CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,488 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
170,124 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-0268 EXP | Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP… | Patch early | 5.0 medium | 3.4% | 2004-11-23 |
| CVE-2007-6403 EXP | Stack-based buffer overflow in Nullsoft Winamp 5.32 allows user-assisted remote attackers to execute arbitrary code via crafted unicode in a .mp4 file… | Patch early | 6.8 medium | 3.4% | 2007-12-17 |
| CVE-2006-6703 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Oracle Portal 9i and 10g allow remote attackers to inject arbitrary JavaScript via the tc param… | Patch early | 6.8 medium | 3.4% | 2006-12-23 |
| CVE-2018-0969 EXP | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel… | Patch early | 5.5 medium | 3.4% | 2018-04-12 |
| CVE-2018-0970 EXP | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel… | Patch early | 5.5 medium | 3.4% | 2018-04-12 |
| CVE-2018-0971 EXP | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel… | Patch early | 5.5 medium | 3.4% | 2018-04-12 |
| CVE-2018-0972 EXP | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel… | Patch early | 5.5 medium | 3.4% | 2018-04-12 |
| CVE-2018-0973 EXP | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel… | Patch early | 5.5 medium | 3.4% | 2018-04-12 |
| CVE-2018-0974 EXP | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel… | Patch early | 5.5 medium | 3.4% | 2018-04-12 |
| CVE-2017-18344 EXP | The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly validate the sigevent->sigev_… | Patch early | 5.5 medium | 3.4% | 2018-07-26 |
| CVE-2007-1487 EXP | Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote attackers to read arbitrary f… | Patch early | 5.0 medium | 3.4% | 2007-03-16 |
| CVE-2007-2050 EXP | Multiple directory traversal vulnerabilities in header.php in RicarGBooK 1.2.1 allow remote attackers to include and execute arbitrary local files via… | Patch early | 5.0 medium | 3.4% | 2007-04-16 |
| CVE-2007-0177 EXP | Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2, wh… | Patch early | 5.1 medium | 3.4% | 2007-01-11 |
| CVE-2004-0247 EXP | The client and server of Chaser 1.50 and earlier allow remote attackers to cause a denial of service (crash via exception) via a UDP packet with a len… | Patch early | 5.0 medium | 3.4% | 2004-11-23 |
| CVE-2010-1143 EXP | Cross-site scripting (XSS) vulnerability in VMware View (formerly Virtual Desktop Manager or VDM) 3.1.x before 3.1.3 build 252693 allows remote attack… | Patch early | 4.3 medium | 3.4% | 2010-05-07 |
| CVE-2006-6277 EXP | Directory traversal vulnerability in admin/FileServer.php in ContentServ 4.x allows remote attackers to read arbitrary files via a .. (dot dot) in the… | Patch early | 5.0 medium | 3.4% | 2006-12-04 |
| CVE-2007-1929 EXP | Directory traversal vulnerability in downloadpic.php in Beryo 2.0, and possibly other versions including 2.4, allows remote attackers to read arbitrar… | Patch early | 5.0 medium | 3.4% | 2007-04-10 |
| CVE-2005-3128 EXP | Cross-site scripting (XSS) vulnerability in add.php in Address Add Plugin 1.9 and 2.0 for Squirrelmail allows remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 3.4% | 2005-10-04 |
| CVE-2008-6946 EXP | Cross-site scripting (XSS) vulnerability in manageproject.php in Collabtive 0.4.8 allows user-assisted remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 3.4% | 2009-08-12 |
| CVE-2009-2544 EXP | Directory traversal vulnerability in the Marcelo Costa FileServer component 1.0 for Microsoft Windows Live Messenger and Messenger Plus! Live (MPL) al… | Patch early | 6.8 medium | 3.4% | 2009-07-20 |
| CVE-2006-4161 EXP | Directory traversal vulnerability in the avatar_gallery action in profile.php in XennoBB 2.1.0 and earlier allows remote attackers to read arbitrary f… | Patch early | 5.0 medium | 3.4% | 2006-08-16 |
| CVE-2007-1247 EXP | Multiple PHP remote file inclusion vulnerabilities in aWeb Labs aWebNews 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the pat… | Patch early | 6.8 medium | 3.4% | 2007-03-03 |
| CVE-2001-0454 EXP | Directory traversal vulnerability in SlimServe HTTPd 1.1a allows remote attackers to read arbitrary files via a ... (modified dot dot) in the HTTP req… | Patch early | 5.0 medium | 3.4% | 2001-06-27 |
| CVE-2008-0465 EXP | Directory traversal vulnerability in optimizer.php in Seagull 0.6.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the files pa… | Patch early | 5.0 medium | 3.4% | 2008-01-25 |
| CVE-2020-13152 EXP | A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will trigger a memory leak, whereby Am… | Patch early | 5.5 medium | 3.4% | 2020-05-20 |
| CVE-2011-3852 EXP | Cross-site scripting (XSS) vulnerability in the EvoLve theme before 1.2.6 for WordPress allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3.4% | 2011-09-28 |
| CVE-2011-3855 EXP | Cross-site scripting (XSS) vulnerability in the F8 Lite theme before 4.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 3.4% | 2011-09-28 |
| CVE-2011-3859 EXP | Cross-site scripting (XSS) vulnerability in the Trending theme before 0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3.4% | 2011-09-28 |
| CVE-2011-3863 EXP | Cross-site scripting (XSS) vulnerability in the RedLine theme before 1.66 for WordPress allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3.4% | 2011-09-28 |
| CVE-2011-4713 EXP | Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot… | Patch early | 5.0 medium | 3.4% | 2011-12-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt