CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,169 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-37759 EXP | Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an… | Patch early | 9.8 critical | 7% | 2023-09-08 |
| CVE-2007-2526 EXP | Heap-based buffer overflow in the ConnectAsyncEx function in VNC Viewer ActiveX control (scvncctrl.dll) in the SmartCode VNC Manager 3.6 allows remote… | Patch early | 9.3 high | 7% | 2007-05-08 |
| CVE-2007-2648 EXP | Stack-based buffer overflow in the Clever Database Comparer 2.2 ActiveX control (comparerax.ocx) allows remote attackers to execute arbitrary code via… | Patch early | 9.3 high | 7% | 2007-05-14 |
| CVE-2015-6763 EXP | Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service or possibly have other impact v… | Patch early | 7.5 high | 7% | 2015-10-15 |
| CVE-2013-4859 EXP | INSTEON Hub 2242-222 lacks Web and API authentication | Patch early | 8.1 high | 7% | 2019-12-27 |
| CVE-2001-1104 EXP | SonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions. | Patch early | 7.5 high | 7% | 2001-07-25 |
| CVE-2014-4688 EXP | pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_dns.php in a Create Alias acti… | Patch early | 6.5 medium | 7% | 2014-07-02 |
| CVE-2017-15270 EXP | The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) file. This can be used by attac… | Patch early | 5.3 medium | 7% | 2017-11-15 |
| CVE-2001-1491 EXP | Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images. | Patch early | 5.0 medium | 7% | 2001-12-31 |
| CVE-2002-1811 EXP | Belkin F5D6130 Wireless Network Access Point running firmware AP14G8 allows remote attackers to cause a denial of service (connection loss) by sending… | Patch early | 5.0 medium | 7% | 2002-12-31 |
| CVE-2008-6960 EXP | download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url p… | Patch early | 5.0 medium | 7% | 2009-08-12 |
| CVE-2006-5250 EXP | PHP remote file inclusion vulnerability in lib/googlesearch/GoogleSearch.php in BlueShoes 4.6_public and earlier allows remote attackers to execute ar… | Patch early | 5.1 medium | 7% | 2006-10-12 |
| CVE-2000-0526 EXP | mailview.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 5.0 medium | 7% | 2000-06-09 |
| CVE-2009-4493 EXP | Orion Application Server 2.0.7 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a w… | Patch early | 5.0 medium | 7% | 2010-01-13 |
| CVE-2007-0643 EXP | Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of service (application crash) and po… | Patch early | 4.3 medium | 7% | 2007-01-31 |
| CVE-2007-4067 EXP | Absolute path traversal vulnerability in the clInetSuiteX6.clWebDav ActiveX control in CLINETSUITEX6.OCX in Clever Internet ActiveX Suite 6.2 allows r… | Patch early | 9.3 high | 7% | 2007-07-30 |
| CVE-2013-0143 EXP | cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authent… | Patch early | 6.5 medium | 7% | 2013-06-07 |
| CVE-1999-0931 EXP | Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands. | Patch early | 5.0 medium | 7% | 1999-09-30 |
| CVE-2004-2719 EXP | Buffer overflow in the UrlToLocal function in PunyLib.dll of Foxmail 5.0.300 allows remote attackers to execute arbitrary code via a mail message with… | Patch early | 6.8 medium | 7% | 2004-12-31 |
| CVE-2017-3316 EXP | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions that are affected are VirtualBox… | Patch early | 8.4 high | 7% | 2017-01-27 |
| CVE-2019-10652 EXP | An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .php files, related to the addon… | Patch early | 7.2 high | 7% | 2019-03-30 |
| CVE-2017-2363 EXP | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. wa… | Patch early | 6.5 medium | 7% | 2017-02-20 |
| CVE-2003-1548 EXP | MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other parameter, which reveals the i… | Patch early | 5.0 medium | 7% | 2003-12-31 |
| CVE-2002-1501 EXP | The MPS functionality in Enterasys SSR8000 (Smart Switch Router) before firmware 8.3.0.10 allows remote attackers to cause a denial of service (crash)… | Patch early | 5.0 medium | 7% | 2003-04-02 |
| CVE-2015-7896 EXP | LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via… | Patch early | 6.5 medium | 7% | 2017-08-24 |
| CVE-2006-4885 EXP | PHP remote file inclusion vulnerability in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ro… | Patch early | 7.5 high | 7% | 2006-09-19 |
| CVE-2006-4904 EXP | Dynamic variable evaluation vulnerability in cmpi.php in Qualiteam X-Cart 4.1.3 and earlier allows remote attackers to overwrite arbitrary program var… | Patch early | 7.5 high | 7% | 2006-09-21 |
| CVE-2006-4921 EXP | PHP remote file inclusion vulnerability in Site@School (S@S) 2.4.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 7% | 2006-09-21 |
| CVE-2007-6113 EXP | Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) 0.10.12 to 0.99.6 allows remote attackers to cause a denial of service… | Patch early | 4.3 medium | 7% | 2007-11-23 |
| CVE-2014-2399 EXP | Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unkn… | Patch early | 4.3 medium | 7% | 2014-04-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt