CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,612 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-1603 EXP | An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DC… | Patch early | 5.3 medium | 16.1% | 2020-01-28 |
| CVE-2009-1872 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 16.1% | 2009-08-18 |
| CVE-2021-24276 EXP | The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribu… | Patch early | 6.1 medium | 16% | 2021-05-05 |
| CVE-2017-14016 EXP | A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of… | Patch early | 6.3 medium | 16% | 2017-11-06 |
| CVE-2004-2090 EXP | Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture metho… | Patch early | 5.0 medium | 16% | 2004-02-07 |
| CVE-2010-1658 EXP | Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remote attackers to read arbitrary… | Patch early | 5.0 medium | 16% | 2010-05-03 |
| CVE-2020-28351 EXP | The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting… | Patch early | 6.1 medium | 16% | 2020-11-09 |
| CVE-2024-8945 EXP | A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulnerability affects unknown code o… | Patch early | 5.5 medium | 16% | 2024-09-17 |
| CVE-2017-0060 EXP | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 201… | Patch early | 5.5 medium | 15.9% | 2017-03-17 |
| CVE-2001-0336 EXP | The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request. | Patch early | 5.0 medium | 15.9% | 2001-06-27 |
| CVE-2010-0943 EXP | Directory traversal vulnerability in the JA Showcase (com_jashowcase) component for Joomla! allows remote attackers to read arbitrary files via a .. (… | Patch early | 5.0 medium | 15.9% | 2010-03-08 |
| CVE-2005-3299 EXP | PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__r… | Patch early | 5.0 medium | 15.9% | 2005-10-23 |
| CVE-2010-1314 EXP | Directory traversal vulnerability in the Highslide JS (com_hsconfig) component 1.5 and 2.0.9 for Joomla! allows remote attackers to read arbitrary fil… | Patch early | 5.0 medium | 15.9% | 2010-04-08 |
| CVE-2010-1354 EXP | Directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .… | Patch early | 5.0 medium | 15.9% | 2010-04-12 |
| CVE-2018-9842 EXP | CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message. | Patch early | 5.3 medium | 15.9% | 2018-04-12 |
| CVE-2009-3898 EXP | Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows rem… | Patch early | 4.9 medium | 15.9% | 2009-11-24 |
| CVE-2024-30269 EXP | DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0.… | Patch early | 5.3 medium | 15.9% | 2024-04-08 |
| CVE-2005-1524 EXP | PHP file inclusion vulnerability in top_graph_header.php in Cacti 0.8.6d and possibly earlier versions allows remote attackers to execute arbitrary PH… | Patch early | 5.0 medium | 15.9% | 2005-06-22 |
| CVE-2011-0518 EXP | Directory traversal vulnerability in core/lib/router.php in LotusCMS Fraise 3.0, when magic_quotes_gpc is disabled, allows remote attackers to include… | Patch early | 5.1 medium | 15.8% | 2011-01-20 |
| CVE-2007-3855 EXP | Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to have… | Patch early | 6.5 medium | 15.8% | 2007-07-18 |
| CVE-2009-0543 EXP | ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte c… | Patch early | 6.8 medium | 15.8% | 2009-02-12 |
| CVE-2006-6310 EXP | Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash) via an invalid src attribute value ("?")… | Patch early | 5.0 medium | 15.8% | 2006-12-06 |
| CVE-2021-46379 EXP | DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site. | Patch early | 6.1 medium | 15.8% | 2022-03-04 |
| CVE-2004-0173 EXP | Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read… | Patch early | 5.0 medium | 15.8% | 2004-04-15 |
| CVE-2002-0862 EXP | The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products includi… | Patch early | 6.8 medium | 15.8% | 2002-10-04 |
| CVE-2015-3623 EXP | XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forgery (SSRF) a… | Patch early | 6.4 medium | 15.8% | 2015-09-16 |
| CVE-2006-5048 EXP | Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier for Joomla! allow remote attack… | Patch early | 6.8 medium | 15.8% | 2006-09-27 |
| CVE-2004-1325 EXP | The getItemInfoByAtom function in the ActiveX control for Microsoft Windows Media Player 9.0 returns a 0 if the file does not exist and the size of th… | Patch early | 5.0 medium | 15.7% | 2004-12-18 |
| CVE-2008-4327 EXP | gdiplus.dll in GDI+ in Microsoft Windows XP SP3 does not properly handle crafted .ico files, which allows remote attackers to cause a denial of servic… | Patch early | 4.3 medium | 15.7% | 2008-09-30 |
| CVE-2000-0200 EXP | Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art l… | Patch early | 5.1 medium | 15.7% | 2000-03-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt