE-2017-8223 EXP | On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streaming without authentication via t… | Patch early | 7.5 high | 4.3% | 2017-04-25 |
| CVE-2008-6916 EXP | Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to bypass authentication via an invalid Host header, possibly involving a t… | Patch early | 10.0 high | 4.3% | 2009-08-07 |
| CVE-2013-5755 EXP | config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin (uoCbM.VEiKQto) for… | Patch early | 10.0 high | 4.3% | 2014-07-16 |
| CVE-2014-5380 EXP | Grand MA 300 allows retrieval of the access PIN from sniffed data. | Patch early | 7.5 high | 4.3% | 2020-01-13 |
| CVE-2006-6567 EXP | PHP remote file inclusion vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to ex… | Patch early | 10.0 high | 4.3% | 2006-12-15 |
| CVE-2020-5726 EXP | The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker c… | Patch early | 7.5 high | 4.3% | 2020-03-30 |
| CVE-2006-5206 EXP | SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.p… | Patch early | 7.5 high | 4.3% | 2006-10-10 |
| CVE-2006-4531 EXP | PHP remote file inclusion vulnerability in lib/config.php in Pheap CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 4.3% | 2006-09-01 |
| CVE-2017-14680 EXP | ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document. | Patch early | 7.5 high | 4.3% | 2017-09-21 |
| CVE-2018-16302 EXP | MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file. | Patch early | 7.8 high | 4.3% | 2018-09-01 |
| CVE-2014-1214 EXP | views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attackers to upload and execute arb… | Patch early | 8.8 high | 4.3% | 2019-11-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt