CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,359 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
169,677 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-5837 EXP | GUI.pm in yarssr 0.2.2, when Gnome default URL handling is disabled, allows remote attackers to execute arbitrary commands via shell metacharacters in… | Patch early | 6.8 medium | 6.2% | 2007-11-05 |
| CVE-2009-4051 EXP | Home FTP Server 1.10.1.139 allows remote attackers to cause a denial of service (daemon outage) via multiple invalid SITE INDEX commands. | Patch early | 5.0 medium | 6.2% | 2009-11-23 |
| CVE-2009-1724 EXP | Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touc… | Patch early | 4.3 medium | 6.2% | 2009-07-09 |
| CVE-2007-4174 EXP | Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify… | Patch early | 5.8 medium | 6.2% | 2007-08-07 |
| CVE-2008-1480 EXP | rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC request. | Patch early | 4.3 medium | 6.2% | 2008-03-24 |
| CVE-2001-0421 EXP | FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permiss… | Patch early | 6.4 medium | 6.2% | 2001-07-02 |
| CVE-2000-0626 EXP | Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request. | Patch early | 5.0 medium | 6.2% | 2000-07-18 |
| CVE-2008-5932 EXP | CodeAvalanche FreeForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download th… | Patch early | 5.0 medium | 6.2% | 2009-01-21 |
| CVE-2008-6869 EXP | Oramon Oracle Database Monitoring Tool 2.0.1 stores sensitive information under the web root with insufficient access control, which allows remote att… | Patch early | 5.0 medium | 6.2% | 2009-07-23 |
| CVE-2000-0001 EXP | RealMedia server allows remote attackers to cause a denial of service via a long ramgen request. | Patch early | 5.0 medium | 6.2% | 1999-12-23 |
| CVE-2008-4907 EXP | The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a d… | Patch early | 4.3 medium | 6.2% | 2008-11-04 |
| CVE-2014-8603 EXP | cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell… | Patch early | 6.5 medium | 6.2% | 2015-06-10 |
| CVE-2008-1357 EXP | Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used i… | Patch early | 5.4 medium | 6.2% | 2008-03-17 |
| CVE-2003-1354 EXP | Multiple GameSpy 3D 2.62 compatible gaming servers generate very large UDP responses to small requests, which allows remote attackers to use the serve… | Patch early | 5.0 medium | 6.2% | 2003-12-31 |
| CVE-2003-1469 EXP | The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the… | Patch early | 5.0 medium | 6.2% | 2003-12-31 |
| CVE-2018-18762 EXP | SaltOS 3.1 r8126 contains a database download vulnerability. | Patch early | 6.5 medium | 6.2% | 2019-03-21 |
| CVE-2018-10371 EXP | An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scripting vulnerability has been ident… | Patch early | 6.1 medium | 6.2% | 2018-05-01 |
| CVE-2007-4638 EXP | Blizzard Entertainment StarCraft Brood War 1.15.1 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed… | Patch early | 4.3 medium | 6.2% | 2007-08-31 |
| CVE-2004-2750 EXP | Directory traversal vulnerability in browser.php in JBrowser 1.0 through 2.1 allows remote attackers to read arbitrary files via the directory paramet… | Patch early | 5.0 medium | 6.2% | 2004-12-31 |
| CVE-2017-15359 EXP | In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/api/Recordi… | Patch early | 6.5 medium | 6.2% | 2017-10-18 |
| CVE-2017-2367 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 6.5 medium | 6.2% | 2017-04-02 |
| CVE-2017-2442 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit JavaScr… | Patch early | 6.5 medium | 6.2% | 2017-04-02 |
| CVE-2006-5634 EXP | Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) r… | Patch early | 6.8 medium | 6.2% | 2006-11-01 |
| CVE-2010-3070 EXP | Cross-site scripting (XSS) vulnerability in NuSOAP 0.9.5, as used in MantisBT and other products, allows remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 6.2% | 2010-09-28 |
| CVE-2013-5688 EXP | Multiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and earlier allow remote authenticated users to read arbitrary files via… | Patch early | 5.5 medium | 6.2% | 2013-11-05 |
| CVE-2019-9834 EXP | The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injecti… | Patch early | 6.1 medium | 6.2% | 2019-03-15 |
| CVE-2000-0720 EXP | news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to ad… | Patch early | 5.0 medium | 6.2% | 2000-10-20 |
| CVE-1999-0175 EXP | The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web ser… | Patch early | 5.0 medium | 6.2% | 1996-07-01 |
| CVE-2019-12562 EXP | Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin no… | Patch early | 6.1 medium | 6.2% | 2019-09-26 |
| CVE-2019-9816 EXP | A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of se… | Patch early | 5.9 medium | 6.2% | 2019-07-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt