CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,831 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-2738 EXP | The VteTerminal in gnome-terminal (vte) before 0.32.2 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) v… | Patch early | 4.0 medium | 11.2% | 2012-07-22 |
| CVE-2010-1979 EXP | Directory traversal vulnerability in the Affiliate Datafeeds (com_datafeeds) component build 880 for Joomla! allows remote attackers to read arbitrary… | Patch early | 6.8 medium | 11.2% | 2010-05-19 |
| CVE-2007-6262 EXP | A certain ActiveX control in axvlc.dll in VideoLAN VLC 0.8.6 before 0.8.6d allows remote attackers to execute arbitrary code via crafted arguments to… | Patch early | 6.8 medium | 11.1% | 2007-12-06 |
| CVE-2006-2743 EXP | Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remot… | Patch early | 5.1 medium | 11.1% | 2006-06-01 |
| CVE-2009-3707 EXP | VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x… | Patch early | 5.0 medium | 11.1% | 2009-10-16 |
| CVE-2015-0059 EXP | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2,… | Patch early | 6.9 medium | 11.1% | 2015-02-11 |
| CVE-2003-0853 EXP | An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a la… | Patch early | 5.0 medium | 11.1% | 2003-11-17 |
| CVE-2006-2802 EXP | Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib 1.1.1 allows remote attackers to cause a denial of service (application crash)… | Patch early | 5.0 medium | 11.1% | 2006-06-03 |
| CVE-2006-0396 EXP | Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-001, allows remote attackers to execute arbitrary… | Patch early | 5.1 medium | 11.1% | 2006-03-14 |
| CVE-2011-1761 EXP | Multiple stack-based buffer overflows in the (1) abc_new_macro and (2) abc_new_umacro functions in src/load_abc.cpp in libmodplug before 0.8.8.3 allow… | Patch early | 6.8 medium | 11.1% | 2012-06-07 |
| CVE-2006-2852 EXP | PHP remote file inclusion vulnerability in dotWidget CMS 1.0.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbit… | Patch early | 6.8 medium | 11.1% | 2006-06-06 |
| CVE-2006-0996 EXP | Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 11.1% | 2006-04-10 |
| CVE-2013-4625 EXP | Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to… | Patch early | 4.3 medium | 11.1% | 2013-08-09 |
| CVE-2006-2868 EXP | Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.6 allow remote attackers to execute arbitrary PHP code via a URL in the includePat… | Patch early | 5.1 medium | 11.1% | 2006-06-06 |
| CVE-2009-0039 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 a… | Patch early | 6.8 medium | 11.1% | 2009-04-17 |
| CVE-2004-0179 EXP | Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4)… | Patch early | 6.8 medium | 11.1% | 2004-06-01 |
| CVE-2017-18195 EXP | An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog p… | Patch early | 5.3 medium | 11.1% | 2018-02-26 |
| CVE-2008-3794 EXP | Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execut… | Patch early | 6.8 medium | 11% | 2008-08-26 |
| CVE-2005-0873 EXP | Multiple cross-site scripting (XSS) vulnerabilities in test.jsp in Oracle Reports Server 10g (9.0.4.3.3) allow remote attackers to inject arbitrary we… | Patch early | 4.3 medium | 11% | 2005-05-02 |
| CVE-2010-2310 EXP | SolarWinds TFTP Server 10.4.0.13 allows remote attackers to cause a denial of service (crash) via a long write request. | Patch early | 5.0 medium | 11% | 2010-06-16 |
| CVE-2006-0528 EXP | The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent… | Patch early | 5.0 medium | 11% | 2006-02-02 |
| CVE-2006-6097 EXP | GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTY… | Patch early | 4.0 medium | 11% | 2006-11-24 |
| CVE-2009-2764 EXP | Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of service (application crash) vi… | Patch early | 5.0 medium | 11% | 2009-08-14 |
| CVE-2005-3202 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers to inject arbitrary web script… | Patch early | 6.8 medium | 11% | 2005-10-14 |
| CVE-2006-3995 EXP | Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php, (4) install.uhp.php, (5) too… | Patch early | 6.8 medium | 11% | 2006-08-05 |
| CVE-2014-7221 EXP | TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (buffer overflow and application crash) by connecti… | Patch early | 6.5 medium | 11% | 2018-01-08 |
| CVE-2014-7222 EXP | Buffer overflow in TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (application crash) by connectin… | Patch early | 6.5 medium | 11% | 2018-01-08 |
| CVE-2006-4901 EXP | Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, and eTrust Audit 1.5 and r8, allows remote attackers to spoof alerts… | Patch early | 6.4 medium | 11% | 2006-09-22 |
| CVE-2001-0590 EXP | Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL… | Patch early | 5.0 medium | 11% | 2001-08-02 |
| CVE-2006-5205 EXP | Directory traversal vulnerability in Invision Gallery 2.0.7 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the dir par… | Patch early | 5.0 medium | 11% | 2006-10-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt