CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,729 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-8393 EXP | DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion. | Patch early | 7.8 high | 8.3% | 2017-08-29 |
| CVE-2006-2152 EXP | PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows… | Patch early | 7.5 high | 8.3% | 2006-05-03 |
| CVE-2002-0681 EXP | Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that gen… | Patch early | 7.5 high | 8.3% | 2002-07-23 |
| CVE-2007-0197 EXP | Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a lo… | Patch early | 6.8 medium | 8.3% | 2007-01-11 |
| CVE-2017-11321 EXP | The restricted shell interface in UCOPIA Wireless Appliance before 5.1.8 allows remote authenticated users to gain 'admin' privileges via shell metach… | Patch early | 7.2 high | 8.3% | 2017-10-03 |
| CVE-2001-0571 EXP | Directory traversal vulnerability in the web server for (1) Elron Internet Manager (IM) Message Inspector and (2) Anti-Virus before 3.0.4 allows remot… | Patch early | 5.0 medium | 8.3% | 2001-08-22 |
| CVE-2002-1004 EXP | Directory traversal vulnerability in webmail feature of ArGoSoft Mail Server Plus or Pro 1.8.1.5 and earlier allows remote attackers to read arbitrary… | Patch early | 5.0 medium | 8.3% | 2002-10-04 |
| CVE-1999-1509 EXP | Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a… | Patch early | 5.0 medium | 8.3% | 1999-11-04 |
| CVE-2000-1171 EXP | Directory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote attackers to ready arbitrary files via a .. (dot dot) attack in… | Patch early | 5.0 medium | 8.3% | 2001-01-09 |
| CVE-2001-0360 EXP | Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitrary files via a .. (dot dot) atta… | Patch early | 5.0 medium | 8.3% | 2001-06-27 |
| CVE-2009-0649 EXP | The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) via JavaScript code that calls… | Patch early | 7.8 high | 8.3% | 2009-02-20 |
| CVE-2017-14087 EXP | A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header, allowing the attack… | Patch early | 7.5 high | 8.3% | 2017-10-06 |
| CVE-2008-2015 EXP | Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attackers to create or overwrite ar… | Patch early | 9.3 high | 8.3% | 2008-04-30 |
| CVE-2007-1001 EXP | Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0 t… | Patch early | 6.8 medium | 8.3% | 2007-04-06 |
| CVE-2026-24479 EXP | HUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. Prior to version 26.01.24, the problem_import_qduoj… | Patch early | 9.8 critical | 8.3% | 2026-01-27 |
| CVE-2012-0276 EXP | Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (application crash) and possibly execut… | Patch early | 6.8 medium | 8.3% | 2012-07-17 |
| CVE-2007-1465 EXP | Stack-based buffer overflow in dproxy.c for dproxy 0.1 through 0.5 allows remote attackers to execute arbitrary code via a long DNS query packet to UD… | Patch early | 10.0 high | 8.3% | 2007-03-24 |
| CVE-2010-1930 EXP | Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (daemon crash) via a long tree par… | Patch early | 5.0 medium | 8.3% | 2010-06-28 |
| CVE-2005-3048 EXP | Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or include arbitrary PHP files via a… | Patch early | 6.4 medium | 8.3% | 2005-09-24 |
| CVE-2023-4114 EXP | A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0. It has been rated as problematic. This issue affects some unknown processing… | Patch early | 4.3 medium | 8.3% | 2023-08-03 |
| CVE-2010-0278 EXP | A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allow… | Patch early | 4.3 medium | 8.3% | 2010-01-12 |
| CVE-2006-1767 EXP | Multiple PHP remote file inclusion vulnerabilities in nicecoder.com INDEXU 5.0.0 and 5.0.1 allow remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 8.3% | 2006-04-13 |
| CVE-2015-1362 EXP | Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary code via a long string in the ma… | Patch early | 7.5 high | 8.3% | 2015-01-27 |
| CVE-2005-0442 EXP | Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter. | Patch early | 5.0 medium | 8.3% | 2005-05-02 |
| CVE-2017-10682 EXP | SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_fa… | Patch early | 9.8 critical | 8.3% | 2017-06-29 |
| CVE-2004-0128 EXP | PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitr… | Patch early | 7.5 high | 8.3% | 2004-03-03 |
| CVE-2004-1934 EXP | PHP remote file inclusion vulnerability in affich.php in Gemitel 3.50 allows remote attackers to execute arbitrary PHP code via the base parameter. | Patch early | 7.5 high | 8.3% | 2004-04-15 |
| CVE-2009-2626 EXP | The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive… | Patch early | 6.4 medium | 8.3% | 2009-12-01 |
| CVE-2017-14702 EXP | ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.UpdateRequest" object deserializa… | Patch early | 9.8 critical | 8.3% | 2017-09-30 |
| CVE-2006-1100 EXP | Buffer overflow in the sgetstr function in shared/cube.h in Sauerbraten 2006_02_28 and earlier, as derived from the Cube engine, allows remote attacke… | Patch early | 7.5 high | 8.3% | 2006-03-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt