CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,116 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
206,665 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-1908 EXP | The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugi… | Patch early | 5.0 medium | 6.8% | 2014-12-29 |
| CVE-2026-34156 EXP | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's W… | Patch early | 9.9 critical | 6.8% | 2026-03-31 |
| CVE-2002-1818 EXP | ezhttpbench.php in eZ httpbench 1.1 allows remote attackers to read arbitrary files via a full pathname in the AnalyseSite parameter. | Patch early | 5.0 medium | 6.8% | 2002-12-31 |
| CVE-2003-1242 EXP | Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path in an error… | Patch early | 5.0 medium | 6.8% | 2003-12-31 |
| CVE-2013-6835 EXP | TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remote… | Patch early | 5.0 medium | 6.8% | 2014-03-14 |
| CVE-1999-0934 EXP | classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters. | Patch early | 5.0 medium | 6.8% | 1999-12-15 |
| CVE-2015-1389 EXP | Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote attackers to inject arbitrary we… | Patch early | 4.3 medium | 6.8% | 2015-05-28 |
| CVE-2009-2557 EXP | Directory traversal vulnerability in system/download.php in Admin News Tools 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in… | Patch early | 5.0 medium | 6.8% | 2009-07-21 |
| CVE-2017-15639 EXP | tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature. | Patch early | 6.5 medium | 6.8% | 2017-10-19 |
| CVE-2003-0488 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) the add_na… | Patch early | 5.1 medium | 6.8% | 2003-08-07 |
| CVE-2015-3001 EXP | SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which allows remote authenticated user… | Patch early | 5.0 medium | 6.8% | 2015-06-08 |
| CVE-2006-4875 EXP | Unrestricted file upload vulnerability in modules/galleryuploadfunction.php in Jupiter CMS allows remote attackers to upload picture files, and possib… | Patch early | 5.0 medium | 6.8% | 2006-09-19 |
| CVE-2006-6288 EXP | Multiple buffer overflows in Niek Albers CoolPlayer 216 and earlier allow remote attackers to execute arbitrary code via (1) a playlist file with long… | Patch early | 4.6 medium | 6.8% | 2006-12-04 |
| CVE-2020-2229 EXP | Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS)… | Patch early | 5.4 medium | 6.8% | 2020-08-12 |
| CVE-2015-8740 EXP | The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x before 2.0.1 does not validate the… | Patch early | 5.3 medium | 6.8% | 2016-01-04 |
| CVE-2014-8657 EXP | The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to cause a den… | Patch early | 5.0 medium | 6.8% | 2014-11-06 |
| CVE-2003-1137 EXP | Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an as… | Patch early | 5.0 medium | 6.8% | 2003-10-27 |
| CVE-2015-4040 EXP | Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 through 3.1.1 allows remote aut… | Patch early | 4.0 medium | 6.8% | 2015-09-17 |
| CVE-2007-6213 EXP | Multiple directory traversal vulnerabilities in mod/chat/index.php in WebED 0.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in… | Patch early | 5.0 medium | 6.8% | 2007-12-04 |
| CVE-2006-2437 EXP | The viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to obtain the source code for… | Patch early | 5.0 medium | 6.8% | 2006-05-17 |
| CVE-2006-2768 EXP | PHP remote file inclusion vulnerability in METAjour 2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via t… | Patch early | 5.1 medium | 6.7% | 2006-06-02 |
| CVE-2000-0016 EXP | Buffer overflow in Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service or execute commands via a long username. | Patch early | 5.0 medium | 6.7% | 1999-10-01 |
| CVE-2003-0413 EXP | Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Su… | Patch early | 6.8 medium | 6.7% | 2003-06-30 |
| CVE-2005-1125 EXP | Race condition in libsafe 2.0.16 and earlier, when running in multi-threaded applications, allows attackers to bypass libsafe protection and exploit o… | Patch early | 5.1 medium | 6.7% | 2005-05-02 |
| CVE-2017-7089 EXP | An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected.… | Patch early | 6.1 medium | 6.7% | 2017-10-23 |
| CVE-2022-36551 EXP | A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authen… | Patch early | 6.5 medium | 6.7% | 2022-10-03 |
| CVE-2007-6620 EXP | Directory traversal vulnerability in include/images.inc.php in Joovili 2.x allows remote attackers to read arbitrary files via a .. (dot dot) in the p… | Patch early | 6.4 medium | 6.7% | 2008-01-04 |
| CVE-2006-3814 EXP | Buffer overflow in the Loader_XM::load_instrument_internal function in loader_xm.cpp for Cheese Tracker 0.9.9 and earlier allows user-assisted attacke… | Patch early | 5.1 medium | 6.7% | 2006-07-25 |
| CVE-2017-2524 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… | Patch early | 9.8 critical | 6.7% | 2017-05-22 |
| CVE-2006-6426 EXP | PHP remote file inclusion vulnerability in design/thinkedit/render.php in ThinkEdit 1.9.2 and earlier, when register_globals is enabled, allows remote… | Patch early | 6.8 medium | 6.7% | 2006-12-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt