CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,240 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-4588 EXP | Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a denial of service (daemon crash) a… | Patch early | 10.0 high | 6.8% | 2008-10-15 |
| CVE-2007-2187 EXP | Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long DNS response. NOTE: this might… | Patch early | 10.0 high | 6.8% | 2007-04-24 |
| CVE-2006-3061 EXP | Multiple cross-site scripting (XSS) vulnerabilities in 5 Star Review allow remote attackers to inject arbitrary web script or HTML via the (1) sort pa… | Patch early | 2.6 low | 6.8% | 2006-06-19 |
| CVE-2017-2527 EXP | An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "CoreAnimation" component. It allows remot… | Patch early | 9.8 critical | 6.8% | 2017-05-22 |
| CVE-2020-8865 EXP | This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authenticat… | Patch early | 6.3 medium | 6.8% | 2020-03-23 |
| CVE-2008-3592 EXP | Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers… | Patch early | 8.5 high | 6.8% | 2008-08-11 |
| CVE-2007-3957 EXP | Buffer overflow in Nipun Jain xserver 0.1 alpha allows remote attackers to cause a denial of service via a POST request with a long URI. | Patch early | 5.0 medium | 6.8% | 2007-07-24 |
| CVE-2005-2846 EXP | PHP remote file inclusion vulnerability in lang.php in CMS Made Simple 0.10 and earlier allows remote attackers to execute arbitrary PHP code via the… | Patch early | 7.5 high | 6.8% | 2005-09-08 |
| CVE-2012-6509 EXP | Unrestricted file upload vulnerability in NetArt Media Car Portal 3.0 allows remote attackers to execute arbitrary PHP code by uploading a file a doub… | Patch early | 7.5 high | 6.8% | 2013-01-24 |
| CVE-2006-6767 EXP | oftpd before 0.3.7 allows remote attackers to cause a denial of service (daemon abort) via a (1) LPRT or (2) LPASV command with an unsupported address… | Patch early | 7.5 high | 6.8% | 2007-01-16 |
| CVE-2018-10653 EXP | There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | Patch early | 9.8 critical | 6.8% | 2018-05-23 |
| CVE-2017-6060 EXP | Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to have unspecified impact via… | Patch early | 7.8 high | 6.8% | 2017-03-15 |
| CVE-2006-2310 EXP | BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to cause a denial of service (hang) via a request for a .cfm file whose… | Patch early | 5.0 medium | 6.8% | 2006-06-26 |
| CVE-2008-1052 EXP | The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large… | Patch early | 6.4 medium | 6.8% | 2008-02-27 |
| CVE-2008-6423 EXP | Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and earlier allows remote attackers to read arbitrary local files via a .. (d… | Patch early | 5.0 medium | 6.8% | 2009-03-06 |
| CVE-2006-2745 EXP | Multiple PHP remote file inclusion vulnerabilities in F@cile Interactive Web 0.8.5 and earlier, when register_globals is enabled, allow remote attacke… | Patch early | 5.1 medium | 6.8% | 2006-06-01 |
| CVE-2014-1908 EXP | The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugi… | Patch early | 5.0 medium | 6.8% | 2014-12-29 |
| CVE-2026-34156 EXP | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's W… | Patch early | 9.9 critical | 6.8% | 2026-03-31 |
| CVE-2003-1242 EXP | Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path in an error… | Patch early | 5.0 medium | 6.8% | 2003-12-31 |
| CVE-2002-1818 EXP | ezhttpbench.php in eZ httpbench 1.1 allows remote attackers to read arbitrary files via a full pathname in the AnalyseSite parameter. | Patch early | 5.0 medium | 6.8% | 2002-12-31 |
| CVE-2013-6835 EXP | TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remote… | Patch early | 5.0 medium | 6.8% | 2014-03-14 |
| CVE-2017-2460 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 6.8% | 2017-04-02 |
| CVE-1999-0934 EXP | classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters. | Patch early | 5.0 medium | 6.8% | 1999-12-15 |
| CVE-2015-1389 EXP | Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote attackers to inject arbitrary we… | Patch early | 4.3 medium | 6.8% | 2015-05-28 |
| CVE-2009-2557 EXP | Directory traversal vulnerability in system/download.php in Admin News Tools 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in… | Patch early | 5.0 medium | 6.8% | 2009-07-21 |
| CVE-2017-15639 EXP | tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature. | Patch early | 6.5 medium | 6.8% | 2017-10-19 |
| CVE-2008-1136 EXP | The Utils::runScripts function in src/utils.cpp in vdccm 0.92 through 0.10.0 in SynCE (SynCE-dccm) allows remote attackers to execute arbitrary comman… | Patch early | 9.3 high | 6.8% | 2008-03-04 |
| CVE-2006-5308 EXP | Multiple PHP remote file inclusion vulnerabilities in Open Conference Systems (OCS) before 1.1.6 allow remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 6.8% | 2006-10-17 |
| CVE-2006-2875 EXP | Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remote attacker… | Patch early | 7.5 high | 6.8% | 2006-06-07 |
| CVE-2003-0488 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) the add_na… | Patch early | 5.1 medium | 6.8% | 2003-08-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt