CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,483 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-2329 EXP | Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of s… | Patch early | 5.0 medium | 62.3% | 2012-05-11 |
| CVE-2006-4446 EXP | Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to c… | Patch early | 5.0 medium | 62.2% | 2006-08-30 |
| CVE-2012-2982 EXP | file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as d… | Patch early | 6.5 medium | 62.2% | 2012-09-11 |
| CVE-2006-4318 EXP | Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands. | Patch early | 6.5 medium | 62.1% | 2006-08-24 |
| CVE-2005-2120 EXP | Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or loca… | Patch early | 6.5 medium | 62% | 2005-10-13 |
| CVE-2005-0277 EXP | Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execu… | Patch early | 5.0 medium | 61.9% | 2005-05-02 |
| CVE-2007-1061 EXP | SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote a… | Patch early | 6.8 medium | 61.8% | 2007-02-22 |
| CVE-2007-3632 EXP | Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a… | Patch early | 6.8 medium | 61.5% | 2007-07-10 |
| CVE-2005-2087 EXP | Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a… | Patch early | 5.0 medium | 61.4% | 2005-07-05 |
| CVE-2013-1428 EXP | Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated… | Patch early | 6.5 medium | 60.7% | 2013-04-26 |
| CVE-2013-4074 EXP | The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 in… | Patch early | 5.0 medium | 60.6% | 2013-06-09 |
| CVE-2018-3639 EXP | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes… | Patch early | 5.5 medium | 60.6% | 2018-05-22 |
| CVE-2006-5198 EXP | The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers… | Patch early | 4.0 medium | 60.4% | 2006-11-14 |
| CVE-2004-0184 EXP | Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP pack… | Patch early | 5.0 medium | 60.3% | 2004-05-04 |
| CVE-2015-8399 EXP | Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdef… | Patch early | 4.3 medium | 60.2% | 2016-04-11 |
| CVE-2010-2333 EXP | LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a… | Patch early | 5.0 medium | 60.2% | 2010-06-18 |
| CVE-2007-4744 EXP | PHP remote file inclusion vulnerability in environment.php in AnyInventory 1.9.1 and 2.0, when register_globals is enabled, allows remote attackers to… | Patch early | 6.8 medium | 60.1% | 2007-09-06 |
| CVE-2014-100002 EXP | Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot… | Patch early | 5.0 medium | 59.9% | 2015-01-13 |
| CVE-2013-3763 EXP | Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to aff… | Patch early | 5.5 medium | 59.8% | 2013-07-17 |
| CVE-2011-4404 EXP | The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Up… | Patch early | 5.0 medium | 59.7% | 2011-11-19 |
| CVE-2011-4317 EXP | The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch i… | Patch early | 4.3 medium | 59.6% | 2011-11-30 |
| CVE-2013-5880 EXP | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.0, 12.2.1, and 12.2.2 allows r… | Patch early | 5.0 medium | 59.6% | 2014-01-15 |
| CVE-2013-7108 EXP | Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote au… | Patch early | 5.5 medium | 59.5% | 2014-01-15 |
| CVE-2013-5795 EXP | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 1… | Patch early | 5.0 medium | 59.5% | 2014-01-15 |
| CVE-2007-3813 EXP | PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitrary PHP c… | Patch early | 4.3 medium | 59.4% | 2007-07-17 |
| CVE-2015-5603 EXP | The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors,… | Patch early | 6.5 medium | 59.3% | 2015-09-21 |
| CVE-2008-5081 EXP | The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause… | Patch early | 5.0 medium | 59.2% | 2008-12-17 |
| CVE-2018-8770 EXP | Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, contr… | Patch early | 5.3 medium | 59.2% | 2018-03-18 |
| CVE-2019-0221 EXP | The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is,… | Patch early | 6.1 medium | 59.2% | 2019-05-28 |
| CVE-2008-2463 EXP | The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Offic… | Patch early | 6.8 medium | 59.1% | 2008-07-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt