CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,331 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
186,142 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-15812 EXP | DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy. | Patch early | 7.5 high | 47.2% | 2019-07-03 |
| CVE-2014-2962 EXP | Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attack… | Patch early | 7.8 high | 47.1% | 2014-06-19 |
| CVE-2008-5405 EXP | Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier, allows remote attackers to ex… | Patch early | 9.3 high | 47% | 2008-12-10 |
| CVE-2004-0214 EXP | Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious ser… | Patch early | 10.0 high | 47% | 2004-11-03 |
| CVE-2014-9013 EXP | The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbi… | Patch early | 8.8 high | 46.9% | 2019-11-06 |
| CVE-2008-2551 EXP | The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution of… | Patch early | 9.3 high | 46.9% | 2008-06-04 |
| CVE-2019-15984 EXP | Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker… | Patch early | 7.2 high | 46.9% | 2020-01-06 |
| CVE-2018-7719 EXP | Acrolinx Server before 5.2.5 on Windows allows Directory Traversal. | Patch early | 7.5 high | 46.9% | 2018-03-25 |
| CVE-2017-11903 EXP | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 G… | Patch early | 7.5 high | 46.8% | 2017-12-12 |
| CVE-2022-29298 EXP | SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal. | Patch early | 7.5 high | 46.8% | 2022-05-12 |
| CVE-2015-6834 EXP | Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary… | Patch early | 9.8 critical | 46.8% | 2016-05-16 |
| CVE-2010-2590 EXP | Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Reports 2008 SP… | Patch early | 9.3 high | 46.8% | 2010-12-22 |
| CVE-2019-9879 EXP | The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are all… | Patch early | 9.8 critical | 46.6% | 2019-06-10 |
| CVE-2025-29306 EXP | An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component. | Patch early | 9.8 critical | 46.6% | 2025-03-27 |
| CVE-2012-6275 EXP | Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impact via (1)… | Patch early | 10.0 high | 46.5% | 2013-02-24 |
| CVE-2011-4929 EXP | Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary comman… | Patch early | 7.5 high | 46.4% | 2012-10-08 |
| CVE-2025-2011 EXP | The Slider & Popup Builder by Depicter plugin for WordPress is vulnerable to generic SQL Injection via the ‘s' parameter in all versions up to, and in… | Patch early | 7.5 high | 46.4% | 2025-05-06 |
| CVE-2003-0228 EXP | Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arb… | Patch early | 7.5 high | 46.3% | 2003-05-27 |
| CVE-2002-0721 EXP | Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could… | Patch early | 10.0 high | 46.3% | 2002-09-05 |
| CVE-2018-9118 EXP | exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the… | Patch early | 7.5 high | 46.3% | 2018-04-12 |
| CVE-2018-8413 EXP | A remote code execution vulnerability exists when "Windows Theme API" does not properly decompress files, aka "Windows Theme API Remote Code Execution… | Patch early | 7.8 high | 46.3% | 2018-10-10 |
| CVE-2008-2689 EXP | PHP remote file inclusion vulnerability in pub/clients.php in BrowserCRM 5.002.00 allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 10.0 high | 46.2% | 2008-06-13 |
| CVE-2013-5036 EXP | The Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter to the deobfuscation function o… | Patch early | 7.5 high | 46.2% | 2014-05-27 |
| CVE-2014-6446 EXP | The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload ar… | Patch early | 7.5 high | 46.2% | 2014-09-26 |
| CVE-2008-2245 EXP | Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Ima… | Patch early | 9.3 high | 46.1% | 2008-08-13 |
| CVE-2023-30145 EXP | Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter. | Patch early | 9.8 critical | 46.1% | 2023-05-26 |
| CVE-2015-9323 EXP | The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection. | Patch early | 9.8 critical | 46.1% | 2019-08-16 |
| CVE-2008-1505 EXP | PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joomla! allows remote attackers t… | Patch early | 7.5 high | 46.1% | 2008-03-25 |
| CVE-2012-6530 EXP | Stack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users with the create folder permissi… | Patch early | 7.1 high | 46.1% | 2013-01-31 |
| CVE-2016-4971 EXP | GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource. | Patch early | 8.8 high | 46.1% | 2016-06-30 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt