CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,370 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-5227 EXP | QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format… | Patch early | 7.5 high | 6.4% | 2017-03-23 |
| CVE-2012-2997 EXP | XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 through 10.2.4 and 11.0.0 through 11.2.1 allows re… | Patch early | 4.0 medium | 6.4% | 2014-01-21 |
| CVE-2000-0482 EXP | Check Point Firewall-1 allows remote attackers to cause a denial of service by sending a large number of malformed fragmented IP packets. | Patch early | 5.0 medium | 6.4% | 2000-06-06 |
| CVE-2006-6558 EXP | Crob FTP Server 3.6.1 b.263 allows remote attackers to cause a denial of service via a long series of "?A" sequences in the (1) LIST and possibly (2)… | Patch early | 5.0 medium | 6.4% | 2006-12-14 |
| CVE-2009-3272 EXP | Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2, allows remote attackers to ca… | Patch early | 5.0 medium | 6.4% | 2009-09-21 |
| CVE-2020-27423 EXP | Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legiti… | Patch early | 7.5 high | 6.4% | 2020-11-16 |
| CVE-2012-4515 EXP | Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers… | Patch early | 6.8 medium | 6.4% | 2012-11-11 |
| CVE-2007-0148 EXP | Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary c… | Patch early | 6.8 medium | 6.4% | 2007-01-09 |
| CVE-2009-4987 EXP | admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative access by setting… | Patch early | 7.5 high | 6.4% | 2010-08-25 |
| CVE-2013-3803 EXP | Unspecified vulnerability in the Hyperion BI+ component in Oracle Hyperion 11.1.1.3, 11.1.1.4.107 and earlier, 11.1.2.1.129 and earlier, and 11.1.2.2.… | Patch early | 3.5 low | 6.4% | 2013-07-17 |
| CVE-2011-4042 EXP | An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute ar… | Patch early | 9.3 high | 6.4% | 2012-04-03 |
| CVE-2020-7656 EXP | jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that… | Patch early | 6.1 medium | 6.4% | 2020-05-19 |
| CVE-2006-0138 EXP | aMSN (aka Alvaro's Messenger) allows remote attackers to cause a denial of service (client hang and termination of client's instant-messaging session)… | Patch early | 5.0 medium | 6.4% | 2006-01-09 |
| CVE-2008-4918 EXP | Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote… | Patch early | 4.3 medium | 6.4% | 2008-11-04 |
| CVE-2008-6996 EXP | Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for remote attackers or malware to ca… | Patch early | 5.0 medium | 6.4% | 2009-08-19 |
| CVE-2001-0566 EXP | Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when SNMP is disa… | Patch early | 5.0 medium | 6.4% | 2001-08-14 |
| CVE-2009-3717 EXP | Heap-based buffer overflow in LucVil PatPlayer 3.9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long U… | Patch early | 9.3 high | 6.4% | 2009-10-16 |
| CVE-2007-2827 EXP | Heap-based buffer overflow in LEAD Technologies LEADTOOLS ISIS ActiveX Control (ltisi14E.ocx) 14.5.0.44 and earlier allows remote attackers to execute… | Patch early | 9.3 high | 6.4% | 2007-05-22 |
| CVE-2007-2981 EXP | Buffer overflow in a certain ActiveX control in LEAD Technologies LEADTOOLS Raster OCR Document Object Library (ltrdc14e.dll) 14.5.0.44 allows remote… | Patch early | 9.3 high | 6.4% | 2007-06-01 |
| CVE-2006-6295 EXP | PHP remote file inclusion vulnerability in includes/mx_common.php in the mx_tinies 1.3.0 Module for MxBB Portal 1.06 allows remote attackers to execut… | Patch early | 6.8 medium | 6.4% | 2006-12-05 |
| CVE-2006-5714 EXP | Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary files under the web root by app… | Patch early | 5.0 medium | 6.4% | 2006-11-04 |
| CVE-2006-5715 EXP | Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrary files under the web root by… | Patch early | 5.0 medium | 6.4% | 2006-11-04 |
| CVE-2008-5965 EXP | Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to check for t… | Patch early | 5.0 medium | 6.4% | 2009-01-26 |
| CVE-2013-1464 EXP | Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to injec… | Patch early | 4.3 medium | 6.4% | 2013-02-07 |
| CVE-2000-0848 EXP | Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header. | Patch early | 10.0 high | 6.4% | 2000-11-14 |
| CVE-2018-15536 EXP | /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extrac… | Patch early | 5.5 medium | 6.4% | 2018-08-24 |
| CVE-2018-13110 EXP | All ADB broadband gateways / routers based on the Epicentro platform are affected by a privilege escalation vulnerability where attackers can gain acc… | Patch early | 7.5 high | 6.4% | 2018-07-06 |
| CVE-2008-7161 EXP | Fortinet FortiGuard Fortinet FortiGate-1000 3.00 build 040075,070111 allows remote attackers to bypass URL filtering via fragmented GET or POST reques… | Patch early | 7.5 high | 6.4% | 2009-09-04 |
| CVE-2015-1494 EXP | The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site sc… | Patch early | 4.3 medium | 6.4% | 2015-02-17 |
| CVE-2003-0371 EXP | Buffer overflow in Prishtina FTP client 1.x allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a l… | Patch early | 7.5 high | 6.4% | 2003-06-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt