CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,696 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-4976 EXP | Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to in… | Patch early | 6.5 medium | 8.5% | 2007-09-19 |
| CVE-2010-3203 EXP | Directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot… | Patch early | 5.0 medium | 8.5% | 2010-09-03 |
| CVE-2014-0329 EXP | The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remote attacker… | Patch early | 9.3 high | 8.5% | 2014-02-04 |
| CVE-2012-2441 EXP | RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes i… | Patch early | 8.5 high | 8.5% | 2012-04-28 |
| CVE-2008-0151 EXP | Heap-based buffer overflow in Foxit WAC Server 2.1.0.910, 2.0 Build 3503, and earlier allows remote attackers to cause a denial of service (crash) and… | Patch early | 10.0 high | 8.5% | 2008-01-09 |
| CVE-2018-9302 EXP | SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TC… | Patch early | 9.1 critical | 8.5% | 2018-05-02 |
| CVE-2018-1038 EXP | The Windows kernel in Windows 7 SP1 and Windows Server 2008 R2 SP1 allows an elevation of privilege vulnerability due to the way it handles objects in… | Patch early | 7.8 high | 8.5% | 2018-04-02 |
| CVE-2017-9746 EXP | The disassemble_bytes function in objdump.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application… | Patch early | 7.8 high | 8.5% | 2017-06-19 |
| CVE-2017-9749 EXP | The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer overflow and application cras… | Patch early | 7.8 high | 8.5% | 2017-06-19 |
| CVE-2010-3313 EXP | phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly… | Patch early | 7.5 high | 8.5% | 2010-09-22 |
| CVE-2008-5715 EXP | Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long string… | Patch early | 5.0 medium | 8.5% | 2008-12-24 |
| CVE-2009-3710 EXP | RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel, which allows remote attacker… | Patch early | 10.0 high | 8.5% | 2009-10-16 |
| CVE-2008-4558 EXP | Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary code via an XSPF playlist file… | Patch early | 6.8 medium | 8.5% | 2008-10-15 |
| CVE-2006-0891 EXP | Multiple directory traversal vulnerabilities in NOCC Webmail 1.0 allow remote attackers to include arbitrary files via .. (dot dot) sequences and a tr… | Patch early | 5.0 medium | 8.5% | 2006-02-25 |
| CVE-2018-20658 EXP | The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD comman… | Patch early | 7.5 high | 8.5% | 2019-01-02 |
| CVE-2007-4533 EXP | Format string vulnerability in the Say command in sv_main.cpp in Vavoom 1.24 and earlier allows remote attackers to execute arbitrary code via format… | Patch early | 6.8 medium | 8.5% | 2007-08-25 |
| CVE-2007-1521 EXP | Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the… | Patch early | 6.8 medium | 8.5% | 2007-03-20 |
| CVE-2019-10848 EXP | Computrols CBAS 18.0.0 allows Username Enumeration. | Patch early | 5.3 medium | 8.5% | 2019-05-24 |
| CVE-2009-1789 EXP | mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted… | Patch early | 4.3 medium | 8.5% | 2009-05-26 |
| CVE-2000-1025 EXP | eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that contains the… | Patch early | 5.0 medium | 8.5% | 2000-12-11 |
| CVE-2005-4558 EXP | IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable valu… | Patch early | 6.5 medium | 8.5% | 2005-12-28 |
| CVE-2006-4437 EXP | Eval injection vulnerability in Tagger LE allows remote attackers to execute arbitrary PHP code via the query string in (1) tags.php, (2) sign.php, an… | Patch early | 7.5 high | 8.5% | 2006-09-14 |
| CVE-2018-7737 EXP | In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.php. NOTE: the software maintain… | Patch early | 5.3 medium | 8.5% | 2018-03-06 |
| CVE-2013-7392 EXP | Gitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/. | Patch early | 7.5 high | 8.5% | 2014-07-22 |
| CVE-2010-1302 EXP | Directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! allows remote attackers to read… | Patch early | 5.0 medium | 8.5% | 2010-04-07 |
| CVE-2007-3701 EXP | TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which might allow remote attackers to… | Patch early | 7.5 high | 8.5% | 2007-07-11 |
| CVE-2017-14704 EXP | Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remo… | Patch early | 8.8 high | 8.5% | 2017-09-26 |
| CVE-2013-3597 EXP | servlet/CollectionListServlet in SearchBlox before 7.5 build 1 allows remote attackers to read usernames and passwords via a getList action. | Patch early | 5.0 medium | 8.5% | 2013-08-28 |
| CVE-2006-0549 EXP | SQL injection vulnerability in the SYS.DBMS_METADATA_UTIL package in Oracle Database 10g, and possibly earlier versions, might allow remote attackers… | Patch early | 7.5 high | 8.5% | 2006-02-04 |
| CVE-2017-2471 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. watchOS before 3.2 is affected. The is… | Patch early | 8.8 high | 8.5% | 2017-04-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt