CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,733 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-4513 EXP | khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via la… | Patch early | 6.4 medium | 12.6% | 2012-11-11 |
| CVE-2005-4134 EXP | Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and dela… | Patch early | 5.0 medium | 12.6% | 2005-12-09 |
| CVE-2017-5415 EXP | An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and furthe… | Patch early | 5.3 medium | 12.6% | 2018-06-11 |
| CVE-2021-25159 EXP | A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x… | Patch early | 6.5 medium | 12.6% | 2021-03-30 |
| CVE-2004-1491 EXP | Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or lau… | Patch early | 5.0 medium | 12.6% | 2004-12-31 |
| CVE-2012-5672 EXP | Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read a… | Patch early | 4.3 medium | 12.5% | 2012-10-25 |
| CVE-2015-5354 EXP | Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks v… | Patch early | 5.8 medium | 12.5% | 2015-07-01 |
| CVE-2012-4528 EXP | The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP app… | Patch early | 5.0 medium | 12.5% | 2012-12-28 |
| CVE-2006-0306 EXP | The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Back… | Patch early | 5.0 medium | 12.5% | 2006-01-19 |
| CVE-2006-2554 EXP | Buffer overflow in the tell_player_surr_changes function in Genecys 0.2 and earlier might allow remote attackers to execute arbitrary code via long ar… | Patch early | 6.4 medium | 12.5% | 2006-05-24 |
| CVE-2006-1260 EXP | Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which… | Patch early | 5.0 medium | 12.5% | 2006-03-19 |
| CVE-2005-3507 EXP | Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" se… | Patch early | 5.0 medium | 12.4% | 2005-11-06 |
| CVE-2021-25155 EXP | A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x… | Patch early | 6.5 medium | 12.4% | 2021-03-30 |
| CVE-2006-1015 EXP | Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additi… | Patch early | 6.4 medium | 12.4% | 2006-03-07 |
| CVE-2017-0785 EXP | A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1… | Patch early | 6.5 medium | 12.4% | 2017-09-14 |
| CVE-2013-3690 EXP | Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and pos… | Patch early | 6.8 medium | 12.4% | 2013-10-01 |
| CVE-2004-1675 EXP | Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DO… | Patch early | 5.0 medium | 12.4% | 2004-09-11 |
| CVE-2016-4314 EXP | Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary fil… | Patch early | 4.9 medium | 12.4% | 2017-02-17 |
| CVE-2009-4496 EXP | Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title,… | Patch early | 5.0 medium | 12.3% | 2010-01-13 |
| CVE-2008-6172 EXP | Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!, when magic_quotes_gpc is dis… | Patch early | 6.8 medium | 12.3% | 2009-02-19 |
| CVE-2007-3655 EXP | Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and earlier, allows remote attacker… | Patch early | 6.8 medium | 12.3% | 2007-07-10 |
| CVE-2009-0192 EXP | Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute… | Patch early | 5.0 medium | 12.3% | 2009-07-14 |
| CVE-2004-0465 EXP | Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows remote attackers to read keys wit… | Patch early | 5.0 medium | 12.3% | 2004-12-31 |
| CVE-2019-17554 EXP | The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Reque… | Patch early | 5.5 medium | 12.2% | 2019-12-04 |
| CVE-2018-15705 EXP | WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a… | Patch early | 6.5 medium | 12.2% | 2018-10-31 |
| CVE-2010-3679 EXP | Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via certain arguments to the BINLO… | Patch early | 4.0 medium | 12.2% | 2011-01-11 |
| CVE-2010-3683 EXP | Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 sends an OK packet when a LOAD DATA INFILE request generates SQL errors, which allows remote authe… | Patch early | 4.0 medium | 12.2% | 2011-01-11 |
| CVE-2010-3681 EXP | Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using the… | Patch early | 4.0 medium | 12.2% | 2011-01-11 |
| CVE-2010-3680 EXP | Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by creating temporary tables with… | Patch early | 4.0 medium | 12.2% | 2011-01-11 |
| CVE-2010-3678 EXP | Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (crash) via (1) IN or (2) CASE operations with NULL argu… | Patch early | 4.0 medium | 12.2% | 2011-01-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt