CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,169 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-5594 EXP | An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when… | Patch early | 7.5 high | 7% | 2017-01-25 |
| CVE-2007-5710 EXP | Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inject arbitrary web script or HTM… | Patch early | 2.6 low | 7% | 2007-10-30 |
| CVE-2017-9147 EXP | LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash)… | Patch early | 6.5 medium | 7% | 2017-05-22 |
| CVE-2004-2082 EXP | The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsystem.exe crash) via a GET request… | Patch early | 5.0 medium | 7% | 2004-02-13 |
| CVE-2015-7897 EXP | The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9 allows remote… | Patch early | 7.5 high | 7% | 2015-11-16 |
| CVE-2004-1741 EXP | Music daemon (musicd) 0.0.3 and earlier allows remote attackers to cause a denial of service (crash) by calling LOAD with a binary file as an argument… | Patch early | 5.0 medium | 7% | 2004-08-23 |
| CVE-2005-0986 EXP | NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of serv… | Patch early | 5.0 medium | 7% | 2005-05-02 |
| CVE-2005-3187 EXP | The listening daemon in Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service (crash) via a long HTTP reque… | Patch early | 5.0 medium | 7% | 2005-12-31 |
| CVE-2000-0045 EXP | MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege. | Patch early | 6.4 medium | 7% | 2000-01-11 |
| CVE-2001-0302 EXP | Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary comman… | Patch early | 5.0 medium | 7% | 2001-05-03 |
| CVE-2019-15811 EXP | In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS. | Patch early | 6.1 medium | 7% | 2019-08-29 |
| CVE-2009-2403 EXP | Heap-based buffer overflow in SCMPX 1.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a lon… | Patch early | 9.3 high | 7% | 2009-07-09 |
| CVE-2003-0508 EXP | Buffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earlier allows remote attackers to execute arbitrary co… | Patch early | 7.5 high | 7% | 2003-08-07 |
| CVE-2014-8868 EXP | EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain the administrator username and… | Patch early | 7.8 high | 7% | 2014-12-07 |
| CVE-2013-7055 EXP | D-Link DIR-100 4.03B07 has PPTP and poe information disclosure | Patch early | 9.8 critical | 7% | 2020-02-04 |
| CVE-2007-4735 EXP | Buffer overflow in Next Generation Software Virtual DJ (VDJ) 5.0 allows user-assisted remote attackers to execute arbitrary code via a long file path… | Patch early | 9.3 high | 7% | 2007-09-06 |
| CVE-2003-0332 EXP | The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing… | Patch early | 7.6 high | 7% | 2003-06-09 |
| CVE-2016-7786 EXP | Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demon… | Patch early | 8.8 high | 7% | 2017-04-07 |
| CVE-2017-17088 EXP | The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The web server does not check bounds… | Patch early | 7.5 high | 7% | 2017-12-19 |
| CVE-2006-4922 EXP | Unrestricted file upload vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and earlier allows remote attackers t… | Patch early | 5.0 medium | 7% | 2006-09-21 |
| CVE-2006-3698 EXP | Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB01 for Change Data Cap… | Patch early | 10.0 high | 7% | 2006-07-21 |
| CVE-2013-4776 EXP | NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier, GS748Tv4 5.4.1.14, and GS510TP 5.0.4.4 allows remote attackers to cause a de… | Patch early | 7.8 high | 7% | 2013-12-19 |
| CVE-2011-1974 EXP | NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly v… | Patch early | 7.2 high | 7% | 2011-08-10 |
| CVE-2003-0442 EXP | Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attacker… | Patch early | 4.3 medium | 7% | 2003-07-24 |
| CVE-2013-7420 EXP | Buffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attribute in a TEXTART XML element… | Patch early | 7.5 high | 7% | 2015-01-12 |
| CVE-2016-4997 EXP | The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow loc… | Patch early | 7.8 high | 7% | 2016-07-03 |
| CVE-2001-0563 EXP | ElectroSystems Engineering Inc. ElectroComm 2.0 and earlier allows a remote attacker to create a denial of service via large (> 160000 character) stri… | Patch early | 5.0 medium | 7% | 2001-08-14 |
| CVE-2002-0923 EXP | CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2) pfooter p… | Patch early | 7.5 high | 7% | 2002-10-04 |
| CVE-2013-1668 EXP | The uploadFile function in upload/index.php in CosCMS before 1.822 allows remote administrators to execute arbitrary commands via shell metacharacters… | Patch early | 8.5 high | 7% | 2014-05-23 |
| CVE-2013-1463 EXP | Cross-site scripting (XSS) vulnerability in js/tabletools/zeroclipboard.swf in the WP-Table Reloaded module before 1.9.4 for Wordpress allows remote a… | Patch early | 4.3 medium | 7% | 2013-02-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt