CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,331 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
206,283 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-10618 EXP | Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracked, allowing a remote attacker… | Patch early | 9.8 critical | 10.1% | 2018-08-01 |
| CVE-2013-3969 EXP | The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitializ… | Patch early | 6.5 medium | 10.1% | 2013-10-01 |
| CVE-2013-2681 EXP | Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access. | Patch early | 9.8 critical | 10.1% | 2020-02-05 |
| CVE-2009-0756 EXP | The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that… | Patch early | 5.0 medium | 10.1% | 2009-03-03 |
| CVE-2011-4618 EXP | Cross-site scripting (XSS) vulnerability in advancedtext.php in Advanced Text Widget plugin before 2.0.2 for WordPress allows remote attackers to inje… | Patch early | 4.3 medium | 10.1% | 2013-01-24 |
| CVE-2007-4722 EXP | Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie07051001.dll 1.0.0.1 in Move Media Pl… | Patch early | 6.8 medium | 10.1% | 2007-09-05 |
| CVE-2009-3305 EXP | Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that… | Patch early | 5.0 medium | 10.1% | 2009-12-24 |
| CVE-2021-30149 EXP | Composr 10.0.36 allows upload and execution of PHP files. | Patch early | 9.8 critical | 10.1% | 2021-04-06 |
| CVE-2017-11435 EXP | The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management consol… | Patch early | 9.8 critical | 10.1% | 2017-07-19 |
| CVE-2011-2522 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attacke… | Patch early | 6.8 medium | 10% | 2011-07-29 |
| CVE-2010-0682 EXP | WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter. | Patch early | 4.0 medium | 10% | 2010-02-23 |
| CVE-2005-0989 EXP | The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attacker… | Patch early | 5.0 medium | 10% | 2005-05-02 |
| CVE-2014-5470 EXP | Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to… | Patch early | 9.8 critical | 10% | 2024-06-21 |
| CVE-2018-6223 EXP | A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate th… | Patch early | 9.8 critical | 10% | 2018-03-15 |
| CVE-2018-20523 EXP | Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a t… | Patch early | 5.3 medium | 10% | 2019-06-07 |
| CVE-2006-2460 EXP | Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESS… | Patch early | 6.4 medium | 10% | 2006-05-19 |
| CVE-2018-19042 EXP | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters o… | Patch early | 5.3 medium | 10% | 2019-01-31 |
| CVE-2018-19043 EXP | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename) via a ../ directory traversal… | Patch early | 5.3 medium | 10% | 2019-01-31 |
| CVE-2000-0213 EXP | The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacha… | Patch early | 5.0 medium | 10% | 2000-02-23 |
| CVE-2021-34370 EXP | Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags an… | Patch early | 6.1 medium | 10% | 2021-06-09 |
| CVE-2021-42580 EXP | Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticate… | Patch early | 9.8 critical | 10% | 2021-11-15 |
| CVE-2007-2807 EXP | Stack-based buffer overflow in mod/server.mod/servrmsg.c in Eggdrop 1.6.18, and possibly earlier, allows user-assisted, remote IRC servers to execute… | Patch early | 6.8 medium | 10% | 2007-05-22 |
| CVE-2006-4019 EXP | Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variabl… | Patch early | 6.4 medium | 10% | 2006-08-11 |
| CVE-2010-2939 EXP | Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and possibly ot… | Patch early | 4.3 medium | 10% | 2010-08-17 |
| CVE-2021-33904 EXP | In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are conf… | Patch early | 6.1 medium | 10% | 2021-06-07 |
| CVE-2012-4552 EXP | Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute arbitrary code via a crafted 3… | Patch early | 6.8 medium | 10% | 2012-11-18 |
| CVE-2011-5265 EXP | Cross-site scripting (XSS) vulnerability in cached_image.php in the Featurific For WordPress plugin 1.6.2 for WordPress allows remote attackers to inj… | Patch early | 4.3 medium | 10% | 2013-02-12 |
| CVE-2013-0238 EXP | The try_parse_v4_netmask function in hostmask.c in IRCD-Hybrid before 8.0.6 does not properly validate masks, which allows remote attackers to cause a… | Patch early | 5.0 medium | 10% | 2013-02-13 |
| CVE-2012-1617 EXP | Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbitrary files via a .. (dot dot)… | Patch early | 6.4 medium | 9.9% | 2012-09-26 |
| CVE-2010-1476 EXP | Directory traversal vulnerability in the AlphaUserPoints (com_alphauserpoints) component 1.5.5 for Joomla! allows remote attackers to read arbitrary f… | Patch early | 6.8 medium | 9.9% | 2010-04-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt