CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,317 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
319,881 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-9054 EXP | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor… | Patch early | 8.8 high | 15.6% | 2024-10-04 |
| CVE-2013-0291 EXP | NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability | Patch early | 7.5 high | 15.6% | 2020-01-30 |
| CVE-2018-8719 EXP | An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not res… | Patch early | 5.3 medium | 15.6% | 2018-04-04 |
| CVE-2013-7051 EXP | D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters | Patch early | 8.8 high | 15.6% | 2020-02-04 |
| CVE-2006-4236 EXP | Multiple PHP remote file inclusion vulnerabilities in POWERGAP allow remote attackers to execute arbitrary PHP code via a URL in the (1) shopid parame… | Patch early | 7.5 high | 15.6% | 2006-08-21 |
| CVE-2001-0100 EXP | bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address. | Patch early | 10.0 high | 15.6% | 2001-02-12 |
| CVE-2006-2864 EXP | Multiple PHP remote file inclusion vulnerabilities in BlueShoes Framework 4.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1… | Patch early | 5.1 medium | 15.6% | 2006-06-06 |
| CVE-2006-3340 EXP | Multiple PHP remote file inclusion vulnerabilities in Pearl For Mambo module 1.6 for Mambo, when register_globals is enabled, allow remote attackers t… | Patch early | 5.1 medium | 15.6% | 2006-07-03 |
| CVE-2006-5302 EXP | Multiple PHP remote file inclusion vulnerabilities in Redaction System 1.0000 allow remote attackers to execute arbitrary PHP code via a URL in the (1… | Patch early | 7.5 high | 15.6% | 2006-10-17 |
| CVE-2003-1378 EXP | Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via… | Patch early | 8.8 high | 15.6% | 2003-12-31 |
| CVE-2010-0187 EXP | Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow remote attackers to cause a denial of service (application crash) via a modi… | Patch early | 4.3 medium | 15.6% | 2010-02-15 |
| CVE-2020-25790 EXP | Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes… | Patch early | 7.2 high | 15.6% | 2020-09-19 |
| CVE-2016-0793 EXP | Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on W… | Patch early | 7.5 high | 15.6% | 2016-04-01 |
| CVE-2008-0912 EXP | Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10.0.1.3415… | Patch early | 10.0 high | 15.6% | 2008-02-22 |
| CVE-2008-0671 EXP | Stack-based buffer overflow in the add_line_buffer function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attackers to execute arbitrary code v… | Patch early | 10.0 high | 15.6% | 2008-02-12 |
| CVE-2017-6554 EXP | pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to write to arbitrary files and con… | Patch early | 7.2 high | 15.6% | 2017-04-14 |
| CVE-2006-6421 EXP | Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to i… | Patch early | 6.0 medium | 15.6% | 2006-12-10 |
| CVE-2012-0874 EXP | The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EW… | Patch early | 6.8 medium | 15.6% | 2013-02-05 |
| CVE-2010-1601 EXP | Directory traversal vulnerability in the JA Comment (com_jacomment) component for Joomla! allows remote attackers to read arbitrary files via a .. (do… | Patch early | 5.0 medium | 15.6% | 2010-04-29 |
| CVE-2022-1103 EXP | The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could… | Patch early | 8.8 high | 15.6% | 2022-05-16 |
| CVE-2017-2547 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" co… | Patch early | 8.8 high | 15.5% | 2017-05-22 |
| CVE-2008-0177 EXP | The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldo… | Patch early | 7.8 high | 15.5% | 2008-02-07 |
| CVE-2015-7250 EXP | Absolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to rea… | Patch early | 7.5 high | 15.5% | 2015-12-30 |
| CVE-2002-0005 EXP | Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long arg… | Patch early | 10.0 high | 15.5% | 2002-01-31 |
| CVE-2005-3560 EXP | Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1,… | Patch early | 7.5 high | 15.5% | 2005-11-16 |
| CVE-2018-1041 EXP | A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could… | Patch early | 7.5 high | 15.5% | 2018-02-15 |
| CVE-2006-4059 EXP | Multiple PHP remote file inclusion vulnerabilities in USOLVED NEWSolved Lite 1.9.2, and possibly earlier, allow remote attackers to execute arbitrary… | Patch early | 7.5 high | 15.5% | 2006-08-10 |
| CVE-2007-4646 EXP | Buffer overflow in the pop3 service in Hexamail Server 3.0.0.001 Lite allows remote attackers to cause a denial of service (daemon crash) and probably… | Patch early | 10.0 high | 15.5% | 2007-08-31 |
| CVE-2009-3373 EXP | Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote at… | Patch early | 10.0 high | 15.5% | 2009-10-29 |
| CVE-2007-2666 EXP | Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attac… | Patch early | 7.6 high | 15.5% | 2007-05-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt