CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,729 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-1636 EXP | Heap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to execute arbitrary… | Patch early | 10.0 high | 8.3% | 2004-10-26 |
| CVE-2018-15172 EXP | TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header. | Patch early | 7.5 high | 8.3% | 2018-08-15 |
| CVE-2008-7090 EXP | Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existence of arbitrary files via a .… | Patch early | 7.8 high | 8.3% | 2009-08-26 |
| CVE-2019-9600 EXP | The Olive Tree FTP Server (aka com.theolivetree.ftpserver) application through 1.32 for Android allows remote attackers to cause a denial of service v… | Patch early | 7.5 high | 8.3% | 2019-03-06 |
| CVE-2019-9601 EXP | The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many simultaneous /?Key=PhoneRequestA… | Patch early | 7.5 high | 8.3% | 2019-03-06 |
| CVE-2002-0893 EXP | Directory traversal vulnerability in NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to read arbitrary files via a URL-encoded request to com… | Patch early | 5.0 medium | 8.3% | 2002-10-04 |
| CVE-2010-2126 EXP | Multiple PHP remote file inclusion vulnerabilities in Snipe Gallery 3.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the cfg_ad… | Patch early | 7.5 high | 8.3% | 2010-06-01 |
| CVE-2006-2995 EXP | Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 8.3% | 2006-06-13 |
| CVE-2006-4051 EXP | PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 8.3% | 2006-08-10 |
| CVE-2006-4440 EXP | PHP remote file inclusion vulnerability in main.php in Ay System Solutions CMS 2.6 and earlier allows remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 8.3% | 2006-08-29 |
| CVE-2007-0820 EXP | Multiple PHP remote file inclusion vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 8.3% | 2007-02-07 |
| CVE-2016-3861 EXP | LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles conversions… | Patch early | 7.8 high | 8.3% | 2016-09-11 |
| CVE-2019-8622 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watc… | Patch early | 8.8 high | 8.3% | 2019-12-18 |
| CVE-2019-8623 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watc… | Patch early | 8.8 high | 8.3% | 2019-12-18 |
| CVE-2002-0611 EXP | Directory traversal vulnerability in FileSeek.cgi allows remote attackers to read arbitrary files via a ....// (modified dot dot) in the (1) head or (… | Patch early | 5.0 medium | 8.3% | 2002-06-18 |
| CVE-2005-4212 EXP | Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via ".." (dot dot) se… | Patch early | 5.0 medium | 8.3% | 2005-12-14 |
| CVE-2018-5753 EXP | The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev… | Patch early | 6.5 medium | 8.3% | 2018-06-16 |
| CVE-2002-1451 EXP | Blazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an HTTP request that ends in a (… | Patch early | 5.0 medium | 8.3% | 2002-08-24 |
| CVE-2008-3195 EXP | Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows remote atta… | Patch early | 6.8 medium | 8.3% | 2008-09-18 |
| CVE-2005-3475 EXP | Hasbani Web Server (WindWeb) 2.0 allows remote attackers to cause a denial of service (infinite loop) via HTTP crafted GET requests. | Patch early | 5.0 medium | 8.3% | 2005-11-03 |
| CVE-2006-5571 EXP | Stack-based buffer overflow in /scripts/cruise/cws.exe in CruiseWorks 1.09c and 1.09d allows remote attackers to execute arbitrary code via a long str… | Patch early | 7.5 high | 8.3% | 2006-10-27 |
| CVE-2007-5299 EXP | Multiple directory traversal vulnerabilities in SkaDate 5.0 and 6.0, and possibly later versions such as 6.482, allow remote attackers to read arbitra… | Patch early | 5.0 medium | 8.3% | 2007-10-09 |
| CVE-2013-3430 EXP | Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspec… | Patch early | 9.0 high | 8.3% | 2013-07-25 |
| CVE-2010-1180 EXP | Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… | Patch early | 9.3 high | 8.3% | 2010-03-29 |
| CVE-2013-2218 EXP | Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers to… | Patch early | 5.0 medium | 8.3% | 2013-09-30 |
| CVE-2012-0744 EXP | IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a reques… | Patch early | 5.0 medium | 8.3% | 2012-08-17 |
| CVE-2007-0485 EXP | PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP code via a URL in the WEBCHATP… | Patch early | 7.5 high | 8.3% | 2007-01-25 |
| CVE-2002-0775 EXP | browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter. | Patch early | 5.0 medium | 8.3% | 2002-08-12 |
| CVE-2017-2446 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 8.3% | 2017-04-02 |
| CVE-2006-5925 EXP | Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an… | Patch early | 7.5 high | 8.3% | 2006-11-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt