CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,045 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
169,914 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-5045 EXP | Unspecified vulnerability in PollXT component (com_pollxt) 1.22.07 and earlier for Joomla! has unspecified impact and attack vectors, probably related… | Patch early | 6.8 medium | 5.6% | 2006-09-27 |
| CVE-2011-3483 EXP | Wireshark 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (application crash) via a malformed capture file that leads to an in… | Patch early | 4.3 medium | 5.6% | 2011-09-20 |
| CVE-2008-1410 EXP | Directory traversal vulnerability in the PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to read arbitra… | Patch early | 4.3 medium | 5.6% | 2008-03-20 |
| CVE-2003-1165 EXP | Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via… | Patch early | 5.0 medium | 5.6% | 2003-12-31 |
| CVE-2005-1086 EXP | Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long Us… | Patch early | 6.4 medium | 5.6% | 2005-05-02 |
| CVE-2005-1162 EXP | Multiple cross-site scripting (XSS) vulnerabilities in OneWorldStore allow remote attackers to inject arbitrary web script or HTML via the (1) sEmail… | Patch early | 5.8 medium | 5.6% | 2005-05-02 |
| CVE-2009-1312 EXP | Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to… | Patch early | 4.3 medium | 5.6% | 2009-04-22 |
| CVE-2009-2379 EXP | Directory traversal vulnerability in public/index.php in BIGACE Web CMS 2.6 allows remote attackers to include and execute arbitrary local files via a… | Patch early | 6.8 medium | 5.6% | 2009-07-08 |
| CVE-2010-4399 EXP | Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote attackers to rea… | Patch early | 4.3 medium | 5.6% | 2010-12-06 |
| CVE-2019-7400 EXP | Rukovoditel before 2.4.1 allows XSS. | Patch early | 6.1 medium | 5.6% | 2019-02-05 |
| CVE-2020-15716 EXP | RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script. A remote attacker could exp… | Patch early | 6.1 medium | 5.6% | 2020-07-15 |
| CVE-2007-4725 EXP | Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assist… | Patch early | 6.8 medium | 5.6% | 2007-09-05 |
| CVE-2009-0251 EXP | Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into… | Patch early | 6.5 medium | 5.6% | 2009-01-22 |
| CVE-2013-4034 EXP | IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1… | Patch early | 4.0 medium | 5.6% | 2013-11-18 |
| CVE-2005-2041 EXP | Buffer overflow in addschup in HAURI ViRobot 2.0, and possibly other products, allows remote attackers to execute arbitrary code via a long ViRobot_ID… | Patch early | 5.0 medium | 5.5% | 2005-06-15 |
| CVE-2014-5094 EXP | Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.php, which calls the phpinfo fu… | Patch early | 5.0 medium | 5.5% | 2014-10-20 |
| CVE-2017-0167 EXP | An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016 when the Wi… | Patch early | 5.5 medium | 5.5% | 2017-04-12 |
| CVE-2007-6648 EXP | Directory traversal vulnerability in index.php in SanyBee Gallery 0.1.0 and 0.1.1 allows remote attackers to include and execute arbitrary local files… | Patch early | 5.0 medium | 5.5% | 2008-01-04 |
| CVE-2015-7249 EXP | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access restrictions via a modified req… | Patch early | 4.9 medium | 5.5% | 2015-12-30 |
| CVE-2007-4010 EXP | The win32std extension in PHP 5.2.3 does not follow safe_mode and disable_functions restrictions, which allows remote attackers to execute arbitrary c… | Patch early | 6.8 medium | 5.5% | 2007-07-26 |
| CVE-2006-5301 EXP | PHP remote file inclusion vulnerability in includes/antispam.php in the SpamBlockerMODv 1.0.2 and earlier module for phpBB allows remote attackers to… | Patch early | 6.8 medium | 5.5% | 2006-10-17 |
| CVE-2007-1263 EXP | GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP… | Patch early | 5.0 medium | 5.5% | 2007-03-06 |
| CVE-2011-4814 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 5.5% | 2011-12-14 |
| CVE-2002-0770 EXP | Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server… | Patch early | 5.0 medium | 5.5% | 2002-08-12 |
| CVE-2007-5821 EXP | Multiple directory traversal vulnerabilities in DM Guestbook 0.4.1 and earlier allow remote attackers to include and execute arbitrary local files via… | Patch early | 6.8 medium | 5.5% | 2007-11-05 |
| CVE-1999-0441 EXP | Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service. | Patch early | 5.0 medium | 5.5% | 1999-02-22 |
| CVE-1999-1113 EXP | Buffer overflow in Eudora Internet Mail Server (EIMS) 2.01 and earlier on MacOS systems allows remote attackers to cause a denial of service via a lon… | Patch early | 5.0 medium | 5.5% | 1998-04-14 |
| CVE-2020-5191 EXP | PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities. | Patch early | 6.1 medium | 5.5% | 2020-01-06 |
| CVE-2012-5991 EXP | screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to cause a… | Patch early | 6.3 medium | 5.5% | 2012-12-19 |
| CVE-2017-11663 EXP | The _WM_SetupMidiEvent function in internal_midi.c:2315 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) vi… | Patch early | 6.5 medium | 5.5% | 2017-08-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt