CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,729 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-1948 EXP | Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoff… | Patch early | 9.3 high | 8.3% | 2007-04-11 |
| CVE-2008-1277 EXP | The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause a denial of… | Patch early | 9.0 high | 8.3% | 2008-03-10 |
| CVE-2014-8835 EXP | The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes key has the xpc_data data type,… | Patch early | 9.3 high | 8.3% | 2015-01-30 |
| CVE-2015-4038 EXP | The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_setti… | Patch early | 6.5 medium | 8.3% | 2015-06-03 |
| CVE-2009-1879 EXP | Cross-site scripting (XSS) vulnerability in index.template.html in the express-install templates in the SDK in Adobe Flex before 3.4, when the install… | Patch early | 2.6 low | 8.3% | 2009-08-21 |
| CVE-2008-6703 EXP | Stack-based buffer overflow in the IPureServer::_Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to… | Patch early | 10.0 high | 8.3% | 2009-04-10 |
| CVE-2008-7031 EXP | Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of service (crash)… | Patch early | 10.0 high | 8.3% | 2009-08-24 |
| CVE-2006-2834 EXP | PHP remote file inclusion vulnerability in includes/common.php in gnopaste 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 8.2% | 2006-06-06 |
| CVE-1999-0063 EXP | Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port. | Patch early | 5.0 medium | 8.2% | 1999-01-11 |
| CVE-2004-2047 EXP | Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot)… | Patch early | 5.0 medium | 8.2% | 2004-07-23 |
| CVE-2002-0483 EXP | index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to… | Patch early | 5.0 medium | 8.2% | 2002-08-12 |
| CVE-2022-24263 EXP | Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email p… | Patch early | 9.8 critical | 8.2% | 2022-01-31 |
| CVE-2010-3135 EXP | Untrusted search path vulnerability in Cisco Packet Tracer 5.2 allows local users, and possibly remote attackers, to execute arbitrary code and conduc… | Patch early | 9.3 high | 8.2% | 2010-08-26 |
| CVE-2004-1641 EXP | Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) via a long FTP command such as (… | Patch early | 5.0 medium | 8.2% | 2004-08-29 |
| CVE-2016-9332 EXP | An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate input. An attacker could prov… | Patch early | 7.5 high | 8.2% | 2017-02-13 |
| CVE-2007-3955 EXP | Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote attackers t… | Patch early | 6.8 medium | 8.2% | 2007-07-24 |
| CVE-2021-34369 EXP | portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensitive information via a modified… | Patch early | 6.5 medium | 8.2% | 2021-06-09 |
| CVE-2021-40964 EXP | A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin cred… | Patch early | 6.5 medium | 8.2% | 2021-09-15 |
| CVE-2008-7269 EXP | Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbitrary web sites and conduct ph… | Patch early | 5.8 medium | 8.2% | 2010-12-01 |
| CVE-2010-1315 EXP | Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1.x before 1.06.02 for Joomla!… | Patch early | 5.0 medium | 8.2% | 2010-04-08 |
| CVE-2010-1461 EXP | Directory traversal vulnerability in the Photo Battle (com_photobattle) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files vi… | Patch early | 5.0 medium | 8.2% | 2010-04-16 |
| CVE-2010-1540 EXP | Directory traversal vulnerability in index.php in the MyBlog (com_myblog) component 3.0.329 for Joomla! allows remote attackers to read arbitrary file… | Patch early | 5.0 medium | 8.2% | 2010-04-26 |
| CVE-2005-0316 EXP | WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which co… | Patch early | 7.5 high | 8.2% | 2005-01-28 |
| CVE-2009-2100 EXP | Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows remote attackers to read arbit… | Patch early | 5.0 medium | 8.2% | 2009-06-17 |
| CVE-2009-0879 EXP | The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of service (daemon crash) via a lon… | Patch early | 5.0 medium | 8.2% | 2009-03-12 |
| CVE-2016-10504 EXP | Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial o… | Patch early | 6.5 medium | 8.2% | 2017-08-30 |
| CVE-2006-2016 EXP | Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8 and earlier allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 2.6 low | 8.2% | 2006-04-25 |
| CVE-2009-4251 EXP | Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers to execute arbitrary code via… | Patch early | 9.3 high | 8.2% | 2009-12-10 |
| CVE-2007-4907 EXP | Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a URL in the xcart_dir parameter… | Patch early | 7.5 high | 8.2% | 2007-09-17 |
| CVE-2007-4553 EXP | The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via an INVITE message with a Via… | Patch early | 5.0 medium | 8.2% | 2007-08-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt