CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,553 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-1465 EXP | Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause a denial of service (applicat… | Patch early | 4.3 medium | 27.1% | 2012-03-19 |
| CVE-2013-3522 EXP | SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authenticated u… | Patch early | 6.5 medium | 27.1% | 2013-05-10 |
| CVE-2002-1567 EXP | Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with… | Patch early | 6.8 medium | 27.1% | 2003-10-06 |
| CVE-2017-18357 EXP | Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backen… | Patch early | 6.5 medium | 27.1% | 2019-01-15 |
| CVE-2018-14665 EXP | A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server all… | Patch early | 6.6 medium | 27% | 2018-10-25 |
| CVE-2013-6719 EXP | delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows re… | Patch early | 6.0 medium | 27% | 2014-03-06 |
| CVE-2006-5296 EXP | PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assi… | Patch early | 4.3 medium | 27% | 2006-10-16 |
| CVE-2010-4804 EXP | The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActi… | Patch early | 4.3 medium | 27% | 2011-06-09 |
| CVE-2003-1025 EXP | Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain po… | Patch early | 4.3 medium | 26.9% | 2004-01-20 |
| CVE-2000-0653 EXP | Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka… | Patch early | 5.0 medium | 26.9% | 2000-07-20 |
| CVE-2004-0558 EXP | The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a ce… | Patch early | 5.0 medium | 26.8% | 2004-09-28 |
| CVE-2009-0026 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 26.8% | 2009-01-21 |
| CVE-2015-2166 EXP | Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attacker… | Patch early | 5.0 medium | 26.8% | 2015-04-06 |
| CVE-2008-4029 EXP | Cross-domain vulnerability in Microsoft XML Core Services 3.0 and 4.0, as used in Internet Explorer, allows remote attackers to obtain sensitive infor… | Patch early | 4.3 medium | 26.7% | 2008-11-12 |
| CVE-2011-4535 EXP | Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC ModbusTagServer 4.1.1.81 and earli… | Patch early | 6.8 medium | 26.7% | 2012-04-03 |
| CVE-2017-8295 EXP | WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitr… | Patch early | 5.9 medium | 26.7% | 2017-05-04 |
| CVE-2011-4044 EXP | An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to modify fil… | Patch early | 5.8 medium | 26.7% | 2012-04-03 |
| CVE-2013-0108 EXP | An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R410.2; SymmetrE R310, R410.1,… | Patch early | 6.8 medium | 26.6% | 2013-02-24 |
| CVE-2008-1776 EXP | PHP remote file inclusion vulnerability in modules/basicfog/basicfogfactory.class.php in PhpBlock A8.4 allows remote attackers to execute arbitrary PH… | Patch early | 6.8 medium | 26.6% | 2008-04-14 |
| CVE-2008-1773 EXP | PHP remote file inclusion vulnerability in includes/header.inc.php in Dragoon 0.1 allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 6.8 medium | 26.6% | 2008-04-14 |
| CVE-2008-1682 EXP | PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1.0.2 component for Joomla! all… | Patch early | 6.8 medium | 26.6% | 2008-04-04 |
| CVE-2007-3763 EXP | The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appli… | Patch early | 5.0 medium | 26.6% | 2007-07-18 |
| CVE-2006-6311 EXP | Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service via a style attribute in an HTML table tag with a width… | Patch early | 5.0 medium | 26.5% | 2006-12-06 |
| CVE-2008-6938 EXP | Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to… | Patch early | 4.3 medium | 26.5% | 2009-08-11 |
| CVE-2010-4598 EXP | Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the… | Patch early | 5.0 medium | 26.5% | 2010-12-23 |
| CVE-2011-4518 EXP | Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to read arbitrary… | Patch early | 5.0 medium | 26.4% | 2013-05-23 |
| CVE-2021-24563 EXP | The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to up… | Patch early | 6.1 medium | 26.4% | 2021-10-11 |
| CVE-2006-3591 EXP | Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the URL property of a TriEditDocum… | Patch early | 5.0 medium | 26.2% | 2006-07-18 |
| CVE-2015-2998 EXP | SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensitive information, as demonstra… | Patch early | 5.0 medium | 26.2% | 2015-06-08 |
| CVE-2014-2314 EXP | Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via u… | Patch early | 4.3 medium | 26.2% | 2014-03-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt