CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,959 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
206,583 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-1112 EXP | IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code… | Patch early | 5.0 medium | 8.6% | 2005-05-02 |
| CVE-2018-10751 EXP | A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml p… | Patch early | 5.3 medium | 8.6% | 2018-05-29 |
| CVE-2012-0788 EXP | The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of… | Patch early | 5.0 medium | 8.6% | 2012-02-14 |
| CVE-2008-0418 EXP | Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addon… | Patch early | 4.3 medium | 8.6% | 2008-02-08 |
| CVE-2012-6708 EXP | jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a… | Patch early | 6.1 medium | 8.6% | 2018-01-18 |
| CVE-2009-2620 EXP | src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote at… | Patch early | 5.0 medium | 8.6% | 2009-07-29 |
| CVE-1999-0060 EXP | Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Conf… | Patch early | 5.0 medium | 8.6% | 1998-03-16 |
| CVE-2008-3432 EXP | Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and 6.3 allows user-assisted attackers to execute arbitrary co… | Patch early | 6.8 medium | 8.6% | 2008-10-10 |
| CVE-2023-33145 EXP | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Patch early | 6.5 medium | 8.6% | 2023-06-14 |
| CVE-2011-4715 EXP | Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlier allows r… | Patch early | 5.0 medium | 8.6% | 2011-12-08 |
| CVE-2010-3039 EXP | /usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated… | Patch early | 6.8 medium | 8.6% | 2010-11-09 |
| CVE-2010-2307 EXP | Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHP… | Patch early | 5.0 medium | 8.6% | 2010-06-16 |
| CVE-2000-0977 EXP | mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" paramet… | Patch early | 5.0 medium | 8.6% | 2000-12-19 |
| CVE-2007-0817 EXP | Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Ag… | Patch early | 4.3 medium | 8.6% | 2007-02-07 |
| CVE-2005-4559 EXP | mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly ini… | Patch early | 5.0 medium | 8.6% | 2005-12-28 |
| CVE-2007-2482 EXP | Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allo… | Patch early | 6.8 medium | 8.6% | 2007-05-03 |
| CVE-2008-4323 EXP | Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application crash) via a crafted .ZIP file. | Patch early | 4.3 medium | 8.6% | 2008-09-29 |
| CVE-2016-3963 EXP | Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 443. | Patch early | 5.3 medium | 8.6% | 2016-04-08 |
| CVE-2011-1143 EXP | epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (NULL pointer… | Patch early | 4.3 medium | 8.6% | 2011-03-03 |
| CVE-2000-0508 EXP | rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request. | Patch early | 5.0 medium | 8.6% | 1994-12-19 |
| CVE-2006-4877 EXP | Variable overwrite vulnerability in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to overwrite arbitrary program variables via… | Patch early | 5.0 medium | 8.6% | 2006-09-19 |
| CVE-2017-17110 EXP | Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request. | Patch early | 9.8 critical | 8.6% | 2017-12-11 |
| CVE-2018-11736 EXP | An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the… | Patch early | 9.8 critical | 8.6% | 2018-06-05 |
| CVE-2023-27290 EXP | Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require… | Patch early | 9.1 critical | 8.6% | 2023-03-03 |
| CVE-2007-6584 EXP | Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot)… | Patch early | 6.4 medium | 8.6% | 2007-12-28 |
| CVE-2010-3306 EXP | Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%… | Patch early | 5.0 medium | 8.6% | 2010-09-24 |
| CVE-2000-0906 EXP | Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to read arbitrary files via a .. (d… | Patch early | 5.0 medium | 8.6% | 2000-12-19 |
| CVE-2015-1482 EXP | Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connecti… | Patch early | 5.0 medium | 8.5% | 2015-02-04 |
| CVE-2018-10575 EXP | An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged S… | Patch early | 9.8 critical | 8.5% | 2018-04-30 |
| CVE-2002-2314 EXP | Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which cause… | Patch early | 5.0 medium | 8.5% | 2002-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt