CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,514 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
169,001 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-0942 EXP | Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header… | Patch early | 5.0 medium | 55.1% | 2005-02-09 |
| CVE-2015-1833 EXP | XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2… | Patch early | 6.4 medium | 55% | 2015-05-29 |
| CVE-2013-5877 EXP | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 1… | Patch early | 5.0 medium | 55% | 2014-01-15 |
| CVE-2004-0594 EXP | The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allo… | Patch early | 5.1 medium | 54.9% | 2004-07-27 |
| CVE-2008-2168 EXP | Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded… | Patch early | 4.3 medium | 54.9% | 2008-05-13 |
| CVE-2014-5446 EXP | Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allows remote a… | Patch early | 5.0 medium | 54.7% | 2014-12-04 |
| CVE-2010-3863 EXP | Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows r… | Patch early | 5.0 medium | 54.5% | 2010-11-05 |
| CVE-2023-41425 EXP | Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded… | Patch early | 6.1 medium | 54.3% | 2023-11-07 |
| CVE-2006-1993 EXP | Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via cert… | Patch early | 5.1 medium | 54% | 2006-04-25 |
| CVE-2005-0455 EXP | Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlie… | Patch early | 5.1 medium | 54% | 2005-05-02 |
| CVE-2013-3502 EXP | monarch_scan.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands, and… | Patch early | 6.5 medium | 53.7% | 2013-05-08 |
| CVE-2016-5312 EXP | Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbi… | Patch early | 6.5 medium | 53.7% | 2017-04-14 |
| CVE-2016-3209 EXP | Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Se… | Patch early | 5.5 medium | 53.7% | 2016-10-14 |
| CVE-2002-1143 EXP | Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document i… | Patch early | 5.0 medium | 53.6% | 2003-04-11 |
| CVE-2006-6761 EXP | Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code… | Patch early | 6.5 medium | 53.4% | 2006-12-27 |
| CVE-2006-2502 EXP | Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute… | Patch early | 5.1 medium | 53.3% | 2006-05-22 |
| CVE-2022-33098 EXP | Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows att… | Patch early | 6.1 medium | 53.3% | 2022-07-07 |
| CVE-2006-5702 EXP | Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-list… | Patch early | 5.0 medium | 53.3% | 2006-11-04 |
| CVE-1999-0191 EXP | IIS newdsn.exe CGI script allows remote users to overwrite files. | Patch early | 6.4 medium | 53.3% | 1997-09-01 |
| CVE-2009-3591 EXP | Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with an invalid location. | Patch early | 5.0 medium | 52.8% | 2009-10-08 |
| CVE-2022-31470 EXP | An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 a… | Patch early | 6.1 medium | 52.7% | 2022-06-07 |
| CVE-2008-2370 EXP | Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization befo… | Patch early | 5.0 medium | 52.7% | 2008-08-04 |
| CVE-2018-8831 EXP | A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of t… | Patch early | 6.1 medium | 52.7% | 2018-04-18 |
| CVE-2008-2549 EXP | Adobe Acrobat Reader 8.1.2 and earlier, and before 7.1.1, allows remote attackers to cause a denial of service (application crash) and possibly execut… | Patch early | 4.3 medium | 52.6% | 2008-06-04 |
| CVE-2012-5192 EXP | Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to read arbitrary files via "''%2F"… | Patch early | 5.0 medium | 52.5% | 2014-01-28 |
| CVE-2007-3898 EXP | The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, wh… | Patch early | 6.4 medium | 52.3% | 2007-11-14 |
| CVE-2015-1397 EXP | SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1.0 and Ent… | Patch early | 6.5 medium | 52.3% | 2015-04-29 |
| CVE-2012-4031 EXP | Multiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote attackers to read arbitrary files via… | Patch early | 5.0 medium | 52.3% | 2012-07-17 |
| CVE-2019-8953 EXP | The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php… | Patch early | 6.1 medium | 52.2% | 2019-02-20 |
| CVE-2012-0897 EXP | Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (… | Patch early | 6.8 medium | 52.2% | 2012-01-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt