CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,415 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-2315 EXP | Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a denial of service (memory consumpt… | Patch early | 7.8 high | 9.6% | 2002-12-31 |
| CVE-2021-43339 EXP | In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functional… | Patch early | 8.8 high | 9.6% | 2021-11-03 |
| CVE-2002-0231 EXP | Buffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickname. | Patch early | 7.5 high | 9.6% | 2002-05-16 |
| CVE-2022-32272 EXP | OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access con… | Patch early | 9.8 critical | 9.6% | 2022-06-09 |
| CVE-2015-4071 EXP | The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticke… | Patch early | 5.3 medium | 9.6% | 2017-08-18 |
| CVE-2006-2863 EXP | PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 5.1 medium | 9.6% | 2006-06-06 |
| CVE-2002-0177 EXP | Buffer overflows in icecast 1.3.11 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request from an MP3 client. | Patch early | 7.5 high | 9.5% | 2002-04-22 |
| CVE-2010-1130 EXP | session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the sessio… | Patch early | 5.0 medium | 9.5% | 2010-03-26 |
| CVE-2007-6341 EXP | Net/DNS/RR/A.pm in Net::DNS 0.60 build 654, as used in packages such as SpamAssassin and OTRS, allows remote attackers to cause a denial of service (p… | Patch early | 5.0 medium | 9.5% | 2007-12-20 |
| CVE-2019-8820 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.… | Patch early | 8.8 high | 9.5% | 2019-12-18 |
| CVE-2017-17876 EXP | Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a user=download request with a pa… | Patch early | 7.5 high | 9.5% | 2017-12-27 |
| CVE-2020-14461 EXP | Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI. | Patch early | 8.6 high | 9.5% | 2020-06-22 |
| CVE-2006-4826 EXP | PHP remote file inclusion vulnerability in bottom.php in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 9.5% | 2006-09-15 |
| CVE-2008-1482 EXP | Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary… | Patch early | 6.8 medium | 9.5% | 2008-03-24 |
| CVE-2008-2795 EXP | Directory traversal vulnerability in the FTP and SFTP clients in IDM Computer Solutions Inc UltraEdit 14.00b allows remote FTP servers to create or ov… | Patch early | 4.3 medium | 9.5% | 2008-06-20 |
| CVE-2006-3531 EXP | includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers t… | Patch early | 7.5 high | 9.5% | 2006-07-12 |
| CVE-2025-2594 EXP | The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enable… | Patch early | 8.1 high | 9.5% | 2025-04-22 |
| CVE-2016-2087 EXP | Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a .. (dot dot) in th… | Patch early | 7.4 high | 9.5% | 2017-01-18 |
| CVE-2009-0687 EXP | The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and Midnight… | Patch early | 7.8 high | 9.5% | 2009-08-11 |
| CVE-2013-2576 EXP | Buffer overflow in Artweaver before 3.1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a craft… | Patch early | 6.8 medium | 9.5% | 2013-08-09 |
| CVE-2011-1470 EXP | The Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via a ziparchive stream that… | Patch early | 4.3 medium | 9.5% | 2011-03-20 |
| CVE-2007-1453 EXP | Buffer underflow in the PHP_FILTER_TRIM_DEFAULT macro in the filtering extension (ext/filter) in PHP 5.2.0 allows context-dependent attackers to execu… | Patch early | 7.5 high | 9.5% | 2007-03-14 |
| CVE-2007-2677 EXP | Multiple PHP remote file inclusion vulnerabilities in phpChess Community Edition 2.0 allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 9.5% | 2007-05-14 |
| CVE-2018-18793 EXP | School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos. | Patch early | 9.8 critical | 9.5% | 2018-11-16 |
| CVE-2006-6740 EXP | Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 9.5% | 2006-12-26 |
| CVE-2017-7041 EXP | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… | Patch early | 8.8 high | 9.5% | 2017-07-20 |
| CVE-2002-0484 EXP | move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to uninten… | Patch early | 5.0 medium | 9.5% | 2002-08-12 |
| CVE-2006-2134 EXP | PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to exe… | Patch early | 5.1 medium | 9.5% | 2006-05-02 |
| CVE-2009-0955 EXP | Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image desc… | Patch early | 9.3 high | 9.5% | 2009-06-02 |
| CVE-2017-15276 EXP | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticat… | Patch early | 8.8 high | 9.5% | 2017-10-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt