CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,483 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
169,001 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-4123 EXP | client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port num… | Patch early | 5.0 medium | 80.5% | 2013-09-16 |
| CVE-2004-0230 EXP | TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to… | Patch early | 5.0 medium | 80.3% | 2004-08-18 |
| CVE-2009-1386 EXP | ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS Chan… | Patch early | 5.0 medium | 80.1% | 2009-06-04 |
| CVE-2004-0790 EXP | Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages,… | Patch early | 5.0 medium | 80.1% | 2005-04-12 |
| CVE-2000-0246 EXP | IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to… | Patch early | 5.0 medium | 80% | 2000-03-30 |
| CVE-2016-0491 EXP | Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows rem… | Patch early | 6.4 medium | 79.9% | 2016-01-21 |
| CVE-2011-4858 EXP | Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trig… | Patch early | 5.0 medium | 79.7% | 2012-01-05 |
| CVE-2023-2745 EXP | WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated at… | Patch early | 5.4 medium | 79.5% | 2023-05-17 |
| CVE-2014-6034 EXP | Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in ZOHO ManageEngine OpManager 8.8… | Patch early | 5.0 medium | 79% | 2014-12-04 |
| CVE-2019-1622 EXP | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to r… | Patch early | 5.3 medium | 78.9% | 2019-06-27 |
| CVE-2000-0302 EXP | Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument t… | Patch early | 5.0 medium | 78.6% | 2000-03-31 |
| CVE-2006-3392 EXP | Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary fi… | Patch early | 5.0 medium | 78.3% | 2006-07-06 |
| CVE-2010-1587 EXP | The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash s… | Patch early | 5.0 medium | 78% | 2010-04-28 |
| CVE-2007-2449 EXP | Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 t… | Patch early | 4.3 medium | 77.4% | 2007-06-14 |
| CVE-2024-23334 EXP | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it i… | Patch early | 5.9 medium | 76.9% | 2024-01-29 |
| CVE-2003-0190 EXP | OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows re… | Patch early | 5.0 medium | 76.8% | 2003-05-12 |
| CVE-2017-9554 EXP | An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumera… | Patch early | 5.3 medium | 76.7% | 2017-07-24 |
| CVE-2005-3081 EXP | wzdftpd 0.5.4 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the SITE command. | Patch early | 4.6 medium | 76.6% | 2005-09-27 |
| CVE-2022-44267 EXP | ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for… | Patch early | 6.5 medium | 76.6% | 2023-02-06 |
| CVE-2010-2156 EXP | ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID. | Patch early | 5.0 medium | 76.4% | 2010-06-07 |
| CVE-2021-22145 EXP | A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary querie… | Patch early | 6.5 medium | 76.2% | 2021-07-21 |
| CVE-2008-1232 EXP | Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers… | Patch early | 4.3 medium | 75.9% | 2008-08-04 |
| CVE-2006-2447 EXP | SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafte… | Patch early | 5.1 medium | 75.8% | 2006-06-06 |
| CVE-2004-2086 EXP | Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (c… | Patch early | 5.0 medium | 75.5% | 2004-02-06 |
| CVE-2001-0925 EXP | The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP requ… | Patch early | 5.0 medium | 75.2% | 2001-03-12 |
| CVE-2014-4977 EXP | Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via the… | Patch early | 6.5 medium | 74.9% | 2014-07-16 |
| CVE-2025-30208 EXP | Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies acce… | Patch early | 5.3 medium | 74.8% | 2025-03-24 |
| CVE-2018-17128 EXP | A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode. | Patch early | 5.4 medium | 74.8% | 2018-09-17 |
| CVE-2004-2466 EXP | chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a… | Patch early | 5.0 medium | 74.7% | 2004-12-31 |
| CVE-2004-1060 EXP | Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network t… | Patch early | 5.0 medium | 74.7% | 2004-04-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt