CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,295 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
186,519 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-23934 EXP | An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager"… | Patch early | 8.8 high | 16% | 2020-08-18 |
| CVE-2012-1831 EXP | Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 555. | Patch early | 10.0 high | 15.9% | 2012-07-05 |
| CVE-2020-23935 EXP | Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)". | Patch early | 9.8 critical | 15.9% | 2020-08-20 |
| CVE-2017-7455 EXP | Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control. | Patch early | 7.5 high | 15.9% | 2017-04-14 |
| CVE-2017-8869 EXP | Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file. | Patch early | 7.8 high | 15.9% | 2017-07-27 |
| CVE-2020-8639 EXP | An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a fi… | Patch early | 8.8 high | 15.9% | 2020-04-03 |
| CVE-2006-0189 EXP | Buffer overflow in eStara Softphone 3.0.1.14 through 3.0.1.46 allows remote attackers to execute arbitrary code via a long attribute (aka "a") field i… | Patch early | 7.5 high | 15.9% | 2006-01-13 |
| CVE-2004-1439 EXP | Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1) USER, (2) PASS, (3) RETR,(4)… | Patch early | 7.5 high | 15.8% | 2004-12-31 |
| CVE-2019-0571 EXP | An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Ser… | Patch early | 7.8 high | 15.8% | 2019-01-08 |
| CVE-2006-5768 EXP | Multiple PHP remote file inclusion vulnerabilities in Cyberfolio 2.0 RC1 and earlier, when register_globals is enabled, allow remote attackers to exec… | Patch early | 7.5 high | 15.8% | 2006-11-06 |
| CVE-2010-2128 EXP | Directory traversal vulnerability in the JE Quotation Form (com_jequoteform) component 1.0b1 for Joomla! allows remote attackers to read arbitrary fil… | Patch early | 7.5 high | 15.8% | 2010-06-01 |
| CVE-2018-1821 EXP | IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data… | Patch early | 7.1 high | 15.8% | 2018-12-13 |
| CVE-2010-2033 EXP | Directory traversal vulnerability in the Percha Multicategory Article (com_perchacategoriestree) component 0.6 for Joomla! allows remote attackers to… | Patch early | 7.5 high | 15.8% | 2010-05-25 |
| CVE-2020-10230 EXP | CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parame… | Patch early | 9.8 critical | 15.8% | 2020-03-16 |
| CVE-2012-5409 EXP | AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet netwo… | Patch early | 10.0 high | 15.8% | 2012-11-01 |
| CVE-2016-7866 EXP | Adobe Animate versions 15.2.1.95 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code… | Patch early | 9.8 critical | 15.8% | 2016-12-15 |
| CVE-2017-3549 EXP | Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Supported versions that are affec… | Patch early | 9.1 critical | 15.8% | 2017-04-24 |
| CVE-2010-2035 EXP | Directory traversal vulnerability in the Percha Gallery (com_perchagallery) component 1.6 Beta for Joomla! allows remote attackers to read arbitrary f… | Patch early | 7.5 high | 15.8% | 2010-05-25 |
| CVE-2025-4094 EXP | The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightfo… | Patch early | 9.8 critical | 15.8% | 2025-05-21 |
| CVE-2022-2651 EXP | Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5. | Patch early | 9.8 critical | 15.8% | 2022-08-04 |
| CVE-2005-0566 EXP | Buffer overflow in Golden FTP Server Pro (goldenftpd) 2.x allows remote attackers to execute arbitrary code via a long RNTO command. | Patch early | 7.5 high | 15.7% | 2005-01-22 |
| CVE-2010-1759 EXP | Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows r… | Patch early | 9.3 high | 15.7% | 2010-06-11 |
| CVE-2021-43136 EXP | An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platfor… | Patch early | 9.8 critical | 15.7% | 2021-11-10 |
| CVE-2011-1206 EXP | Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before… | Patch early | 10.0 high | 15.7% | 2011-04-21 |
| CVE-2010-1306 EXP | Directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote attackers to read arbitrary loca… | Patch early | 7.5 high | 15.7% | 2010-04-08 |
| CVE-2010-1875 EXP | Directory traversal vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to read arbitra… | Patch early | 7.5 high | 15.7% | 2010-05-12 |
| CVE-2018-1218 EXP | In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the 'nsrd' daemon causes a buffer o… | Patch early | 7.5 high | 15.7% | 2018-03-19 |
| CVE-2010-2351 EXP | Stack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remote attackers to execute arbitr… | Patch early | 10.0 high | 15.7% | 2010-06-21 |
| CVE-2006-4489 EXP | Multiple PHP remote file inclusion vulnerabilities in MiniBill 2006-07-14 (1.2.2) allow remote attackers to execute arbitrary PHP code via (1) a URL i… | Patch early | 7.5 high | 15.7% | 2006-08-31 |
| CVE-2019-3924 EXP | MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The software will execute user defin… | Patch early | 7.5 high | 15.7% | 2019-02-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt