CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,265 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
400,265 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-1423 EXP | Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versio… | Patch early | 9.3 high | 55.6% | 2010-04-15 |
| CVE-2007-4818 EXP | Multiple PHP remote file inclusion vulnerabilities in Txx CMS 0.2 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root param… | Patch early | 7.5 high | 55.5% | 2007-09-11 |
| CVE-2012-1196 EXP | Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote… | Patch early | 5.0 medium | 55.5% | 2012-02-18 |
| CVE-2023-0159 EXP | The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when… | Patch early | 7.5 high | 55.5% | 2023-02-13 |
| CVE-2006-1388 EXP | Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors. | Patch early | 7.5 high | 55.5% | 2006-03-24 |
| CVE-2002-0186 EXP | Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a l… | Patch early | 7.5 high | 55.5% | 2002-07-03 |
| CVE-2007-2931 EXP | Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbit… | Patch early | 9.3 high | 55.5% | 2007-08-31 |
| CVE-2005-2551 EXP | Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain acces… | Patch early | 7.5 high | 55.4% | 2005-08-12 |
| CVE-2014-7228 EXP | Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professio… | Patch early | 7.5 high | 55.4% | 2014-11-03 |
| CVE-2006-0395 EXP | The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an unsafe type, which allows user… | Patch early | 5.1 medium | 55.4% | 2006-08-05 |
| CVE-2023-22809 EXP | In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISU… | Patch early | 7.8 high | 55.4% | 2023-01-18 |
| CVE-2021-43857 EXP | Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched… | Patch early | 9.8 critical | 55.3% | 2021-12-27 |
| CVE-2022-24124 EXP | The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organiz… | Patch early | 7.5 high | 55.3% | 2022-01-29 |
| CVE-2017-3730 EXP | In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attem… | Patch early | 7.5 high | 55.3% | 2017-05-04 |
| CVE-2010-0266 EXP | Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value o… | Patch early | 9.3 high | 55.3% | 2010-07-15 |
| CVE-2005-4734 EXP | Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remote attacke… | Patch early | 6.4 medium | 55.3% | 2005-12-31 |
| CVE-2010-4335 EXP | The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the i… | Patch early | 7.5 high | 55.2% | 2011-01-14 |
| CVE-2007-6509 EXP | Unspecified vulnerability in Appian Enterprise Business Process Management (BPM) Suite 5.6 SP1 allows remote attackers to cause a denial of service vi… | Patch early | 7.8 high | 55.2% | 2007-12-21 |
| CVE-2015-2993 EXP | SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator acc… | Patch early | 7.5 high | 55.1% | 2015-06-08 |
| CVE-2004-0942 EXP | Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header… | Patch early | 5.0 medium | 55.1% | 2005-02-09 |
| CVE-2009-1430 EXP | Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management System 2 (AMS2), as used in Symant… | Patch early | 9.3 high | 55.1% | 2009-04-29 |
| CVE-2018-9205 EXP | Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path. | Patch early | 7.5 high | 55.1% | 2018-04-04 |
| CVE-2016-6602 EXP | ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartex… | Patch early | 9.8 critical | 55.1% | 2017-01-23 |
| CVE-2015-1833 EXP | XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2… | Patch early | 6.4 medium | 55% | 2015-05-29 |
| CVE-2006-4948 EXP | Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cau… | Patch early | 7.5 high | 55% | 2006-09-23 |
| CVE-2013-5877 EXP | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 1… | Patch early | 5.0 medium | 55% | 2014-01-15 |
| CVE-2018-10956 EXP | IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal. | Patch early | 7.5 high | 55% | 2018-06-25 |
| CVE-2019-11229 EXP | models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution. | Patch early | 8.8 high | 55% | 2019-04-15 |
| CVE-2018-0834 EXP | Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how t… | Patch early | 7.5 high | 54.9% | 2018-02-15 |
| CVE-2004-0389 EXP | RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a… | Patch early | 7.5 high | 54.9% | 2004-06-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt