CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,603 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-0229 EXP | The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of servic… | Patch early | 7.8 high | 76.4% | 2013-01-31 |
| CVE-2009-1979 EXP | Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confident… | Patch early | 10.0 high | 76.4% | 2009-10-22 |
| CVE-2010-4417 EXP | Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2.0.1.2.1, and 2.0.1.3 allows r… | Patch early | 7.5 high | 76.3% | 2011-01-19 |
| CVE-2014-5073 EXP | vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands via shell metacharacters in th… | Patch early | 7.5 high | 76.3% | 2014-08-29 |
| CVE-2021-22145 EXP | A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary querie… | Patch early | 6.5 medium | 76.2% | 2021-07-21 |
| CVE-2007-0042 EXP | Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers… | Patch early | 7.8 high | 76.2% | 2007-07-10 |
| CVE-2013-1391 EXP | Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allow… | Patch early | 7.5 high | 76.1% | 2019-10-30 |
| CVE-2023-4220 EXP | Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows… | Patch early | 8.1 high | 76.1% | 2023-11-28 |
| CVE-2023-38836 EXP | File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks. | Patch early | 8.8 high | 76% | 2023-08-21 |
| CVE-2002-1142 EXP | Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explor… | Patch early | 7.5 high | 76% | 2002-11-29 |
| CVE-2013-5486 EXP | Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows re… | Patch early | 10.0 high | 76% | 2013-09-23 |
| CVE-2007-4880 EXP | Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.… | Patch early | 10.0 high | 75.9% | 2007-09-28 |
| CVE-2018-8065 EXP | An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access violation on the syncbrs.exe me… | Patch early | 7.5 high | 75.9% | 2018-03-12 |
| CVE-2008-1232 EXP | Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers… | Patch early | 4.3 medium | 75.9% | 2008-08-04 |
| CVE-2019-1937 EXP | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Di… | Patch early | 9.8 critical | 75.9% | 2019-08-21 |
| CVE-2009-4140 EXP | Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0.2.35 thro… | Patch early | 7.5 high | 75.8% | 2009-12-22 |
| CVE-2006-2447 EXP | SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafte… | Patch early | 5.1 medium | 75.8% | 2006-06-06 |
| CVE-2012-5959 EXP | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… | Patch early | 10.0 high | 75.8% | 2013-01-31 |
| CVE-2009-0837 EXP | Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to execute arbitrary code via a lo… | Patch early | 10.0 high | 75.8% | 2009-03-10 |
| CVE-2017-1092 EXP | IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servers. IBM X… | Patch early | 9.8 critical | 75.8% | 2017-05-22 |
| CVE-2010-2550 EXP | The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Win… | Patch early | 10.0 high | 75.7% | 2010-08-11 |
| CVE-2022-2884 EXP | A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated… | Patch early | 9.9 critical | 75.7% | 2022-10-17 |
| CVE-2004-0847 EXP | The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted director… | Patch early | 9.8 critical | 75.7% | 2004-11-03 |
| CVE-2014-9735 EXP | The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not proper… | Patch early | 7.5 high | 75.7% | 2015-06-30 |
| CVE-2011-2371 EXP | Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey thro… | Patch early | 10.0 high | 75.7% | 2011-06-30 |
| CVE-2022-1162 EXP | A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7… | Patch early | 9.1 critical | 75.6% | 2022-04-04 |
| CVE-2010-2729 EXP | The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and… | Patch early | 9.3 high | 75.6% | 2010-09-15 |
| CVE-2018-9160 EXP | SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses. | Patch early | 9.8 critical | 75.6% | 2018-03-31 |
| CVE-2022-32429 EXP | An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 all… | Patch early | 9.8 critical | 75.6% | 2022-08-10 |
| CVE-2010-3275 EXP | libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an AMV file,… | Patch early | 9.3 high | 75.5% | 2011-03-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt