CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,373 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-5172 EXP | Stack-based buffer overflow in StoryBoard Quick 6 Build 3786, and possibly StoryBoard Artist and StoryBoard Studio, allows remote attackers to execute… | Patch early | 9.3 high | 6.4% | 2012-09-15 |
| CVE-2008-0632 EXP | Unrestricted file upload vulnerability in cp_upload_image.php in LightBlog 9.5 allows remote attackers to execute arbitrary code by uploading a file w… | Patch early | 9.3 high | 6.4% | 2008-02-06 |
| CVE-2012-0025 EXP | Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for Irfan… | Patch early | 6.8 medium | 6.4% | 2012-11-02 |
| CVE-2008-6955 EXP | mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configurati… | Patch early | 7.5 high | 6.4% | 2009-08-12 |
| CVE-2008-2338 EXP | Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified scripts i… | Patch early | 7.5 high | 6.4% | 2008-05-19 |
| CVE-2007-6668 EXP | admin/uploadgames.php in MySpace Content Zone (MCZ) 3.x does not require administrative privileges, which allows remote attackers to perform unrestric… | Patch early | 7.5 high | 6.4% | 2008-01-08 |
| CVE-2008-5897 EXP | CodeAvalanche FreeWallpaper stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa… | Patch early | 7.5 high | 6.4% | 2009-01-12 |
| CVE-2008-5898 EXP | CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download th… | Patch early | 7.5 high | 6.4% | 2009-01-12 |
| CVE-2008-5899 EXP | CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download t… | Patch early | 7.5 high | 6.4% | 2009-01-12 |
| CVE-2008-5900 EXP | CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… | Patch early | 7.5 high | 6.4% | 2009-01-12 |
| CVE-2009-4091 EXP | comments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers to edit or delete comments via… | Patch early | 5.0 medium | 6.4% | 2009-11-29 |
| CVE-2001-1490 EXP | Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images. | Patch early | 5.0 medium | 6.4% | 2001-12-31 |
| CVE-2006-2516 EXP | mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite variables such as $xoopsOption['noc… | Patch early | 5.1 medium | 6.4% | 2006-05-22 |
| CVE-2009-3643 EXP | Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote attackers to cause a denial of service via a long argument to the (1) LIST and (2) NLST comman… | Patch early | 5.0 medium | 6.4% | 2009-10-09 |
| CVE-2008-6752 EXP | adminlogin/password.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging does not verify the original password before changing passwords,… | Patch early | 7.5 high | 6.3% | 2009-04-24 |
| CVE-2019-8927 EXP | An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfi… | Patch early | 6.1 medium | 6.3% | 2019-05-17 |
| CVE-2013-2682 EXP | Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information. | Patch early | 4.3 medium | 6.3% | 2020-02-05 |
| CVE-2012-4600 EXP | Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x before 3.0.16, and 3.1.x before 3.1… | Patch early | 2.6 low | 6.3% | 2012-08-31 |
| CVE-2010-5194 EXP | Stack-based buffer overflow in the Image2PDF function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageViewer2.ocx) in Viscom Image Viewer CP Pro… | Patch early | 9.3 high | 6.3% | 2012-08-31 |
| CVE-2015-8612 EXP | The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users to gain privileges via the dh… | Patch early | 8.4 high | 6.3% | 2016-01-08 |
| CVE-2021-45814 EXP | Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an administrative account… | Patch early | 9.8 critical | 6.3% | 2021-12-28 |
| CVE-2008-7240 EXP | Directory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows remote attackers to include and e… | Patch early | 7.5 high | 6.3% | 2009-09-17 |
| CVE-2007-6537 EXP | Stack-based buffer overflow in the zfile_gunzip function in zfile.c in WinUAE 1.4.4 and earlier allows user-assisted remote attackers to execute arbit… | Patch early | 6.8 medium | 6.3% | 2007-12-27 |
| CVE-2020-14944 EXP | Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeov… | Patch early | 9.8 critical | 6.3% | 2020-06-22 |
| CVE-2005-3010 EXP | Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers… | Patch early | 7.5 high | 6.3% | 2005-09-21 |
| CVE-2009-0572 EXP | PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enab… | Patch early | 5.1 medium | 6.3% | 2009-02-13 |
| CVE-2000-0146 EXP | The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service via a long URL to the servlet… | Patch early | 5.0 medium | 6.3% | 2000-02-07 |
| CVE-2002-1910 EXP | Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtai… | Patch early | 7.5 high | 6.3% | 2002-12-31 |
| CVE-2017-2479 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affect… | Patch early | 6.5 medium | 6.3% | 2017-04-02 |
| CVE-2014-3146 EXP | Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) at… | Patch early | 6.1 medium | 6.3% | 2014-05-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt