CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,759 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-15500 EXP | An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response… | Patch early | 6.1 medium | 12.2% | 2020-07-01 |
| CVE-2009-1970 EXP | Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to… | Patch early | 5.0 medium | 12.2% | 2009-07-14 |
| CVE-2003-0801 EXP | Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal… | Patch early | 4.3 medium | 12.2% | 2003-10-06 |
| CVE-2007-0908 EXP | The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a nu… | Patch early | 5.0 medium | 12.2% | 2007-02-13 |
| CVE-2017-14955 EXP | Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to… | Patch early | 5.9 medium | 12.1% | 2017-10-02 |
| CVE-2018-19040 EXP | The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir parameter of an mrelocator_getdir… | Patch early | 5.3 medium | 12.1% | 2019-01-31 |
| CVE-2010-0295 EXP | lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a deni… | Patch early | 5.0 medium | 12.1% | 2010-02-03 |
| CVE-2019-1244 EXP | An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosu… | Patch early | 6.5 medium | 12.1% | 2019-09-11 |
| CVE-2006-1834 EXP | Integer signedness error in Opera before 8.54 allows remote attackers to execute arbitrary code via long values in a stylesheet attribute, which pass… | Patch early | 5.1 medium | 12.1% | 2006-04-19 |
| CVE-2007-0017 EXP | Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and t… | Patch early | 6.8 medium | 12.1% | 2007-01-03 |
| CVE-2006-4208 EXP | Directory traversal vulnerability in wp-db-backup.php in Skippy WP-DB-Backup plugin for WordPress 1.7 and earlier allows remote authenticated users wi… | Patch early | 5.0 medium | 12.1% | 2006-08-17 |
| CVE-2001-0054 EXP | Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a str… | Patch early | 5.0 medium | 12% | 2001-02-16 |
| CVE-2009-4017 EXP | PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, whi… | Patch early | 5.0 medium | 12% | 2009-11-24 |
| CVE-2012-5533 EXP | The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via… | Patch early | 5.0 medium | 12% | 2012-11-24 |
| CVE-2016-9722 EXP | IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended… | Patch early | 4.2 medium | 12% | 2018-01-10 |
| CVE-2004-2104 EXP | Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, vi… | Patch early | 5.0 medium | 11.9% | 2004-12-31 |
| CVE-2011-5252 EXP | Open redirect vulnerability in Users/Account/LogOff in Orchard 1.0.x before 1.0.21, 1.1.x before 1.1.31, 1.2.x before 1.2.42, and 1.3.x before 1.3.10… | Patch early | 5.8 medium | 11.9% | 2013-01-12 |
| CVE-2009-1284 EXP | Buffer overflow in BibTeX 0.99 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a long .bib bibliogra… | Patch early | 5.0 medium | 11.9% | 2009-04-09 |
| CVE-2004-1488 EXP | wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web… | Patch early | 5.0 medium | 11.9% | 2005-04-27 |
| CVE-2012-3793 EXP | Integer overflow in Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attac… | Patch early | 5.0 medium | 11.9% | 2012-06-25 |
| CVE-2008-1270 EXP | mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrar… | Patch early | 5.0 medium | 11.9% | 2008-03-10 |
| CVE-2004-2043 EXP | Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allo… | Patch early | 5.0 medium | 11.9% | 2004-05-01 |
| CVE-2010-1981 EXP | Directory traversal vulnerability in the Fabrik (com_fabrik) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot d… | Patch early | 6.8 medium | 11.9% | 2010-05-19 |
| CVE-2006-5846 EXP | Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a .. (… | Patch early | 6.4 medium | 11.9% | 2006-11-10 |
| CVE-2010-1320 EXP | Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote… | Patch early | 4.0 medium | 11.9% | 2010-04-22 |
| CVE-2002-1954 EXP | Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the q… | Patch early | 4.3 medium | 11.9% | 2002-12-31 |
| CVE-2008-1489 EXP | Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly… | Patch early | 6.8 medium | 11.8% | 2008-03-25 |
| CVE-2008-1881 EXP | Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a… | Patch early | 6.8 medium | 11.8% | 2008-04-17 |
| CVE-2011-4153 EXP | PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL p… | Patch early | 5.0 medium | 11.8% | 2012-01-18 |
| CVE-2018-8468 EXP | An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." This affec… | Patch early | 4.7 medium | 11.8% | 2018-09-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt