CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,503 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
169,001 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-2087 EXP | Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a… | Patch early | 5.0 medium | 61.4% | 2005-07-05 |
| CVE-2013-1428 EXP | Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated… | Patch early | 6.5 medium | 60.7% | 2013-04-26 |
| CVE-2013-4074 EXP | The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 in… | Patch early | 5.0 medium | 60.6% | 2013-06-09 |
| CVE-2018-3639 EXP | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes… | Patch early | 5.5 medium | 60.6% | 2018-05-22 |
| CVE-2006-5198 EXP | The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers… | Patch early | 4.0 medium | 60.4% | 2006-11-14 |
| CVE-2004-0184 EXP | Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP pack… | Patch early | 5.0 medium | 60.3% | 2004-05-04 |
| CVE-2015-8399 EXP | Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdef… | Patch early | 4.3 medium | 60.2% | 2016-04-11 |
| CVE-2010-2333 EXP | LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a… | Patch early | 5.0 medium | 60.2% | 2010-06-18 |
| CVE-2007-4744 EXP | PHP remote file inclusion vulnerability in environment.php in AnyInventory 1.9.1 and 2.0, when register_globals is enabled, allows remote attackers to… | Patch early | 6.8 medium | 60.1% | 2007-09-06 |
| CVE-2014-100002 EXP | Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot… | Patch early | 5.0 medium | 59.9% | 2015-01-13 |
| CVE-2013-3763 EXP | Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to aff… | Patch early | 5.5 medium | 59.8% | 2013-07-17 |
| CVE-2011-4404 EXP | The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Up… | Patch early | 5.0 medium | 59.7% | 2011-11-19 |
| CVE-2011-4317 EXP | The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch i… | Patch early | 4.3 medium | 59.6% | 2011-11-30 |
| CVE-2013-5880 EXP | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.0, 12.2.1, and 12.2.2 allows r… | Patch early | 5.0 medium | 59.6% | 2014-01-15 |
| CVE-2013-7108 EXP | Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote au… | Patch early | 5.5 medium | 59.5% | 2014-01-15 |
| CVE-2013-5795 EXP | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 1… | Patch early | 5.0 medium | 59.5% | 2014-01-15 |
| CVE-2007-3813 EXP | PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitrary PHP c… | Patch early | 4.3 medium | 59.4% | 2007-07-17 |
| CVE-2015-5603 EXP | The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors,… | Patch early | 6.5 medium | 59.3% | 2015-09-21 |
| CVE-2008-5081 EXP | The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause… | Patch early | 5.0 medium | 59.2% | 2008-12-17 |
| CVE-2018-8770 EXP | Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, contr… | Patch early | 5.3 medium | 59.2% | 2018-03-18 |
| CVE-2019-0221 EXP | The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is,… | Patch early | 6.1 medium | 59.2% | 2019-05-28 |
| CVE-2008-2463 EXP | The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Offic… | Patch early | 6.8 medium | 59.1% | 2008-07-07 |
| CVE-2007-3386 EXP | Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to… | Patch early | 4.3 medium | 59% | 2007-08-14 |
| CVE-2008-0506 EXP | include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows… | Patch early | 6.8 medium | 58.9% | 2008-01-31 |
| CVE-2000-0574 EXP | FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle… | Patch early | 5.0 medium | 58.9% | 2000-07-07 |
| CVE-2006-2212 EXP | Buffer overflow in KarjaSoft Sami FTP Server 2.0.2 and earlier allows remote attackers to execute arbitrary code via a long (1) USER or (2) PASS comma… | Patch early | 6.4 medium | 58.9% | 2006-05-05 |
| CVE-2012-4347 EXP | Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated users to r… | Patch early | 5.0 medium | 58.8% | 2012-12-05 |
| CVE-2013-1559 EXP | Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated… | Patch early | 4.0 medium | 58.8% | 2013-04-17 |
| CVE-2002-0654 EXP | Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .v… | Patch early | 5.0 medium | 58.7% | 2002-09-05 |
| CVE-2004-1305 EXP | The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers… | Patch early | 5.0 medium | 58.6% | 2004-12-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt