CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,806 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-5627 EXP | Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the… | Patch early | 4.0 medium | 11.4% | 2013-10-01 |
| CVE-2003-0276 EXP | Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GET request wit… | Patch early | 5.0 medium | 11.4% | 2003-06-16 |
| CVE-2006-5295 EXP | Unspecified vulnerability in ClamAV before 0.88.5 allows remote attackers to cause a denial of service (scanning service crash) via a crafted Compress… | Patch early | 5.0 medium | 11.4% | 2006-10-16 |
| CVE-2012-0551 EXP | Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE 7 update 4 and earlier and 6 update 32 and earlier, and the GlassFis… | Patch early | 5.8 medium | 11.4% | 2012-05-03 |
| CVE-2019-15889 EXP | The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_d… | Patch early | 6.1 medium | 11.4% | 2019-09-03 |
| CVE-2001-0643 EXP | Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into… | Patch early | 5.0 medium | 11.4% | 2001-09-20 |
| CVE-2007-0816 EXP | The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlier allows remote attackers to c… | Patch early | 5.0 medium | 11.4% | 2007-02-07 |
| CVE-2015-3081 EXP | Race condition in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, A… | Patch early | 4.3 medium | 11.4% | 2015-05-13 |
| CVE-2007-5925 EXP | The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to… | Patch early | 4.0 medium | 11.4% | 2007-11-10 |
| CVE-2003-0108 EXP | isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP pa… | Patch early | 5.0 medium | 11.3% | 2003-03-07 |
| CVE-2008-2595 EXP | Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.4.2 has unknown impact a… | Patch early | 5.0 medium | 11.3% | 2008-07-15 |
| CVE-2007-0243 EXP | Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and… | Patch early | 6.8 medium | 11.3% | 2007-01-17 |
| CVE-2007-2583 EXP | The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a deni… | Patch early | 4.0 medium | 11.3% | 2007-05-10 |
| CVE-2022-2552 EXP | The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server… | Patch early | 5.3 medium | 11.3% | 2022-08-22 |
| CVE-2015-7039 EXP | Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbit… | Patch early | 6.8 medium | 11.3% | 2015-12-11 |
| CVE-2006-4089 EXP | Multiple buffer overflows in Andy Lo-A-Foe AlsaPlayer 0.99.76 and earlier allow remote attackers to cause a denial of service (application crash), or… | Patch early | 5.0 medium | 11.3% | 2006-08-11 |
| CVE-2010-3870 EXP | The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, whic… | Patch early | 6.8 medium | 11.3% | 2010-11-12 |
| CVE-2006-2223 EXP | RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authent… | Patch early | 5.0 medium | 11.3% | 2006-05-05 |
| CVE-2019-10009 EXP | A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to preview an uploa… | Patch early | 6.5 medium | 11.3% | 2019-06-03 |
| CVE-2007-4005 EXP | Stack-based buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 allows remote attackers to execute arbitrary code via a long string to the sh… | Patch early | 5.0 medium | 11.2% | 2007-07-26 |
| CVE-2004-1789 EXP | Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 11.2% | 2004-12-31 |
| CVE-2021-24488 EXP | The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being out… | Patch early | 6.1 medium | 11.2% | 2021-08-02 |
| CVE-2025-2126 EXP | A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the fi… | Patch early | 6.3 medium | 11.2% | 2025-03-09 |
| CVE-2004-1584 EXP | CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HT… | Patch early | 5.0 medium | 11.2% | 2004-12-31 |
| CVE-2009-4880 EXP | Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attacker… | Patch early | 5.0 medium | 11.2% | 2010-06-01 |
| CVE-2012-1008 EXP | OfficeSIP Server 3.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted To header in a SIP INVITE message. | Patch early | 5.0 medium | 11.2% | 2012-02-08 |
| CVE-2004-1992 EXP | Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which trigge… | Patch early | 5.0 medium | 11.2% | 2004-04-20 |
| CVE-2008-1996 EXP | licq before 1.3.6 allows remote attackers to cause a denial of service (file-descriptor exhaustion and application crash) via a large number of connec… | Patch early | 5.0 medium | 11.2% | 2008-04-28 |
| CVE-2009-3111 EXP | The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Passwor… | Patch early | 5.0 medium | 11.2% | 2009-09-09 |
| CVE-2019-8929 EXP | An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/selectDevice.… | Patch early | 6.1 medium | 11.2% | 2019-05-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt