CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,157 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-2262 EXP | Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper"… | Patch early | 5.1 medium | 6.5% | 2005-07-13 |
| CVE-2017-9122 EXP | The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumpti… | Patch early | 6.5 medium | 6.5% | 2017-06-12 |
| CVE-2007-6290 EXP | Multiple directory traversal vulnerabilities in js/get_js.php in SERWeb 2.0.0 dev1 and earlier allow remote attackers to read arbitrary files via a ..… | Patch early | 5.0 medium | 6.5% | 2007-12-10 |
| CVE-2009-0886 EXP | Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via a .. (dot… | Patch early | 5.0 medium | 6.5% | 2009-03-12 |
| CVE-2004-2130 EXP | Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbitrary script or HTML via the (… | Patch early | 4.3 medium | 6.5% | 2004-12-23 |
| CVE-2000-0484 EXP | Small HTTP Server ver 3.06 contains a memory corruption bug causing a memory overflow. The overflowed buffer crashes into a Structured Exception Handl… | Patch early | 5.0 medium | 6.5% | 2000-06-15 |
| CVE-2007-2940 EXP | Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary PHP code via a URL in the pacht… | Patch early | 6.8 medium | 6.5% | 2007-05-31 |
| CVE-2009-1234 EXP | Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a long series of start-tags with no… | Patch early | 4.3 medium | 6.5% | 2009-04-02 |
| CVE-2012-0067 EXP | wiretap/iptrace.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via… | Patch early | 4.3 medium | 6.5% | 2012-04-11 |
| CVE-2010-2375 EXP | Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware… | Patch early | 6.4 medium | 6.5% | 2010-07-13 |
| CVE-2012-5318 EXP | Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin 1.2 for WordPress allows remote attackers t… | Patch early | 6.8 medium | 6.5% | 2012-10-08 |
| CVE-2012-5335 EXP | Directory traversal vulnerability in Tiny Server 1.1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the URI of an H… | Patch early | 4.0 medium | 6.5% | 2012-10-08 |
| CVE-2007-5320 EXP | Multiple absolute path traversal vulnerabilities in Pegasus Imaging ImagXpress 8.0 allow remote attackers to (1) delete arbitrary files via the CacheF… | Patch early | 4.0 medium | 6.5% | 2007-10-09 |
| CVE-2007-2483 EXP | Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, al… | Patch early | 6.8 medium | 6.5% | 2007-05-03 |
| CVE-2019-10963 EXP | Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow se… | Patch early | 4.3 medium | 6.5% | 2019-10-08 |
| CVE-2009-4142 EXP | The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) inv… | Patch early | 4.3 medium | 6.5% | 2009-12-21 |
| CVE-2013-2624 EXP | Telean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive information through a special… | Patch early | 5.3 medium | 6.5% | 2020-02-03 |
| CVE-2016-1910 EXP | The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290. | Patch early | 5.3 medium | 6.5% | 2016-01-15 |
| CVE-2007-2832 EXP | Cross-site scripting (XSS) vulnerability in the web application firewall in Cisco CallManager before 3.3(5)sr3, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3… | Patch early | 4.3 medium | 6.5% | 2007-05-24 |
| CVE-2015-6995 EXP | The Disk Images component in Apple iOS before 9.1 and OS X before 10.11.1 misparses images, which allows attackers to execute arbitrary code or cause… | Patch early | 6.8 medium | 6.5% | 2015-10-23 |
| CVE-2001-1290 EXP | admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify the configuration, gain privileg… | Patch early | 5.0 medium | 6.5% | 2001-06-28 |
| CVE-2001-0466 EXP | Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | Patch early | 5.0 medium | 6.5% | 2001-06-18 |
| CVE-2001-0075 EXP | Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename pa… | Patch early | 5.0 medium | 6.5% | 2001-02-12 |
| CVE-2001-0293 EXP | Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command. | Patch early | 5.0 medium | 6.5% | 2001-05-03 |
| CVE-2001-0305 EXP | Directory traversal vulnerability in store.cgi in Thinking Arts ES.One package allows remote attackers to read arbitrary files via a .. (dot dot) in t… | Patch early | 5.0 medium | 6.5% | 2001-05-03 |
| CVE-2010-2435 EXP | Weborf HTTP Server 0.12.1 and earlier allows remote attackers to cause a denial of service (crash) via Unicode characters in a Connection HTTP header,… | Patch early | 5.0 medium | 6.5% | 2010-06-24 |
| CVE-2007-1049 EXP | Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0… | Patch early | 4.3 medium | 6.5% | 2007-02-21 |
| CVE-2010-1748 EXP | The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before… | Patch early | 4.3 medium | 6.5% | 2010-06-17 |
| CVE-2019-2413 EXP | Vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware (subcomponent: Valid Session). The supported version that is affec… | Patch early | 6.1 medium | 6.5% | 2019-01-16 |
| CVE-2007-4328 EXP | Multiple PHP remote file inclusion vulnerabilities in Mapos Bilder Galerie 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the c… | Patch early | 6.8 medium | 6.5% | 2007-08-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt