CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,939 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-5880 EXP | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.0, 12.2.1, and 12.2.2 allows r… | Patch early | 5.0 medium | 59.6% | 2014-01-15 |
| CVE-2013-7108 EXP | Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote au… | Patch early | 5.5 medium | 59.5% | 2014-01-15 |
| CVE-2005-0768 EXP | Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions before 5.0.7, allows remote attacke… | Patch early | 10.0 high | 59.5% | 2005-05-02 |
| CVE-2013-5795 EXP | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 1… | Patch early | 5.0 medium | 59.5% | 2014-01-15 |
| CVE-2007-3813 EXP | PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitrary PHP c… | Patch early | 4.3 medium | 59.4% | 2007-07-17 |
| CVE-2012-2576 EXP | SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWi… | Patch early | 9.8 critical | 59.4% | 2017-12-20 |
| CVE-2022-47075 EXP | An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to Expo… | Patch early | 7.5 high | 59.4% | 2023-02-28 |
| CVE-2017-16249 EXP | The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to ha… | Patch early | 7.5 high | 59.4% | 2017-11-10 |
| CVE-2007-1868 EXP | The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP… | Patch early | 10.0 high | 59.3% | 2007-04-04 |
| CVE-2004-1595 EXP | Buffer overflow in ShixxNote 6.net build 117 allows remote attackers to execute arbitrary code via a long font field. | Patch early | 7.5 high | 59.3% | 2004-10-13 |
| CVE-2015-5603 EXP | The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors,… | Patch early | 6.5 medium | 59.3% | 2015-09-21 |
| CVE-2012-2957 EXP | The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file incl… | Patch early | 7.2 high | 59.3% | 2012-07-23 |
| CVE-2012-0500 EXP | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaF… | Patch early | 10.0 high | 59.2% | 2012-02-15 |
| CVE-2008-5081 EXP | The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause… | Patch early | 5.0 medium | 59.2% | 2008-12-17 |
| CVE-2018-8770 EXP | Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, contr… | Patch early | 5.3 medium | 59.2% | 2018-03-18 |
| CVE-2007-4370 EXP | Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbitrary code via a long string to… | Patch early | 7.5 high | 59.2% | 2007-08-15 |
| CVE-2019-0221 EXP | The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is,… | Patch early | 6.1 medium | 59.2% | 2019-05-28 |
| CVE-2007-3216 EXP | Multiple buffer overflows in the LGServer component of CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.1 allow remote… | Patch early | 10.0 high | 59.2% | 2007-06-14 |
| CVE-2008-4037 EXP | Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers t… | Patch early | 9.3 high | 59.1% | 2008-11-12 |
| CVE-2008-2463 EXP | The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Offic… | Patch early | 6.8 medium | 59.1% | 2008-07-07 |
| CVE-2017-1000170 EXP | jqueryFileTree 2.1.5 and older Directory Traversal | Patch early | 7.5 high | 59.1% | 2017-11-17 |
| CVE-2012-0549 EXP | Unspecified vulnerability in the Oracle AutoVue Office component in Oracle Supply Chain Products Suite 20.1.1 allows remote attackers to affect confid… | Patch early | 7.5 high | 59% | 2012-05-03 |
| CVE-2014-10021 EXP | Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 59% | 2015-01-13 |
| CVE-2007-3386 EXP | Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to… | Patch early | 4.3 medium | 59% | 2007-08-14 |
| CVE-2006-6063 EXP | Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via a M3U file containing a long (… | Patch early | 7.5 high | 59% | 2006-11-22 |
| CVE-2021-42840 EXP | SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account t… | Patch early | 8.8 high | 58.9% | 2021-10-22 |
| CVE-2008-0506 EXP | include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows… | Patch early | 6.8 medium | 58.9% | 2008-01-31 |
| CVE-2021-46381 EXP | Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow]. | Patch early | 7.5 high | 58.9% | 2022-03-04 |
| CVE-2000-0574 EXP | FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle… | Patch early | 5.0 medium | 58.9% | 2000-07-07 |
| CVE-2006-2212 EXP | Buffer overflow in KarjaSoft Sami FTP Server 2.0.2 and earlier allows remote attackers to execute arbitrary code via a long (1) USER or (2) PASS comma… | Patch early | 6.4 medium | 58.9% | 2006-05-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt