CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,759 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-1029 EXP | Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS… | Patch early | 5.0 medium | 11.7% | 2010-03-19 |
| CVE-2013-4295 EXP | The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an external… | Patch early | 5.0 medium | 11.7% | 2013-10-24 |
| CVE-2006-1206 EXP | Matt Johnston Dropbear SSH server 0.47 and earlier, as used in embedded Linux devices and on general-purpose operating systems, allows remote attacker… | Patch early | 5.0 medium | 11.7% | 2006-03-14 |
| CVE-2005-2792 EXP | Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in… | Patch early | 5.0 medium | 11.7% | 2005-09-02 |
| CVE-2010-2122 EXP | Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows remote attackers to include and… | Patch early | 6.8 medium | 11.7% | 2010-06-01 |
| CVE-1999-1520 EXP | A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, whi… | Patch early | 5.0 medium | 11.7% | 1999-05-11 |
| CVE-2008-0333 EXP | Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read a… | Patch early | 5.0 medium | 11.7% | 2008-01-17 |
| CVE-2014-3976 EXP | Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a… | Patch early | 5.0 medium | 11.6% | 2014-06-05 |
| CVE-2001-0311 EXP | Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client. | Patch early | 4.6 medium | 11.6% | 2001-06-02 |
| CVE-2002-0591 EXP | Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute co… | Patch early | 5.0 medium | 11.6% | 2002-06-18 |
| CVE-2009-1574 EXP | racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a… | Patch early | 5.0 medium | 11.6% | 2009-05-06 |
| CVE-2003-0129 EXP | Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that i… | Patch early | 5.0 medium | 11.6% | 2003-03-24 |
| CVE-2019-8925 EXP | An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerability in the Administration zon… | Patch early | 4.3 medium | 11.6% | 2019-05-17 |
| CVE-2007-2209 EXP | Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.20 and possibly other products… | Patch early | 6.8 medium | 11.6% | 2007-04-24 |
| CVE-2014-9014 EXP | Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allo… | Patch early | 4.3 medium | 11.6% | 2019-11-06 |
| CVE-2012-1125 EXP | Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 for WordPress allows remote atta… | Patch early | 6.8 medium | 11.6% | 2012-10-08 |
| CVE-2008-7257 EXP | CRLF injection vulnerability in +webvpn+/index.html in WebVPN on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1… | Patch early | 4.3 medium | 11.6% | 2010-06-29 |
| CVE-2007-4254 EXP | Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Designer 7.0 for Microsoft Visual St… | Patch early | 6.8 medium | 11.5% | 2007-08-08 |
| CVE-2008-0944 EXP | Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote attackers to cause a denial of service (NULL dereference and application crash) via… | Patch early | 5.0 medium | 11.5% | 2008-02-25 |
| CVE-2019-6273 EXP | download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files. | Patch early | 6.5 medium | 11.5% | 2019-03-21 |
| CVE-2010-0397 EXP | The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, w… | Patch early | 5.0 medium | 11.5% | 2010-03-16 |
| CVE-2018-15120 EXP | libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application cras… | Patch early | 6.5 medium | 11.5% | 2018-08-24 |
| CVE-2008-6222 EXP | Directory traversal vulnerability in the Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 for Joomla! allows remote attackers to read arbi… | Patch early | 5.0 medium | 11.5% | 2009-02-20 |
| CVE-2016-0070 EXP | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT… | Patch early | 5.5 medium | 11.5% | 2016-10-14 |
| CVE-2007-1912 EXP | Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file. | Patch early | 6.8 medium | 11.5% | 2007-04-10 |
| CVE-2010-3682 EXP | Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXP… | Patch early | 4.0 medium | 11.4% | 2011-01-11 |
| CVE-2015-3221 EXP | OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated use… | Patch early | 4.0 medium | 11.4% | 2015-08-26 |
| CVE-2013-4788 EXP | The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the ra… | Patch early | 5.1 medium | 11.4% | 2013-10-04 |
| CVE-2007-0107 EXP | WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers… | Patch early | 6.8 medium | 11.4% | 2007-01-09 |
| CVE-2010-1056 EXP | Directory traversal vulnerability in the RokDownloads (com_rokdownloads) component before 1.0.1 for Joomla! allows remote attackers to include and exe… | Patch early | 6.8 medium | 11.4% | 2010-03-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt