CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,145 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-3292 EXP | constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the photoalbumadmin cook… | Patch early | 6.4 medium | 7.3% | 2008-07-24 |
| CVE-2006-0791 EXP | PHP remote file inclusion vulnerability in index.php in DreamCost HostAdmin allows remote attackers to include arbitrary files via the $path variable,… | Patch early | 7.5 high | 7.3% | 2006-02-19 |
| CVE-2007-3312 EXP | Directory traversal vulnerability in admin/plugin_manager.php in Jasmine CMS 1.0 allows remote authenticated administrators to include and execute arb… | Patch early | 9.0 high | 7.3% | 2007-06-21 |
| CVE-2007-3140 EXP | SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value i… | Patch early | 6.5 medium | 7.3% | 2007-06-08 |
| CVE-2001-0224 EXP | Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter. | Patch early | 5.0 medium | 7.3% | 2001-06-02 |
| CVE-2001-1115 EXP | generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter. | Patch early | 5.0 medium | 7.3% | 2001-08-13 |
| CVE-2006-1124 EXP | Buffer overflow in RevilloC MailServer and Proxy 1.21 allows remote attackers to execute arbitrary code via a long USER command. | Patch early | 7.5 high | 7.3% | 2006-03-09 |
| CVE-2008-5625 EXP | PHP 5 before 5.2.7 does not enforce the error_log safe_mode restrictions when safe_mode is enabled through a php_admin_flag setting in httpd.conf, whi… | Patch early | 7.5 high | 7.3% | 2008-12-17 |
| CVE-2026-42167 EXP | mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER request… | Patch early | 8.1 high | 7.3% | 2026-04-28 |
| CVE-2019-19143 EXP | TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi/softup URI. | Patch early | 6.1 medium | 7.3% | 2020-01-27 |
| CVE-2006-3082 EXP | parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, allows remote attackers to cause a denial of service (gpg crash) and possibly ov… | Patch early | 5.0 medium | 7.3% | 2006-06-19 |
| CVE-2006-2256 EXP | PHP remote file inclusion vulnerability in includes/dbal.php in EQdkp 1.3.0 and earlier allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 6.4 medium | 7.3% | 2006-05-09 |
| CVE-2013-4097 EXP | ServerAdmin/TestDRConnection.jsp in DS3 Authentication Server allows remote attackers to obtain sensitive information via a direct request, which reve… | Patch early | 5.0 medium | 7.3% | 2013-06-28 |
| CVE-2006-2439 EXP | Stack-based buffer overflow in ZipCentral 4.01 allows remote user-assisted attackers to execute arbitrary code via a ZIP archive containing a long fil… | Patch early | 7.6 high | 7.3% | 2006-06-01 |
| CVE-2018-9035 EXP | CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to… | Patch early | 9.6 critical | 7.3% | 2018-04-04 |
| CVE-2022-2941 EXP | The WP-UserOnline plugin for WordPress has multiple Stored Cross-Site Scripting vulnerabilities in versions up to, and including 2.88.0. This is due t… | Patch early | 5.5 medium | 7.3% | 2022-09-06 |
| CVE-2000-0234 EXP | The default configuration of Cobalt RaQ2 and RaQ3 as specified in access.conf allows remote attackers to view sensitive contents of a .htaccess file. | Patch early | 5.0 medium | 7.3% | 2000-03-31 |
| CVE-2000-0243 EXP | AnalogX SimpleServer:WWW HTTP server 1.03 allows remote attackers to cause a denial of service via a short GET request to cgi-bin. | Patch early | 5.0 medium | 7.3% | 2000-03-25 |
| CVE-2000-0644 EXP | WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST command is still executing. | Patch early | 5.0 medium | 7.3% | 2000-07-21 |
| CVE-2001-0558 EXP | T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS devic… | Patch early | 5.0 medium | 7.3% | 2001-08-14 |
| CVE-2008-0647 EXP | Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.2… | Patch early | 10.0 high | 7.3% | 2008-02-07 |
| CVE-2007-1569 EXP | Stack-based buffer overflow in NewsBin Pro 4.32 allows remote attackers to cause a denial of service or execute arbitrary code via a yEnc (yEncode) en… | Patch early | 10.0 high | 7.3% | 2007-03-21 |
| CVE-2009-4841 EXP | Heap-based buffer overflow in the SonicMediaPlayer ActiveX control in SonicMediaPlayer.dll in Roxio CinePlayer 3.2 allows remote attackers to execute… | Patch early | 9.3 high | 7.3% | 2010-05-06 |
| CVE-2017-14521 EXP | In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload. | Patch early | 8.8 high | 7.3% | 2018-01-26 |
| CVE-2007-2059 EXP | Multiple buffer overflows in the ESA protocol implementation in eIQnetworks Enterprise Security Analyzer (ESA) 2.5 allow remote attackers to execute a… | Patch early | 10.0 high | 7.3% | 2007-04-18 |
| CVE-2009-0328 EXP | ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root with insufficient access contro… | Patch early | 5.0 medium | 7.3% | 2009-01-29 |
| CVE-2017-13260 EXP | In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosu… | Patch early | 7.5 high | 7.3% | 2018-04-04 |
| CVE-2004-1484 EXP | Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly optio… | Patch early | 5.0 medium | 7.3% | 2004-12-31 |
| CVE-2002-1685 EXP | Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary… | Patch early | 4.3 medium | 7.3% | 2002-12-31 |
| CVE-2008-1910 EXP | Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 SP2 allows remote attackers to execute arbitrary code via… | Patch early | 10.0 high | 7.3% | 2008-04-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt