CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,558 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-1999-0448 EXP | IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request. | Patch early | 5.0 medium | 24.6% | 1999-01-01 |
| CVE-2006-0032 EXP | Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Au… | Patch early | 4.3 medium | 24.6% | 2006-09-12 |
| CVE-2015-2790 EXP | Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a cra… | Patch early | 4.3 medium | 24.5% | 2015-03-30 |
| CVE-2008-5793 EXP | Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers… | Patch early | 6.8 medium | 24.5% | 2008-12-31 |
| CVE-2006-0015 EXP | Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services… | Patch early | 6.8 medium | 24.4% | 2006-04-11 |
| CVE-2018-6794 EXP | Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious server breaks a normal TCP flow… | Patch early | 5.3 medium | 24.3% | 2018-02-07 |
| CVE-2008-7182 EXP | Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users to cause a d… | Patch early | 4.0 medium | 24.3% | 2009-09-08 |
| CVE-2006-3512 EXP | Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) by setting the Enabled property of a DXTFilter ActiveX… | Patch early | 5.0 medium | 24.3% | 2006-07-11 |
| CVE-2006-3605 EXP | Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Transition property on an uninitialized DXIm… | Patch early | 5.0 medium | 24.3% | 2006-07-18 |
| CVE-2006-3427 EXP | Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL attribute on an uninitialized Di… | Patch early | 5.0 medium | 24.3% | 2006-07-07 |
| CVE-2006-3899 EXP | Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the stringToBina… | Patch early | 5.0 medium | 24.3% | 2006-07-27 |
| CVE-2006-3898 EXP | Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the Click method… | Patch early | 5.0 medium | 24.3% | 2006-07-27 |
| CVE-2002-1700 EXP | Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary scri… | Patch early | 4.3 medium | 24.3% | 2002-12-31 |
| CVE-2016-5725 EXP | Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write… | Patch early | 5.9 medium | 24.1% | 2017-01-19 |
| CVE-2006-3101 EXP | Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 24% | 2006-06-21 |
| CVE-2012-5611 EXP | Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.… | Patch early | 6.5 medium | 24% | 2012-12-03 |
| CVE-2020-9467 EXP | Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function. | Patch early | 5.4 medium | 23.8% | 2020-03-26 |
| CVE-2001-0205 EXP | Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by inserting "..." into the requested p… | Patch early | 5.0 medium | 23.6% | 2001-05-03 |
| CVE-2008-1126 EXP | PHP remote file inclusion vulnerability in main.php in Barryvan Compo Manager 0.3 allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 6.8 medium | 23.6% | 2008-03-03 |
| CVE-2013-3585 EXP | Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information v… | Patch early | 5.0 medium | 23.5% | 2013-08-28 |
| CVE-2010-4476 EXP | The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and ear… | Patch early | 5.0 medium | 23.5% | 2011-02-17 |
| CVE-2008-0566 EXP | PHP remote file inclusion vulnerability in includes/smarty.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary… | Patch early | 6.8 medium | 23.5% | 2008-02-05 |
| CVE-2018-8532 EXP | An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a refere… | Patch early | 5.5 medium | 23.4% | 2018-10-10 |
| CVE-2018-8527 EXP | An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a referen… | Patch early | 5.5 medium | 23.4% | 2018-10-10 |
| CVE-2018-8533 EXP | An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a refere… | Patch early | 5.5 medium | 23.4% | 2018-10-10 |
| CVE-2005-0452 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or… | Patch early | 4.3 medium | 23.4% | 2005-02-16 |
| CVE-2011-4106 EXP | TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute… | Patch early | 6.8 medium | 23.3% | 2013-10-26 |
| CVE-2006-3897 EXP | Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating a… | Patch early | 5.0 medium | 23.3% | 2006-07-27 |
| CVE-2003-0002 EXP | Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to exec… | Patch early | 6.8 medium | 23.3% | 2003-02-07 |
| CVE-2013-5528 EXP | Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users… | Patch early | 4.0 medium | 23.3% | 2013-10-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt