CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,939 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-1996 EXP | Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessi… | Patch early | 9.3 high | 58.8% | 2011-10-12 |
| CVE-2012-4347 EXP | Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated users to r… | Patch early | 5.0 medium | 58.8% | 2012-12-05 |
| CVE-2013-1559 EXP | Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated… | Patch early | 4.0 medium | 58.8% | 2013-04-17 |
| CVE-2003-0605 EXP | The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to… | Patch early | 7.5 high | 58.8% | 2003-08-27 |
| CVE-2019-5485 EXP | NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository na… | Patch early | 10.0 critical | 58.8% | 2019-09-13 |
| CVE-2018-0707 EXP | Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to… | Patch early | 7.2 high | 58.8% | 2018-07-17 |
| CVE-2006-1364 EXP | Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allo… | Patch early | 7.5 high | 58.7% | 2006-03-23 |
| CVE-2012-0432 EXP | Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified… | Patch early | 10.0 high | 58.7% | 2012-12-25 |
| CVE-2007-1373 EXP | Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers to execute arbitrary code via… | Patch early | 10.0 high | 58.7% | 2007-03-10 |
| CVE-2002-0654 EXP | Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .v… | Patch early | 5.0 medium | 58.7% | 2002-09-05 |
| CVE-2015-5453 EXP | Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id para… | Patch early | 6.5 medium | 58.7% | 2015-07-08 |
| CVE-2008-5619 EXP | html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, M… | Patch early | 10.0 high | 58.6% | 2008-12-17 |
| CVE-2013-2068 EXP | Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to create and o… | Patch early | 9.4 high | 58.6% | 2013-09-28 |
| CVE-2004-1305 EXP | The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers… | Patch early | 5.0 medium | 58.6% | 2004-12-23 |
| CVE-2019-12347 EXP | In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit… | Patch early | 6.1 medium | 58.6% | 2019-05-29 |
| CVE-2018-0780 EXP | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compr… | Patch early | 5.3 medium | 58.6% | 2018-01-04 |
| CVE-2016-6515 EXP | The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows re… | Patch early | 7.5 high | 58.6% | 2016-08-07 |
| CVE-2007-4834 EXP | Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP code via a URL in the MGR paramet… | Patch early | 7.5 high | 58.5% | 2007-09-12 |
| CVE-2008-2158 EXP | Multiple stack-based buffer overflows in the Command Line Interface process in the Server Agent in EMC AlphaStor 3.1 SP1 for Windows allow remote atta… | Patch early | 10.0 high | 58.4% | 2008-05-29 |
| CVE-2007-0217 EXP | The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server res… | Patch early | 10.0 high | 58.4% | 2007-02-13 |
| CVE-2005-0555 EXP | Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted… | Patch early | 7.5 high | 58.4% | 2005-04-12 |
| CVE-2006-2237 EXP | The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metacharac… | Patch early | 5.1 medium | 58.4% | 2006-05-08 |
| CVE-2003-0831 EXP | ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to… | Patch early | 9.0 high | 58.4% | 2003-11-17 |
| CVE-2004-2115 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script… | Patch early | 6.8 medium | 58.4% | 2004-12-31 |
| CVE-2011-4166 EXP | Directory traversal vulnerability in the MPAUploader.Uploader.1.UploadFiles method in HP Managed Printing Administration before 2.6.4 allows remote at… | Patch early | 7.5 high | 58.3% | 2011-12-27 |
| CVE-2015-7601 EXP | Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..// (dot dot double slash) in a R… | Patch early | 7.8 high | 58.3% | 2015-09-29 |
| CVE-2006-5229 EXP | OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows remote attackers to d… | Patch early | 2.6 low | 58.3% | 2006-10-10 |
| CVE-2013-3184 EXP | Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 58.3% | 2013-08-14 |
| CVE-2015-7243 EXP | Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a… | Patch early | 7.5 high | 58.3% | 2015-09-18 |
| CVE-2006-1186 EXP | Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll… | Patch early | 10.0 high | 58.3% | 2006-04-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt