CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,648 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-14696 EXP | Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter. | Patch early | 6.1 medium | 15.7% | 2019-08-06 |
| CVE-2008-3443 EXP | The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows re… | Patch early | 5.0 medium | 15.7% | 2008-08-14 |
| CVE-2007-2356 EXP | Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attackers to e… | Patch early | 6.8 medium | 15.7% | 2007-04-30 |
| CVE-2009-1335 EXP | Microsoft Internet Explorer 7 and 8 on Windows XP and Vista allows remote attackers to cause a denial of service (application hang) via a large docume… | Patch early | 4.3 medium | 15.7% | 2009-04-17 |
| CVE-2007-5219 EXP | Directory traversal vulnerability in the CLAVSetting.CLSetting.1 ActiveX control in CLAVSetting.DLL 1.00.1829 in the CLAVSetting module in CyberLink P… | Patch early | 6.4 medium | 15.7% | 2007-10-05 |
| CVE-2014-9119 EXP | Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary file… | Patch early | 5.0 medium | 15.7% | 2014-12-31 |
| CVE-2009-0991 EXP | Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to… | Patch early | 5.0 medium | 15.6% | 2009-04-15 |
| CVE-2018-8719 EXP | An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not res… | Patch early | 5.3 medium | 15.6% | 2018-04-04 |
| CVE-2006-3340 EXP | Multiple PHP remote file inclusion vulnerabilities in Pearl For Mambo module 1.6 for Mambo, when register_globals is enabled, allow remote attackers t… | Patch early | 5.1 medium | 15.6% | 2006-07-03 |
| CVE-2006-2864 EXP | Multiple PHP remote file inclusion vulnerabilities in BlueShoes Framework 4.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1… | Patch early | 5.1 medium | 15.6% | 2006-06-06 |
| CVE-2010-0187 EXP | Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow remote attackers to cause a denial of service (application crash) via a modi… | Patch early | 4.3 medium | 15.6% | 2010-02-15 |
| CVE-2006-6421 EXP | Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to i… | Patch early | 6.0 medium | 15.6% | 2006-12-10 |
| CVE-2012-0874 EXP | The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EW… | Patch early | 6.8 medium | 15.6% | 2013-02-05 |
| CVE-2010-1601 EXP | Directory traversal vulnerability in the JA Comment (com_jacomment) component for Joomla! allows remote attackers to read arbitrary files via a .. (do… | Patch early | 5.0 medium | 15.6% | 2010-04-29 |
| CVE-2008-2138 EXP | Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/po… | Patch early | 5.0 medium | 15.5% | 2008-05-12 |
| CVE-2019-3778 EXP | Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported ver… | Patch early | 6.5 medium | 15.5% | 2019-03-07 |
| CVE-2007-0103 EXP | The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknown impact, possibly including d… | Patch early | 6.8 medium | 15.5% | 2007-01-09 |
| CVE-2020-28978 EXP | The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and e… | Patch early | 5.3 medium | 15.4% | 2020-11-30 |
| CVE-2020-28977 EXP | The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and e… | Patch early | 5.3 medium | 15.4% | 2020-11-30 |
| CVE-2014-1778 EXP | Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, ak… | Patch early | 6.8 medium | 15.4% | 2014-06-11 |
| CVE-2007-2237 EXP | Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO fil… | Patch early | 5.5 medium | 15.4% | 2007-06-06 |
| CVE-2008-2841 EXP | Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary… | Patch early | 6.8 medium | 15.4% | 2008-06-24 |
| CVE-2008-6668 EXP | Multiple directory traversal vulnerabilities in nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1… | Patch early | 5.0 medium | 15.3% | 2009-04-08 |
| CVE-2005-1477 EXP | The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute… | Patch early | 5.1 medium | 15.2% | 2005-05-09 |
| CVE-2006-5864 EXP | Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to exec… | Patch early | 5.1 medium | 15.2% | 2006-11-11 |
| CVE-2008-3790 EXP | The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (C… | Patch early | 5.0 medium | 15.2% | 2008-08-27 |
| CVE-2025-9090 EXP | A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet S… | Patch early | 6.3 medium | 15.2% | 2025-08-17 |
| CVE-2012-4409 EXP | Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to execute ar… | Patch early | 6.8 medium | 15.1% | 2012-11-21 |
| CVE-2017-8644 EXP | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that… | Patch early | 4.3 medium | 15.1% | 2017-08-08 |
| CVE-2010-4645 EXP | strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to… | Patch early | 5.0 medium | 15.1% | 2011-01-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt