CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,286 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-0278 EXP | Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file… | Patch early | 9.3 high | 10.1% | 2012-04-18 |
| CVE-2011-3981 EXP | PHP remote file inclusion vulnerability in actions.php in the Allwebmenus plugin 1.1.3 for WordPress allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 10.1% | 2011-10-04 |
| CVE-2014-10011 EXP | Stack-based buffer overflow in UltraCamLib in the UltraCam ActiveX Control (UltraCamX.ocx) for the TRENDnet SecurView camera TV-IP422WN allows remote… | Patch early | 7.5 high | 10.1% | 2015-01-13 |
| CVE-2000-0272 EXP | RealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at port 7070. | Patch early | 7.8 high | 10.1% | 2000-04-20 |
| CVE-2009-0103 EXP | Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) apps_pat… | Patch early | 7.5 high | 10.1% | 2009-01-09 |
| CVE-2017-11435 EXP | The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management consol… | Patch early | 9.8 critical | 10.1% | 2017-07-19 |
| CVE-2011-2522 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attacke… | Patch early | 6.8 medium | 10% | 2011-07-29 |
| CVE-2010-0682 EXP | WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter. | Patch early | 4.0 medium | 10% | 2010-02-23 |
| CVE-1999-0192 EXP | Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable. | Patch early | 10.0 high | 10% | 1997-10-18 |
| CVE-2005-2772 EXP | Multiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to execute arbitrary code via (1)… | Patch early | 7.5 high | 10% | 2005-09-02 |
| CVE-2005-0989 EXP | The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attacker… | Patch early | 5.0 medium | 10% | 2005-05-02 |
| CVE-2005-0439 EXP | Buffer overflow in the decode_post function in ELOG before 2.5.7 allows remote attackers to execute arbitrary code via attachments with long file name… | Patch early | 7.5 high | 10% | 2005-05-02 |
| CVE-2000-0443 EXP | The web interface server in HP Web JetAdmin 5.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 7.5 high | 10% | 2000-05-24 |
| CVE-2014-2223 EXP | Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to execute arbit… | Patch early | 7.5 high | 10% | 2014-09-11 |
| CVE-2004-1892 EXP | Stack-based buffer overflow in DecodeBase16 function, as used in the (1) IRC module and (2) web server in eMule 0.42d, allows remote attackers to exec… | Patch early | 7.5 high | 10% | 2004-12-31 |
| CVE-2008-7126 EXP | Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of service (cra… | Patch early | 10.0 high | 10% | 2009-08-31 |
| CVE-2014-5470 EXP | Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to… | Patch early | 9.8 critical | 10% | 2024-06-21 |
| CVE-2018-6223 EXP | A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate th… | Patch early | 9.8 critical | 10% | 2018-03-15 |
| CVE-2018-20782 EXP | The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages. | Patch early | 7.5 high | 10% | 2019-02-17 |
| CVE-2018-20523 EXP | Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a t… | Patch early | 5.3 medium | 10% | 2019-06-07 |
| CVE-2013-2474 EXP | Directory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' parameter. | Patch early | 7.5 high | 10% | 2020-01-27 |
| CVE-2008-2511 EXP | Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEventCli.dll in CA Internet Secu… | Patch early | 9.3 high | 10% | 2008-06-02 |
| CVE-2006-2460 EXP | Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESS… | Patch early | 6.4 medium | 10% | 2006-05-19 |
| CVE-2018-19042 EXP | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters o… | Patch early | 5.3 medium | 10% | 2019-01-31 |
| CVE-2018-19043 EXP | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename) via a ../ directory traversal… | Patch early | 5.3 medium | 10% | 2019-01-31 |
| CVE-2000-0213 EXP | The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacha… | Patch early | 5.0 medium | 10% | 2000-02-23 |
| CVE-2018-10618 EXP | Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracked, allowing a remote attacker… | Patch early | 9.8 critical | 10% | 2018-08-01 |
| CVE-2009-4427 EXP | Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbitrary local files via a .. (do… | Patch early | 7.5 high | 10% | 2009-12-28 |
| CVE-2021-34370 EXP | Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags an… | Patch early | 6.1 medium | 10% | 2021-06-09 |
| CVE-2006-1777 EXP | Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execute arbitra… | Patch early | 7.5 high | 10% | 2006-04-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt