CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,707 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2003-0795 EXP | The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker… | Patch early | 5.0 medium | 8.4% | 2003-12-15 |
| CVE-2000-0538 EXP | ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a long login password. | Patch early | 5.0 medium | 8.4% | 2000-06-07 |
| CVE-2006-4029 EXP | Stack-based buffer overflow in sipd.dll in AGEphone 1.24 and 1.38.1 allows remote attackers to execute arbitrary code via a crafted UDP SIP packet. | Patch early | 7.5 high | 8.4% | 2006-08-09 |
| CVE-2010-4056 EXP | solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing a… | Patch early | 5.0 medium | 8.4% | 2010-10-23 |
| CVE-2007-2271 EXP | Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbitrary files via a .. (dot dot)… | Patch early | 9.4 high | 8.4% | 2007-04-25 |
| CVE-2017-11664 EXP | The _WM_SetupMidiEvent function in internal_midi.c:2122 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) vi… | Patch early | 6.5 medium | 8.4% | 2017-08-17 |
| CVE-2007-6332 EXP | The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBC… | Patch early | 9.3 high | 8.4% | 2007-12-13 |
| CVE-2000-0198 EXP | Buffer overflow in POP3 and IMAP servers in the MERCUR mail server suite allows remote attackers to cause a denial of service. | Patch early | 5.0 medium | 8.4% | 2000-03-15 |
| CVE-2009-3890 EXP | Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain config… | Patch early | 6.0 medium | 8.4% | 2009-11-17 |
| CVE-2007-3407 EXP | Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) via a URL with a trailing encode… | Patch early | 5.0 medium | 8.4% | 2007-06-26 |
| CVE-2007-2369 EXP | Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to read arbit… | Patch early | 5.0 medium | 8.4% | 2007-04-30 |
| CVE-2000-0109 EXP | The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily g… | Patch early | 10.0 high | 8.4% | 2000-01-31 |
| CVE-2023-4112 EXP | A vulnerability was found in PHP Jabbers Shuttle Booking Software 1.0. It has been classified as problematic. This affects an unknown part of the file… | Patch early | 4.3 medium | 8.4% | 2023-08-03 |
| CVE-2023-4113 EXP | A vulnerability was found in PHP Jabbers Service Booking Script 1.0. It has been declared as problematic. This vulnerability affects unknown code of t… | Patch early | 4.3 medium | 8.4% | 2023-08-03 |
| CVE-2023-4115 EXP | A vulnerability classified as problematic has been found in PHP Jabbers Cleaning Business 1.0. Affected is an unknown function of the file /index.php.… | Patch early | 4.3 medium | 8.4% | 2023-08-03 |
| CVE-2023-4116 EXP | A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0. Affected by this vulnerability is an unknown functionality of the… | Patch early | 4.3 medium | 8.4% | 2023-08-03 |
| CVE-2007-3934 EXP | PHP remote file inclusion vulnerability in postscript/postscript.php in BBS E-Market allows remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 8.4% | 2007-07-21 |
| CVE-2011-1249 EXP | The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server… | Patch early | 7.2 high | 8.4% | 2011-06-16 |
| CVE-2009-1236 EXP | Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers… | Patch early | 10.0 high | 8.4% | 2009-04-02 |
| CVE-2009-0680 EXP | cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (device crash) via a crafted quer… | Patch early | 7.8 high | 8.4% | 2009-02-22 |
| CVE-2005-4720 EXP | Mozilla Firefox 1.0.7 and earlier on Linux allows remote attackers to cause a denial of service (client crash) via an IFRAME element with a large valu… | Patch early | 5.0 medium | 8.4% | 2005-12-31 |
| CVE-2002-1792 EXP | Buffer overflow in Fake Identd 0.9 through 1.4 allows remote attackers to execute arbitrary code as root via a long request that is split into multipl… | Patch early | 10.0 high | 8.4% | 2002-12-31 |
| CVE-2010-1723 EXP | Directory traversal vulnerability in the iNetLanka Contact Us Draw Root Map (com_drawroot) component 1.1 for Joomla! allows remote attackers to read a… | Patch early | 6.8 medium | 8.4% | 2010-05-04 |
| CVE-2011-4531 EXP | Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allows remote attackers to cause a denial of service (NULL pointer dereference and d… | Patch early | 5.0 medium | 8.4% | 2012-01-08 |
| CVE-2007-6268 EXP | Directory traversal vulnerability in pages/default.aspx in Absolute News Manager.NET 5.1 allows remote attackers to read arbitrary files via a .. (dot… | Patch early | 5.0 medium | 8.4% | 2007-12-07 |
| CVE-2013-4743 EXP | Static HTTP Server 1.0 has a Local Overflow | Patch early | 9.8 critical | 8.4% | 2019-12-27 |
| CVE-2015-2184 EXP | ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls the phpinfo function. | Patch early | 5.0 medium | 8.4% | 2015-03-10 |
| CVE-2001-0385 EXP | GoAhead webserver 2.1 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory. | Patch early | 5.0 medium | 8.4% | 2001-07-02 |
| CVE-2004-2254 EXP | SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface… | Patch early | 7.5 high | 8.4% | 2004-12-31 |
| CVE-2009-1313 EXP | The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of s… | Patch early | 9.3 high | 8.4% | 2009-04-30 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt