CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,488 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
149,881 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-2680 EXP | Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive information. | Patch early | 7.5 high | 8.7% | 2020-02-05 |
| CVE-2001-1199 EXP | Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to execute Javascript… | Patch early | 7.5 high | 8.7% | 2001-12-17 |
| CVE-2019-15943 EXP | vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by creating a… | Patch early | 8.8 high | 8.7% | 2019-09-19 |
| CVE-2013-5745 EXP | The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, d… | Patch early | 7.1 high | 8.7% | 2013-10-01 |
| CVE-1999-0176 EXP | The Webgais program allows a remote user to execute arbitrary commands. | Patch early | 7.5 high | 8.7% | 1997-07-10 |
| CVE-1999-0207 EXP | Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command. | Patch early | 7.5 high | 8.7% | 1994-06-09 |
| CVE-2005-2885 EXP | The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which… | Patch early | 7.5 high | 8.7% | 2005-09-14 |
| CVE-1999-0147 EXP | The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands. | Patch early | 7.5 high | 8.7% | 1997-07-01 |
| CVE-2003-0470 EXP | Buffer overflow in the "RuFSI Utility Class" ActiveX control (aka "RuFSI Registry Information Class"), as used for the Symantec Security Check service… | Patch early | 7.5 high | 8.7% | 2003-08-07 |
| CVE-2001-0596 EXP | Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascript. | Patch early | 7.5 high | 8.7% | 2001-08-02 |
| CVE-2008-0493 EXP | fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which… | Patch early | 9.3 high | 8.7% | 2008-01-30 |
| CVE-2008-4343 EXP | The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to create, overwrite, and modify ar… | Patch early | 9.3 high | 8.7% | 2008-09-30 |
| CVE-2016-4313 EXP | Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a .. (dot dot) in… | Patch early | 7.8 high | 8.7% | 2017-04-24 |
| CVE-2004-1915 EXP | Buffer overflow in the parse_all_client_messages function in LCDproc 0.4.x up to 0.4.4 allows remote attackers to execute arbitrary code via a large n… | Patch early | 7.5 high | 8.7% | 2004-04-08 |
| CVE-2016-8024 EXP | Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows… | Patch early | 8.1 high | 8.7% | 2017-03-14 |
| CVE-2007-2338 EXP | Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unauthorized b… | Patch early | 7.5 high | 8.7% | 2007-04-27 |
| CVE-2009-3904 EXP | classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to… | Patch early | 7.5 high | 8.7% | 2009-11-06 |
| CVE-2009-2550 EXP | Stack-based buffer overflow in Hamster Audio Player 0.3a allows remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .hpl… | Patch early | 9.3 high | 8.7% | 2009-07-20 |
| CVE-2006-4780 EXP | PHP remote file inclusion vulnerability in includes/functions.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 8.7% | 2006-09-14 |
| CVE-2007-1735 EXP | Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute arbitrary code via a long pri… | Patch early | 9.3 high | 8.7% | 2007-03-28 |
| CVE-2006-4823 EXP | PHP remote file inclusion vulnerability in scripts/news_page.php in Reamday Enterprises Magic News Pro 1.0.3 and earlier allows remote attackers to ex… | Patch early | 7.5 high | 8.7% | 2006-09-15 |
| CVE-2000-1023 EXP | The Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers to modify domain name informati… | Patch early | 7.5 high | 8.6% | 2000-12-11 |
| CVE-2002-1222 EXP | Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of ser… | Patch early | 7.1 high | 8.6% | 2002-10-28 |
| CVE-2008-5334 EXP | PHP remote file inclusion vulnerability in includes/common.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 10.0 high | 8.6% | 2008-12-05 |
| CVE-2017-11154 EXP | Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to c… | Patch early | 7.2 high | 8.6% | 2017-08-08 |
| CVE-2022-46604 EXP | An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP fil… | Patch early | 8.8 high | 8.6% | 2023-02-02 |
| CVE-2005-4135 EXP | Direct static code injection vulnerability in includes/newtopic.php in SimpleBBS 1.1 and earlier allows remote attackers to execute arbitrary commands… | Patch early | 7.5 high | 8.6% | 2005-12-09 |
| CVE-2010-3133 EXP | Untrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and 1.2.0 through 1.2.10 allows local users, and possibly remote attackers, to e… | Patch early | 9.3 high | 8.6% | 2010-08-26 |
| CVE-2002-0552 EXP | Multiple buffer overflows in Melange Chat server 2.02 allow remote or local attackers to cause a denial of service (crash) and possibly execute arbitr… | Patch early | 7.5 high | 8.6% | 2002-07-03 |
| CVE-2003-0328 EXP | EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service (crash) and… | Patch early | 7.5 high | 8.6% | 2003-06-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt