CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,959 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
206,592 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-3487 EXP | Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote attackers to… | Patch early | 6.4 medium | 8.8% | 2007-06-29 |
| CVE-2014-0372 EXP | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 1… | Patch early | 5.5 medium | 8.8% | 2014-01-15 |
| CVE-2012-4878 EXP | Absolute path traversal vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 allows remote administrators to read arbitrary files via a full… | Patch early | 5.0 medium | 8.8% | 2012-09-06 |
| CVE-2013-3539 EXP | Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC… | Patch early | 6.8 medium | 8.8% | 2013-10-01 |
| CVE-2014-4643 EXP | Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a denial of service (application cr… | Patch early | 5.0 medium | 8.8% | 2014-06-25 |
| CVE-2011-3642 EXP | Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, a… | Patch early | 9.6 critical | 8.8% | 2020-02-08 |
| CVE-2013-3239 EXP | phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary… | Patch early | 4.6 medium | 8.8% | 2013-04-26 |
| CVE-2014-10079 EXP | In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML sou… | Patch early | 5.3 medium | 8.7% | 2019-02-23 |
| CVE-2011-3489 EXP | RnaUtility.dll in RsvcHost.exe 2.30.0.23 in Rockwell RSLogix 19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted… | Patch early | 5.0 medium | 8.7% | 2011-09-16 |
| CVE-2017-15271 EXP | A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729. This issue could be triggered prior to authentica… | Patch early | 5.9 medium | 8.7% | 2017-11-15 |
| CVE-1999-0750 EXP | Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account. | Patch early | 5.1 medium | 8.7% | 1999-09-13 |
| CVE-2014-8826 EXP | LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypass the Gatekeeper protection me… | Patch early | 5.0 medium | 8.7% | 2015-01-30 |
| CVE-2012-1614 EXP | Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/i… | Patch early | 5.0 medium | 8.7% | 2012-09-04 |
| CVE-2017-17055 EXP | Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involv… | Patch early | 9.0 critical | 8.7% | 2017-12-07 |
| CVE-2004-1150 EXP | Stack-based buffer overflow in the in_cdda.dll plugin for Winamp 5.0 through 5.08c allows attackers to execute arbitrary code via a cda:// URL with a… | Patch early | 5.1 medium | 8.7% | 2004-12-31 |
| CVE-2004-2280 EXP | Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial of service (crash) via unknown… | Patch early | 5.0 medium | 8.7% | 2004-12-31 |
| CVE-2009-1219 EXP | Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allows remote attackers t… | Patch early | 5.0 medium | 8.7% | 2009-04-01 |
| CVE-2012-5913 EXP | Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject… | Patch early | 4.3 medium | 8.7% | 2012-11-17 |
| CVE-2010-1313 EXP | Directory traversal vulnerability in the Seber Cart (com_sebercart) component 1.0.0.12 and 1.0.0.13 for Joomla!, when magic_quotes_gpc is disabled, al… | Patch early | 4.3 medium | 8.7% | 2010-04-08 |
| CVE-2016-5678 EXP | NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain admin… | Patch early | 9.8 critical | 8.7% | 2016-08-31 |
| CVE-2007-6333 EXP | The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBC… | Patch early | 5.8 medium | 8.7% | 2007-12-13 |
| CVE-2004-1897 EXP | Administration interface in Monit 1.4 through 4.2 allows remote attackers to cause a denial of service (segmentation fault) by sending a Basic Authent… | Patch early | 5.0 medium | 8.7% | 2004-12-31 |
| CVE-2004-2116 EXP | Directory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a .. (dot dot) in the URL. | Patch early | 5.0 medium | 8.7% | 2004-12-31 |
| CVE-2009-4413 EXP | The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remote attackers to cause a denial… | Patch early | 5.0 medium | 8.7% | 2009-12-24 |
| CVE-2009-1684 EXP | Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2… | Patch early | 4.3 medium | 8.7% | 2009-06-10 |
| CVE-2017-8224 EXP | Wireless IP Camera (P2P) WIFICAM devices have a backdoor root account that can be accessed with TELNET. | Patch early | 9.8 critical | 8.7% | 2017-04-25 |
| CVE-2001-0852 EXP | TUX HTTP server 2.1.0-2 in Red Hat Linux allows remote attackers to cause a denial of service via a long Host: header. | Patch early | 5.0 medium | 8.7% | 2001-12-06 |
| CVE-2018-7318 EXP | SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, description_search, or filter_order p… | Patch early | 9.8 critical | 8.7% | 2018-02-22 |
| CVE-2006-2024 EXP | Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors… | Patch early | 4.0 medium | 8.7% | 2006-04-25 |
| CVE-2009-0177 EXP | vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6.5.1 build 126130, 6.5.1 and earlier; VMware Player… | Patch early | 5.0 medium | 8.6% | 2009-01-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt