CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,331 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
206,283 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-6830 EXP | libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass… | Patch early | 5.0 medium | 9.8% | 2015-09-14 |
| CVE-2013-5945 EXP | Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N wit… | Patch early | 9.8 critical | 9.8% | 2020-02-11 |
| CVE-2017-14089 EXP | An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the Office… | Patch early | 9.8 critical | 9.8% | 2017-10-06 |
| CVE-2019-8662 EXP | This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able… | Patch early | 9.8 critical | 9.8% | 2019-12-18 |
| CVE-2014-4663 EXP | TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary commands via shell metacharac… | Patch early | 6.8 medium | 9.8% | 2014-07-15 |
| CVE-2006-2026 EXP | Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly e… | Patch early | 6.5 medium | 9.7% | 2006-04-25 |
| CVE-2000-0908 EXP | BrowseGate 2.80 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long Authorization or Referer MIME he… | Patch early | 5.0 medium | 9.7% | 2000-12-19 |
| CVE-2018-5723 EXP | MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account. | Patch early | 9.8 critical | 9.7% | 2018-01-16 |
| CVE-2004-0958 EXP | php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that… | Patch early | 5.0 medium | 9.7% | 2004-11-03 |
| CVE-2006-3682 EXP | awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode or (3) mont… | Patch early | 5.0 medium | 9.7% | 2006-07-21 |
| CVE-2021-40352 EXP | OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users. | Patch early | 6.5 medium | 9.7% | 2021-09-01 |
| CVE-2012-4514 EXP | rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a c… | Patch early | 5.0 medium | 9.7% | 2012-11-11 |
| CVE-2000-0179 EXP | HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port 5555. | Patch early | 5.0 medium | 9.7% | 2000-02-28 |
| CVE-2010-1316 EXP | Multiple stack-based buffer overflows in Tembria Server Monitor before 5.6.1 allow remote attackers to cause a denial of service (daemon crash) or pos… | Patch early | 5.0 medium | 9.7% | 2010-04-14 |
| CVE-2010-1813 EXP | WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory cor… | Patch early | 6.8 medium | 9.7% | 2010-09-09 |
| CVE-2016-3542 EXP | Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 a… | Patch early | 6.5 medium | 9.7% | 2016-07-21 |
| CVE-2019-1943 EXP | A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attacke… | Patch early | 4.7 medium | 9.7% | 2019-07-17 |
| CVE-2003-0169 EXP | hpnst.exe in the GoAhead-Webs webserver for HP Instant TopTools before 5.55 allows remote attackers to cause a denial of service (CPU consumption) via… | Patch early | 5.0 medium | 9.7% | 2003-04-11 |
| CVE-2008-3408 EXP | Stack-based buffer overflow in CoolPlayer 2.18, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a cra… | Patch early | 6.8 medium | 9.7% | 2008-07-31 |
| CVE-2017-0259 EXP | The Windows kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows… | Patch early | 4.7 medium | 9.7% | 2017-05-12 |
| CVE-2006-0717 EXP | IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532… | Patch early | 5.0 medium | 9.7% | 2006-02-15 |
| CVE-2008-2006 EXP | Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to cause a denial of service (NULL pointer dereference… | Patch early | 4.3 medium | 9.7% | 2008-05-22 |
| CVE-1999-1431 EXP | ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), inst… | Patch early | 4.6 medium | 9.7% | 2005-01-07 |
| CVE-2019-6716 EXP | An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote atta… | Patch early | 9.4 critical | 9.6% | 2019-03-21 |
| CVE-2017-3546 EXP | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework). Supported versi… | Patch early | 6.5 medium | 9.6% | 2017-04-24 |
| CVE-2019-19516 EXP | Intelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a password. | Patch early | 6.5 medium | 9.6% | 2019-12-02 |
| CVE-2001-1083 EXP | Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (… | Patch early | 5.0 medium | 9.6% | 2001-06-26 |
| CVE-2007-5036 EXP | Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated users to cause a denial of ser… | Patch early | 5.0 medium | 9.6% | 2007-09-24 |
| CVE-2002-1320 EXP | Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email message with a From header that… | Patch early | 5.0 medium | 9.6% | 2002-12-11 |
| CVE-2018-9021 EXP | An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with sp… | Patch early | 9.8 critical | 9.6% | 2018-06-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt