CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,692 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-1487 EXP | The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by sending the raw messages (1) 2… | Patch early | 5.0 medium | 13.6% | 2003-04-02 |
| CVE-2002-1522 EXP | Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute ar… | Patch early | 5.0 medium | 13.6% | 2003-04-02 |
| CVE-2006-2686 EXP | PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[AA_INC_PAT… | Patch early | 6.4 medium | 13.6% | 2006-05-31 |
| CVE-2020-11027 EXP | In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to… | Patch early | 6.1 medium | 13.6% | 2020-04-30 |
| CVE-2010-1340 EXP | Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote attackers to read arbitrary f… | Patch early | 5.0 medium | 13.6% | 2010-04-09 |
| CVE-2010-1534 EXP | Directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (d… | Patch early | 5.0 medium | 13.6% | 2010-04-26 |
| CVE-2010-1858 EXP | Directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote attackers to read arbitrary files… | Patch early | 5.0 medium | 13.6% | 2010-05-07 |
| CVE-2010-1312 EXP | Directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote attackers to read arbitrary f… | Patch early | 5.0 medium | 13.6% | 2010-04-08 |
| CVE-2008-4787 EXP | Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a URL with a hostname containing… | Patch early | 5.8 medium | 13.6% | 2008-10-29 |
| CVE-2010-1352 EXP | Directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote attackers to read arbitrary fi… | Patch early | 5.0 medium | 13.6% | 2010-04-12 |
| CVE-2010-1491 EXP | Directory traversal vulnerability in the MMS Blog (com_mmsblog) component 2.3.0 for Joomla! allows remote attackers to read arbitrary files and possib… | Patch early | 5.0 medium | 13.6% | 2010-04-23 |
| CVE-2006-3121 EXP | The peel_netstring function in cl_netstring.c in the heartbeat subsystem in High-Availability Linux before 1.2.5, and 2.0 before 2.0.7, allows remote… | Patch early | 5.0 medium | 13.6% | 2006-08-17 |
| CVE-2006-0179 EXP | The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary p… | Patch early | 5.0 medium | 13.6% | 2006-01-11 |
| CVE-1999-0140 EXP | Denial of service in RAS/PPTP on NT systems. | Patch early | 5.0 medium | 13.6% | 1999-06-30 |
| CVE-2006-4227 EXP | MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine… | Patch early | 6.5 medium | 13.6% | 2006-08-18 |
| CVE-2014-5465 EXP | Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress allows remote attackers to re… | Patch early | 5.0 medium | 13.5% | 2014-09-03 |
| CVE-2006-3210 EXP | Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers to conduct PHP remote file inc… | Patch early | 5.1 medium | 13.5% | 2006-06-24 |
| CVE-2011-0421 EXP | The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argume… | Patch early | 4.3 medium | 13.5% | 2011-03-20 |
| CVE-2005-1267 EXP | The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attacker… | Patch early | 5.0 medium | 13.5% | 2005-06-10 |
| CVE-2005-0815 EXP | Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corr… | Patch early | 6.4 medium | 13.4% | 2005-05-02 |
| CVE-2005-3737 EXP | Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute arbitrary code via a SVG file… | Patch early | 5.1 medium | 13.4% | 2005-11-22 |
| CVE-1999-0196 EXP | websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variabl… | Patch early | 5.0 medium | 13.4% | 1997-07-08 |
| CVE-2018-14335 EXP | An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of th… | Patch early | 6.5 medium | 13.4% | 2018-07-24 |
| CVE-2017-1000373 EXP | The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort()… | Patch early | 6.5 medium | 13.4% | 2017-06-19 |
| CVE-2013-2683 EXP | Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresse… | Patch early | 5.3 medium | 13.4% | 2020-02-06 |
| CVE-2002-2062 EXP | Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP si… | Patch early | 4.3 medium | 13.3% | 2002-12-31 |
| CVE-2010-3709 EXP | The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of… | Patch early | 4.3 medium | 13.3% | 2010-11-09 |
| CVE-2019-12477 EXP | Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authe… | Patch early | 5.5 medium | 13.3% | 2019-06-07 |
| CVE-2015-4153 EXP | Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to include and execute arb… | Patch early | 5.0 medium | 13.3% | 2015-06-10 |
| CVE-2007-3473 EXP | The gdImageCreateXbm function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (cra… | Patch early | 4.3 medium | 13.3% | 2007-06-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt