CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,074 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
169,946 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-1063 EXP | Buffer overflow in eXeScope 6.50 allows user-assisted remote attackers to execute arbitrary code via a crafted executable (.exe) file. | Patch early | 6.8 medium | 4.7% | 2009-03-26 |
| CVE-2017-9978 EXP | On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on… | Patch early | 5.3 medium | 4.7% | 2017-08-28 |
| CVE-2009-2654 EXP | Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a… | Patch early | 5.8 medium | 4.7% | 2009-08-03 |
| CVE-2007-1264 EXP | Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail from visually distinguishing b… | Patch early | 5.0 medium | 4.7% | 2007-03-06 |
| CVE-2013-5220 EXP | goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted HTTP POST d… | Patch early | 6.1 medium | 4.7% | 2013-12-30 |
| CVE-2010-0440 EXP | Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA… | Patch early | 4.3 medium | 4.7% | 2010-02-03 |
| CVE-2010-4821 EXP | Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to… | Patch early | 4.3 medium | 4.7% | 2012-10-22 |
| CVE-2010-1947 EXP | Directory traversal vulnerability in scr/soustab.php in openMairie Openregistrecil 1.02, when register_globals is enabled, allows remote attackers to… | Patch early | 6.8 medium | 4.7% | 2010-05-19 |
| CVE-2006-3103 EXP | Cross-site scripting (XSS) vulnerability in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error parameter i… | Patch early | 4.3 medium | 4.7% | 2006-06-21 |
| CVE-2017-13869 EXP | An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchO… | Patch early | 5.5 medium | 4.7% | 2017-12-25 |
| CVE-2005-4467 EXP | Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrary files vi… | Patch early | 5.0 medium | 4.7% | 2005-12-22 |
| CVE-2012-1904 EXP | mp4fformat.dll in the QuickTime File Format plugin in RealNetworks RealPlayer 15 and earlier, and RealPlayer SP 1.1.4 Build 12.0.0.756 and earlier, al… | Patch early | 4.3 medium | 4.7% | 2012-03-28 |
| CVE-2004-1569 EXP | Buffer overflow in (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe in dBpowerAMP Audio Player 2.0 and dbPowerAmp Music Converter 10.0 allows… | Patch early | 4.0 medium | 4.7% | 2004-12-31 |
| CVE-2004-2564 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, allow remote attacke… | Patch early | 4.3 medium | 4.7% | 2004-12-31 |
| CVE-2008-6806 EXP | Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and earlier allows remote attackers to execute arbitrary code by uploa… | Patch early | 6.8 medium | 4.7% | 2009-05-12 |
| CVE-2015-8728 EXP | The Mobile Identity parser in (1) epan/dissectors/packet-ansi_a.c in the ANSI A dissector and (2) epan/dissectors/packet-gsm_a_common.c in the GSM A d… | Patch early | 5.5 medium | 4.7% | 2016-01-04 |
| CVE-2006-0660 EXP | Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary files or trigger an error mess… | Patch early | 6.4 medium | 4.7% | 2006-02-13 |
| CVE-2010-1186 EXP | Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inje… | Patch early | 4.3 medium | 4.7% | 2010-04-07 |
| CVE-2023-33383 EXP | Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a device reload… | Patch early | 5.3 medium | 4.7% | 2023-08-02 |
| CVE-2002-1079 EXP | Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in a… | Patch early | 5.0 medium | 4.7% | 2002-10-04 |
| CVE-2005-0253 EXP | Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to delete arbitrary files via… | Patch early | 4.0 medium | 4.7% | 2005-05-02 |
| CVE-2008-4584 EXP | Insecure method vulnerability in Chilkat Mail 7.8 ActiveX control (ChilkatCert.dll) allows remote attackers to overwrite arbitrary files via a full pa… | Patch early | 6.8 medium | 4.7% | 2008-10-15 |
| CVE-2011-3607 EXP | Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_set… | Patch early | 4.4 medium | 4.7% | 2011-11-08 |
| CVE-2006-7080 EXP | Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".."… | Patch early | 4.3 medium | 4.7% | 2007-03-02 |
| CVE-2007-4537 EXP | Heap-based buffer overflow in the Huffman decompression algorithm implemented in Skulltag 0.97d-beta4.1 and earlier allows remote attackers to execute… | Patch early | 6.8 medium | 4.7% | 2007-08-27 |
| CVE-2007-2980 EXP | Heap-based buffer overflow in a certain ActiveX control in LEADTOOLS LEAD Raster ISIS Object (LTRIS14e.DLL) 14.5.0.44 allows remote attackers to cause… | Patch early | 6.8 medium | 4.7% | 2007-06-01 |
| CVE-2017-13868 EXP | An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchO… | Patch early | 5.5 medium | 4.7% | 2017-12-25 |
| CVE-2014-4962 EXP | Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantity parame… | Patch early | 6.4 medium | 4.7% | 2014-07-15 |
| CVE-2006-1102 EXP | Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (client exit) by forcing the server to c… | Patch early | 5.0 medium | 4.7% | 2006-03-09 |
| CVE-2019-10226 EXP | HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI. NOTE: the ven… | Patch early | 5.4 medium | 4.7% | 2019-06-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt