CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,903 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-0781 EXP | The tidy_diagnose function in PHP 5.3.8 might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via… | Patch early | 5.0 medium | 10.4% | 2012-01-18 |
| CVE-2009-2958 EXP | The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL poi… | Patch early | 4.3 medium | 10.4% | 2009-09-02 |
| CVE-2008-1110 EXP | Buffer overflow in demuxers/demux_asf.c (aka the ASF demuxer) in the xineplug_dmx_asf.so plugin in xine-lib before 1.1.10 allows remote attackers to e… | Patch early | 6.8 medium | 10.4% | 2008-02-29 |
| CVE-2007-6483 EXP | Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier versions, and Sentinel Keys Server 1.… | Patch early | 5.0 medium | 10.4% | 2007-12-20 |
| CVE-2021-24287 EXP | The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitis… | Patch early | 6.1 medium | 10.4% | 2021-05-14 |
| CVE-2006-2224 EXP | RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify rout… | Patch early | 5.0 medium | 10.4% | 2006-05-05 |
| CVE-2006-2906 EXP | The LZW decoding in the gdImageCreateFromGifPtr function in the Thomas Boutell graphics draw (GD) library (aka libgd) 2.0.33 allows remote attackers t… | Patch early | 5.4 medium | 10.4% | 2006-06-08 |
| CVE-2021-24169 EXP | This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the A… | Patch early | 6.1 medium | 10.3% | 2021-04-05 |
| CVE-2010-1042 EXP | Microsoft Windows Media Player 11 does not properly perform colorspace conversion, which allows remote attackers to cause a denial of service (memory… | Patch early | 4.3 medium | 10.3% | 2010-03-23 |
| CVE-2003-0130 EXP | The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allo… | Patch early | 5.0 medium | 10.3% | 2003-03-24 |
| CVE-2015-2863 EXP | Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before… | Patch early | 4.3 medium | 10.3% | 2015-07-20 |
| CVE-2012-4032 EXP | Open redirect vulnerability in the login page in WebsitePanel before 1.2.2.1 allows remote attackers to redirect users to arbitrary web sites and cond… | Patch early | 5.8 medium | 10.3% | 2012-07-17 |
| CVE-2001-0375 EXP | Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows remote attackers to cause a denial of service via a… | Patch early | 5.0 medium | 10.3% | 2001-06-18 |
| CVE-2010-1586 EXP | Open redirect vulnerability in red2301.html in HP System Management Homepage (SMH) 2.x.x.x allows remote attackers to redirect users to arbitrary web… | Patch early | 4.3 medium | 10.3% | 2010-04-28 |
| CVE-2002-0748 EXP | LabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request that ends in two newline cha… | Patch early | 5.0 medium | 10.3% | 2002-08-12 |
| CVE-2020-6519 EXP | Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page. | Patch early | 6.5 medium | 10.3% | 2020-07-22 |
| CVE-2019-15993 EXP | A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information.… | Patch early | 5.3 medium | 10.3% | 2020-09-23 |
| CVE-2013-1114 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unity Express before 8.0 allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 10.3% | 2013-02-13 |
| CVE-2021-25157 EXP | A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.… | Patch early | 4.9 medium | 10.3% | 2021-03-30 |
| CVE-2008-4500 EXP | Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted stou com… | Patch early | 4.0 medium | 10.3% | 2008-10-09 |
| CVE-2009-0922 EXP | PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and cras… | Patch early | 4.0 medium | 10.2% | 2009-03-17 |
| CVE-2012-6303 EXP | Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows rem… | Patch early | 6.8 medium | 10.2% | 2013-10-28 |
| CVE-2007-5301 EXP | Buffer overflow in the vorbis_stream_info function in input/vorbis/vorbis_engine.c (aka the vorbis input plugin) in AlsaPlayer before 0.99.80-rc3 allo… | Patch early | 6.8 medium | 10.2% | 2007-10-09 |
| CVE-2005-4718 EXP | Opera 8.02 and earlier allows remote attackers to cause a denial of service (client crash) via (1) a crafted HTML file with a "content: url(0);" style… | Patch early | 5.0 medium | 10.2% | 2005-12-31 |
| CVE-2012-0221 EXP | The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does not… | Patch early | 5.0 medium | 10.2% | 2012-04-02 |
| CVE-2012-2577 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inje… | Patch early | 4.3 medium | 10.2% | 2012-08-12 |
| CVE-2013-4579 EXP | The ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12 uses a BSSID masking approach… | Patch early | 4.3 medium | 10.2% | 2013-11-20 |
| CVE-2013-0332 EXP | Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x before 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in t… | Patch early | 5.0 medium | 10.2% | 2013-03-20 |
| CVE-2006-1931 EXP | The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a lar… | Patch early | 5.0 medium | 10.2% | 2006-04-20 |
| CVE-2005-1280 EXP | The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of… | Patch early | 5.0 medium | 10.2% | 2005-05-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt