CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,237 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-0319 EXP | Directory traversal vulnerability in the FTP server (port 22003/tcp) in Farmers WIFE 4.4 SP1 allows remote attackers to create arbitrary files via "..… | Patch early | 5.0 medium | 6.9% | 2006-01-19 |
| CVE-2006-3556 EXP | PHP remote file inclusion vulnerability in extcalendar.php in Mohamed Moujami ExtCalendar 2.0 allows remote attackers to execute arbitrary PHP code vi… | Patch early | 6.8 medium | 6.9% | 2006-07-13 |
| CVE-2005-2767 EXP | Buffer overflow in LeapFTP allows remote attackers to execute arbitrary code via a long Host string in a Site Queue (.lsq) file. | Patch early | 7.5 high | 6.9% | 2005-09-02 |
| CVE-2010-3136 EXP | Untrusted search path vulnerability in Skype 4.2.0.169 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and co… | Patch early | 9.3 high | 6.9% | 2010-08-26 |
| CVE-2018-5715 EXP | phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable). | Patch early | 6.1 medium | 6.9% | 2018-01-16 |
| CVE-2018-10255 EXP | A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command th… | Patch early | 8.8 high | 6.9% | 2018-05-01 |
| CVE-2002-1463 EXP | Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/1200/1300, and Gateway Security 5… | Patch early | 7.5 high | 6.9% | 2003-06-09 |
| CVE-2015-6639 EXP | The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted… | Patch early | 7.8 high | 6.9% | 2016-01-06 |
| CVE-2018-4240 EXP | An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchO… | Patch early | 6.5 medium | 6.9% | 2018-06-08 |
| CVE-2000-0780 EXP | The web server in IPSWITCH IMail 6.04 and earlier allows remote attackers to read and delete arbitrary files via a .. (dot dot) attack. | Patch early | 6.4 medium | 6.9% | 2000-10-20 |
| CVE-2008-3285 EXP | The Filesys::SmbClientParser module 2.7 and earlier for Perl allows remote SMB servers to execute arbitrary code via a folder name containing shell me… | Patch early | 9.3 high | 6.9% | 2008-07-24 |
| CVE-2016-1594 EXP | Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as dem… | Patch early | 6.5 medium | 6.9% | 2016-04-22 |
| CVE-2018-13980 EXP | The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser… | Patch early | 5.5 medium | 6.9% | 2018-07-16 |
| CVE-2006-0658 EXP | Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload an… | Patch early | 5.0 medium | 6.9% | 2006-02-13 |
| CVE-1999-0174 EXP | The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 6.4 medium | 6.9% | 1997-02-01 |
| CVE-2011-2201 EXP | The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of d… | Patch early | 4.3 medium | 6.9% | 2011-09-14 |
| CVE-2016-8017 EXP | Special element injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers… | Patch early | 4.1 medium | 6.9% | 2017-03-14 |
| CVE-2014-3975 EXP | Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via a full pathname in the viewdir… | Patch early | 5.0 medium | 6.9% | 2014-06-05 |
| CVE-2014-9436 EXP | Absolute path traversal vulnerability in SysAid On-Premise before 14.4.2 allows remote attackers to read arbitrary files via a \\\\ (four backslashes)… | Patch early | 5.0 medium | 6.9% | 2015-01-02 |
| CVE-2008-6280 EXP | Cross-site scripting (XSS) vulnerability in apply.cgi on the Linksys WRT160N allows remote attackers to inject arbitrary web script or HTML via the ac… | Patch early | 4.3 medium | 6.9% | 2009-02-25 |
| CVE-2003-1240 EXP | PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in… | Patch early | 7.5 high | 6.9% | 2003-12-31 |
| CVE-2012-0550 EXP | Unspecified vulnerability in the GlassFish Enterprise Server component in Oracle Sun Products Suite GlassFish Enterprise Server 3.1.1 allows remote at… | Patch early | 6.8 medium | 6.9% | 2012-05-03 |
| CVE-2019-8624 EXP | An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5.3. A remote attacker may be able to leak memory. | Patch early | 7.5 high | 6.9% | 2019-12-18 |
| CVE-2008-4048 EXP | Heap-based buffer overflow in a certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remot… | Patch early | 6.8 medium | 6.9% | 2008-09-11 |
| CVE-2008-4729 EXP | Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Control 13.0 and earlier allows re… | Patch early | 6.8 medium | 6.9% | 2008-10-24 |
| CVE-2015-7248 EXP | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password hashes by reading the cgi-bin/we… | Patch early | 7.5 high | 6.9% | 2015-12-30 |
| CVE-2009-3812 EXP | Heap-based buffer overflow in OtsAV DJ trial version 1.85.64.0, Radio trial version 1.85.64.0, TV trial version 1.85.64.0, and Free version 1.77.001 a… | Patch early | 9.3 high | 6.9% | 2009-10-27 |
| CVE-2010-2932 EXP | Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary code via a long argument to t… | Patch early | 9.3 high | 6.9% | 2010-08-05 |
| CVE-2009-0812 EXP | Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions allows remote attackers to execut… | Patch early | 9.3 high | 6.9% | 2009-03-04 |
| CVE-2013-2642 EXP | Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to t… | Patch early | 9.3 high | 6.9% | 2014-03-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt