CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,483 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-3386 EXP | Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to… | Patch early | 4.3 medium | 59% | 2007-08-14 |
| CVE-2008-0506 EXP | include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows… | Patch early | 6.8 medium | 58.9% | 2008-01-31 |
| CVE-2000-0574 EXP | FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle… | Patch early | 5.0 medium | 58.9% | 2000-07-07 |
| CVE-2006-2212 EXP | Buffer overflow in KarjaSoft Sami FTP Server 2.0.2 and earlier allows remote attackers to execute arbitrary code via a long (1) USER or (2) PASS comma… | Patch early | 6.4 medium | 58.9% | 2006-05-05 |
| CVE-2012-4347 EXP | Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated users to r… | Patch early | 5.0 medium | 58.8% | 2012-12-05 |
| CVE-2013-1559 EXP | Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated… | Patch early | 4.0 medium | 58.8% | 2013-04-17 |
| CVE-2002-0654 EXP | Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .v… | Patch early | 5.0 medium | 58.7% | 2002-09-05 |
| CVE-2004-1305 EXP | The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers… | Patch early | 5.0 medium | 58.6% | 2004-12-23 |
| CVE-2019-12347 EXP | In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit… | Patch early | 6.1 medium | 58.6% | 2019-05-29 |
| CVE-2018-0780 EXP | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compr… | Patch early | 5.3 medium | 58.6% | 2018-01-04 |
| CVE-2006-2237 EXP | The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metacharac… | Patch early | 5.1 medium | 58.4% | 2006-05-08 |
| CVE-2004-2115 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script… | Patch early | 6.8 medium | 58.4% | 2004-12-31 |
| CVE-2007-1355 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 throug… | Patch early | 4.3 medium | 58.2% | 2007-05-21 |
| CVE-2019-6111 EXP | An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent… | Patch early | 5.9 medium | 58.2% | 2019-01-31 |
| CVE-2006-0848 EXP | The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to execute arbitrary commands by tr… | Patch early | 5.1 medium | 58.1% | 2006-02-22 |
| CVE-2000-0408 EXP | IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions… | Patch early | 5.0 medium | 58% | 2000-05-11 |
| CVE-2019-10475 EXP | A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages… | Patch early | 6.1 medium | 57.7% | 2019-10-23 |
| CVE-2014-5377 EXP | ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct… | Patch early | 5.0 medium | 57.5% | 2014-09-04 |
| CVE-2014-100015 EXP | Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write to arbitrary files via a .. (do… | Patch early | 6.4 medium | 57.4% | 2015-01-13 |
| CVE-2005-1218 EXP | The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of servic… | Patch early | 5.0 medium | 57.3% | 2005-08-10 |
| CVE-2015-5453 EXP | Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id para… | Patch early | 6.5 medium | 57.3% | 2015-07-08 |
| CVE-2006-4364 EXP | Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attackers to cause a denial of service… | Patch early | 5.0 medium | 57.3% | 2006-08-27 |
| CVE-2010-1899 EXP | Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attack… | Patch early | 4.3 medium | 57.2% | 2010-09-15 |
| CVE-2008-1358 EXP | Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary code via a F… | Patch early | 6.5 medium | 57.1% | 2008-03-17 |
| CVE-2015-2997 EXP | SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getAgentLogFil… | Patch early | 5.0 medium | 57% | 2015-06-08 |
| CVE-2005-2287 EXP | SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large TCP packet with a leading space… | Patch early | 5.0 medium | 56.8% | 2005-07-18 |
| CVE-2001-0731 EXP | Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" quer… | Patch early | 5.0 medium | 56.8% | 2001-10-01 |
| CVE-2012-1006 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 56.6% | 2012-02-07 |
| CVE-2022-1104 EXP | The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as… | Patch early | 4.8 medium | 56.4% | 2022-05-09 |
| CVE-2016-0784 EXP | Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated ad… | Patch early | 6.5 medium | 56.3% | 2016-04-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt