CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,887 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-11446 EXP | An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files se… | Patch early | 8.8 high | 7.8% | 2019-04-22 |
| CVE-2021-27825 EXP | A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL. | Patch early | 7.5 high | 7.8% | 2023-05-29 |
| CVE-2013-3956 EXP | The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2 on Windows Vista and Windows… | Patch early | 7.2 high | 7.8% | 2013-07-31 |
| CVE-2006-5196 EXP | The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with… | Patch early | 7.8 high | 7.8% | 2006-10-10 |
| CVE-2017-6805 EXP | Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read arbitrary files via a .. (dot d… | Patch early | 5.3 medium | 7.8% | 2017-03-20 |
| CVE-2012-6470 EXP | Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a denial of serv… | Patch early | 9.3 high | 7.8% | 2013-01-02 |
| CVE-2009-1353 EXP | Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause a denial of service (daemon cr… | Patch early | 5.0 medium | 7.8% | 2009-04-21 |
| CVE-2005-2719 EXP | Ventrilo 2.1.2 through 2.3.0 allows remote attackers to cause a denial of service (application crash) via a status packet that contains less data than… | Patch early | 5.0 medium | 7.8% | 2005-08-30 |
| CVE-2007-1568 EXP | Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via a yEnc (yEncode) encoded arti… | Patch early | 10.0 high | 7.8% | 2007-03-21 |
| CVE-2018-19277 EXP | securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file | Patch early | 8.8 high | 7.8% | 2018-11-14 |
| CVE-2004-0285 EXP | PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers t… | Patch early | 9.8 critical | 7.8% | 2004-11-23 |
| CVE-2017-2468 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 7.8% | 2017-04-02 |
| CVE-2019-15104 EXP | An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via… | Patch early | 8.8 high | 7.8% | 2019-08-16 |
| CVE-2019-15105 EXP | An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration… | Patch early | 8.8 high | 7.8% | 2019-08-16 |
| CVE-2017-17538 EXP | MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets. | Patch early | 7.5 high | 7.8% | 2017-12-13 |
| CVE-2008-6713 EXP | World in Conflict (WIC) 1.008 and earlier allows remote attackers to cause a denial of service (access violation and crash) via a zero-byte data block… | Patch early | 5.0 medium | 7.8% | 2009-04-10 |
| CVE-2007-2594 EXP | PHP remote file inclusion vulnerability in inc/articles.inc.php in phpMyPortal 3.0.0 RC3 allows remote attackers to execute arbitrary PHP code via a U… | Patch early | 7.5 high | 7.8% | 2007-05-11 |
| CVE-2007-6179 EXP | Multiple PHP remote file inclusion vulnerabilities in Charray's CMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the ccms_l… | Patch early | 7.5 high | 7.8% | 2007-11-30 |
| CVE-2002-0335 EXP | Buffer overflow in Galacticomm Worldgroup web server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbit… | Patch early | 10.0 high | 7.8% | 2002-06-25 |
| CVE-2000-0423 EXP | Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd, and utag. | Patch early | 5.0 medium | 7.8% | 2000-05-05 |
| CVE-2017-15012 EXP | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILE RPC-comma… | Patch early | 8.8 high | 7.8% | 2017-10-13 |
| CVE-2007-4596 EXP | The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eval… | Patch early | 7.5 high | 7.8% | 2007-08-30 |
| CVE-2003-0595 EXP | Buffer overflow in WiTango Application Server and Tango 2000 allows remote attackers to execute arbitrary code via a long cookie to Witango_UserRefere… | Patch early | 7.5 high | 7.8% | 2003-08-27 |
| CVE-2003-0762 EXP | Buffer overflow in (1) foxweb.dll and (2) foxweb.exe of Foxweb 2.5 allows remote attackers to execute arbitrary code via a long URL (PATH_INFO value). | Patch early | 7.5 high | 7.8% | 2003-09-17 |
| CVE-2009-3242 EXP | Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2.0 and 1.2.1 allows remote attackers to cause a denial of service (app… | Patch early | 5.0 medium | 7.8% | 2009-09-18 |
| CVE-2009-4117 EXP | Multiple stack-based buffer overflows in pdf_shade4.c in MuPDF before commit 20091125231942, as used in SumatraPDF before 1.0.1, allow remote attacker… | Patch early | 9.3 high | 7.8% | 2009-12-01 |
| CVE-2018-12979 EXP | An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions allow an authenticated user t… | Patch early | 6.5 medium | 7.8% | 2018-07-12 |
| CVE-2005-0575 EXP | Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via… | Patch early | 7.5 high | 7.8% | 2005-05-02 |
| CVE-2008-3319 EXP | admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary… | Patch early | 7.5 high | 7.8% | 2008-07-25 |
| CVE-2008-3321 EXP | admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitr… | Patch early | 7.5 high | 7.8% | 2008-07-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt