CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,522 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
149,888 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-3437 EXP | The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requ… | Patch early | 7.5 high | 8.5% | 2014-11-07 |
| CVE-2006-3970 EXP | PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows remote attackers to execute arb… | Patch early | 7.5 high | 8.5% | 2006-08-01 |
| CVE-2000-0187 EXP | EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metachar… | Patch early | 7.5 high | 8.5% | 2000-02-27 |
| CVE-2008-0396 EXP | Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Ente… | Patch early | 7.8 high | 8.5% | 2008-01-23 |
| CVE-2008-1262 EXP | The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote… | Patch early | 10.0 high | 8.5% | 2008-03-10 |
| CVE-2007-2364 EXP | Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the ro… | Patch early | 7.5 high | 8.5% | 2007-04-30 |
| CVE-2014-0242 EXP | mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type h… | Patch early | 7.5 high | 8.5% | 2019-12-09 |
| CVE-2007-0684 EXP | PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 8.5% | 2007-02-03 |
| CVE-2014-0329 EXP | The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remote attacker… | Patch early | 9.3 high | 8.5% | 2014-02-04 |
| CVE-2012-2441 EXP | RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes i… | Patch early | 8.5 high | 8.5% | 2012-04-28 |
| CVE-2008-0151 EXP | Heap-based buffer overflow in Foxit WAC Server 2.1.0.910, 2.0 Build 3503, and earlier allows remote attackers to cause a denial of service (crash) and… | Patch early | 10.0 high | 8.5% | 2008-01-09 |
| CVE-2018-1038 EXP | The Windows kernel in Windows 7 SP1 and Windows Server 2008 R2 SP1 allows an elevation of privilege vulnerability due to the way it handles objects in… | Patch early | 7.8 high | 8.5% | 2018-04-02 |
| CVE-2017-9746 EXP | The disassemble_bytes function in objdump.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application… | Patch early | 7.8 high | 8.5% | 2017-06-19 |
| CVE-2017-9749 EXP | The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer overflow and application cras… | Patch early | 7.8 high | 8.5% | 2017-06-19 |
| CVE-2010-3313 EXP | phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly… | Patch early | 7.5 high | 8.5% | 2010-09-22 |
| CVE-2009-3710 EXP | RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel, which allows remote attacker… | Patch early | 10.0 high | 8.5% | 2009-10-16 |
| CVE-2018-20658 EXP | The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD comman… | Patch early | 7.5 high | 8.5% | 2019-01-02 |
| CVE-2006-4437 EXP | Eval injection vulnerability in Tagger LE allows remote attackers to execute arbitrary PHP code via the query string in (1) tags.php, (2) sign.php, an… | Patch early | 7.5 high | 8.5% | 2006-09-14 |
| CVE-2013-7392 EXP | Gitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/. | Patch early | 7.5 high | 8.5% | 2014-07-22 |
| CVE-2007-3701 EXP | TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which might allow remote attackers to… | Patch early | 7.5 high | 8.5% | 2007-07-11 |
| CVE-2017-14704 EXP | Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remo… | Patch early | 8.8 high | 8.5% | 2017-09-26 |
| CVE-2006-0549 EXP | SQL injection vulnerability in the SYS.DBMS_METADATA_UTIL package in Oracle Database 10g, and possibly earlier versions, might allow remote attackers… | Patch early | 7.5 high | 8.5% | 2006-02-04 |
| CVE-2017-2471 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. watchOS before 3.2 is affected. The is… | Patch early | 8.8 high | 8.5% | 2017-04-02 |
| CVE-2017-1000499 EXP | phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to… | Patch early | 8.8 high | 8.5% | 2018-01-03 |
| CVE-2015-8566 EXP | The Session package 1.x before 1.3.1 for Joomla! Framework allows remote attackers to execute arbitrary code via unspecified session values. | Patch early | 7.5 high | 8.5% | 2015-12-16 |
| CVE-2007-5984 EXP | classes/Url.php in Justin Hagstrom AutoIndex PHP Script before 2.2.4 allows remote attackers to cause a denial of service (CPU and memory consumption)… | Patch early | 7.8 high | 8.5% | 2007-11-15 |
| CVE-2009-2110 EXP | Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arb… | Patch early | 7.6 high | 8.4% | 2009-06-18 |
| CVE-2006-0644 EXP | Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 allow remote attackers to includ… | Patch early | 7.5 high | 8.4% | 2006-02-10 |
| CVE-2015-7571 EXP | Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploading a file with an executable ex… | Patch early | 7.8 high | 8.4% | 2017-08-07 |
| CVE-2006-5820 EXP | The LinkSBIcons method in the SuperBuddy ActiveX control (Sb.SuperBuddy.1) in America Online 9.0 Security Edition dereferences an arbitrary function p… | Patch early | 9.3 high | 8.4% | 2007-04-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt