CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,921 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-02
206,547 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-9261 EXP | The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to rea… | Patch early | 5.0 medium | 9% | 2015-03-23 |
| CVE-2007-0676 EXP | SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | Patch early | 6.8 medium | 9% | 2007-02-03 |
| CVE-2009-0677 EXP | avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to exec… | Patch early | 6.5 medium | 9% | 2009-02-22 |
| CVE-2000-0656 EXP | Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the FTP proto… | Patch early | 5.0 medium | 9% | 2000-07-25 |
| CVE-2016-10043 EXP | An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was discovered to be vulnerable to OS… | Patch early | 10.0 critical | 9% | 2017-01-31 |
| CVE-2009-1220 EXP | Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30… | Patch early | 4.3 medium | 9% | 2009-04-01 |
| CVE-2008-0132 EXP | Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message window and waiting for the adminis… | Patch early | 5.0 medium | 9% | 2008-01-08 |
| CVE-2004-1965 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 9% | 2004-04-25 |
| CVE-2006-4126 EXP | The dc_chat function in cmd.dc.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to cause a denial of service (application crash) by send… | Patch early | 5.0 medium | 9% | 2006-08-14 |
| CVE-2006-4192 EXP | Multiple buffer overflows in MODPlug Tracker (OpenMPT) 1.17.02.43 and earlier and libmodplug 0.8 and earlier, as used in GStreamer and possibly other… | Patch early | 5.1 medium | 9% | 2006-08-17 |
| CVE-2020-25495 EXP | A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote attackers to inject arbitrary we… | Patch early | 6.1 medium | 9% | 2020-12-18 |
| CVE-2019-9184 EXP | SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the produ… | Patch early | 9.8 critical | 9% | 2019-02-26 |
| CVE-2007-4802 EXP | Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a long eighth argument to the SetI… | Patch early | 6.8 medium | 9% | 2007-09-11 |
| CVE-2018-14418 EXP | In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI. | Patch early | 9.8 critical | 9% | 2018-07-20 |
| CVE-2011-2744 EXP | Directory traversal vulnerability in Chyrp 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded d… | Patch early | 6.8 medium | 9% | 2011-07-19 |
| CVE-2009-4495 EXP | Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or pos… | Patch early | 5.0 medium | 9% | 2010-01-13 |
| CVE-2004-1269 EXP | lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subs… | Patch early | 5.0 medium | 9% | 2005-01-10 |
| CVE-2002-1816 EXP | Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via… | Patch early | 9.8 critical | 9% | 2002-12-31 |
| CVE-2022-31056 EXP | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affect… | Patch early | 9.8 critical | 9% | 2022-06-28 |
| CVE-2019-3474 EXP | A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authenticated as a low privilege user… | Patch early | 6.5 medium | 9% | 2019-02-20 |
| CVE-2009-2285 EXP | Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial of service (crash) via a crafte… | Patch early | 4.3 medium | 9% | 2009-07-01 |
| CVE-2008-3286 EXP | SWAT 4 1.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via a (1) VERIFYCONTENT or (2) GAMECONFIG command sent to t… | Patch early | 5.0 medium | 8.9% | 2008-07-24 |
| CVE-2012-1835 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the All-in-One Event Calendar plugin 1.4 and 1.5 for WordPress allow remote attackers to inject… | Patch early | 4.3 medium | 8.9% | 2012-08-14 |
| CVE-2001-0080 EXP | Cisco Catalyst 6000, 5000, or 4000 switches allow remote attackers to cause a denial of service by connecting to the SSH service with a non-SSH client… | Patch early | 5.0 medium | 8.9% | 2001-02-12 |
| CVE-2016-4004 EXP | Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated administrators to read arbitrary file… | Patch early | 4.9 medium | 8.9% | 2016-04-12 |
| CVE-2009-4494 EXP | AOLserver 4.5.1 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title,… | Patch early | 5.0 medium | 8.9% | 2010-01-13 |
| CVE-2008-1561 EXP | Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of service (appli… | Patch early | 5.0 medium | 8.9% | 2008-03-31 |
| CVE-2003-0211 EXP | Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections. | Patch early | 5.0 medium | 8.9% | 2003-05-05 |
| CVE-2008-5642 EXP | Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a… | Patch early | 5.0 medium | 8.9% | 2008-12-17 |
| CVE-2006-2458 EXP | Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code via (1) the asf_read_header f… | Patch early | 4.0 medium | 8.9% | 2006-05-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt