CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,166 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-1276 EXP | Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allow remote au… | Patch early | 9.0 high | 7.1% | 2008-03-10 |
| CVE-2002-0106 EXP | BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP files that contain an MS-DOS dev… | Patch early | 5.0 medium | 7.1% | 2002-03-25 |
| CVE-2007-1648 EXP | 0irc 1345 build 20060823 allows remote attackers to cause a denial of service (application crash) by operating an IRC server that sends a long string… | Patch early | 7.8 high | 7.1% | 2007-03-24 |
| CVE-2007-2497 EXP | RealNetworks RealPlayer 10 Gold allows remote attackers to cause a denial of service (memory consumption) via a certain .ra file. NOTE: this issue wa… | Patch early | 7.8 high | 7.1% | 2007-05-04 |
| CVE-2012-0292 EXP | The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Alt… | Patch early | 5.0 medium | 7.1% | 2012-03-08 |
| CVE-2020-11700 EXP | An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an attacker t… | Patch early | 6.5 medium | 7.1% | 2020-09-17 |
| CVE-2013-1465 EXP | The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP object… | Patch early | 9.8 critical | 7.1% | 2013-02-08 |
| CVE-2009-1057 EXP | MicroSmarts Enterprise ZipItFast! 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file that triggers memory corruption, relat… | Patch early | 10.0 high | 7.1% | 2009-03-24 |
| CVE-2008-3950 EXP | Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iPhone 1.1.4 and 2.0 and iPod to… | Patch early | 5.0 medium | 7.1% | 2008-09-16 |
| CVE-2013-3314 EXP | The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2) firmware versions (ui and sys… | Patch early | 7.5 high | 7.1% | 2019-11-21 |
| CVE-2014-2630 EXP | Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via unknown vectors. | Patch early | 4.4 medium | 7.1% | 2014-08-12 |
| CVE-2019-16399 EXP | Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory witho… | Patch early | 9.8 critical | 7.1% | 2019-09-18 |
| CVE-2018-4087 EXP | An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. Th… | Patch early | 7.8 high | 7.1% | 2018-04-03 |
| CVE-2002-1238 EXP | Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request with a sequenc… | Patch early | 7.5 high | 7.1% | 2002-11-12 |
| CVE-2001-0298 EXP | Buffer overflow in WebReflex 1.55 HTTPd allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP… | Patch early | 5.0 medium | 7.1% | 2001-05-03 |
| CVE-2002-1830 EXP | Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via a direct request to moderator.… | Patch early | 5.0 medium | 7.1% | 2002-12-31 |
| CVE-2005-3982 EXP | CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response s… | Patch early | 5.0 medium | 7.1% | 2005-12-04 |
| CVE-2007-5256 EXP | Multiple stack-based buffer overflows in FSD 2.052 d9 and earlier, and FSFDT FSD 3.000 d9 and earlier, allow (1) remote attackers to execute arbitrary… | Patch early | 7.5 high | 7.1% | 2007-10-06 |
| CVE-2008-4926 EXP | Multiple insecure method vulnerabilities in MW6 Technologies PDF417 ActiveX control (MW6PDF417Lib.PDF417, MW6PDF417.dll) 3.0.0.1 allow remote attacker… | Patch early | 9.0 high | 7.1% | 2008-11-04 |
| CVE-2003-1459 EXP | Multiple PHP remote file inclusion vulnerabilities in ttCMS 2.2 and ttForum allow remote attackers to execute arbitrary PHP code via the (1) template… | Patch early | 6.8 medium | 7.1% | 2003-12-31 |
| CVE-2006-2583 EXP | PHP remote file inclusion vulnerability in nucleus/libs/PLUGINADMIN.php in Nucleus 3.22 and earlier allows remote attackers to execute arbitrary PHP c… | Patch early | 5.1 medium | 7.1% | 2006-05-25 |
| CVE-2011-0403 EXP | Untrusted search path vulnerability in ImgBurn.exe in ImgBurn 2.4.0.0, 2.5.4.0, and other versions allows local users, and possibly remote attackers,… | Patch early | 9.3 high | 7.1% | 2011-01-11 |
| CVE-2014-5521 EXP | plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in… | Patch early | 6.5 medium | 7.1% | 2014-09-02 |
| CVE-2015-2314 EXP | SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang param… | Patch early | 7.5 high | 7.1% | 2015-03-17 |
| CVE-2004-1020 EXP | The addslashes function in PHP 4.3.9 does not properly escape a NULL (/0) character, which may allow remote attackers to read arbitrary files in PHP a… | Patch early | 5.0 medium | 7.1% | 2005-01-10 |
| CVE-2006-3162 EXP | PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 7.1% | 2006-06-22 |
| CVE-2016-9684 EXP | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative i… | Patch early | 9.8 critical | 7.1% | 2017-02-22 |
| CVE-2007-6347 EXP | PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Shop Evaluation 3.3.2, and (4) Sh… | Patch early | 6.8 medium | 7.1% | 2007-12-13 |
| CVE-2016-2203 EXP | The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by… | Patch early | 7.8 high | 7.1% | 2016-04-22 |
| CVE-2003-0625 EXP | Off-by-one error in certain versions of xfstt allows remote attackers to read potentially sensitive memory via a malformed client request in the conne… | Patch early | 7.5 high | 7.1% | 2003-08-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt