CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,546 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
149,895 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-7031 EXP | Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of service (crash)… | Patch early | 10.0 high | 8.3% | 2009-08-24 |
| CVE-2006-2834 EXP | PHP remote file inclusion vulnerability in includes/common.php in gnopaste 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 8.2% | 2006-06-06 |
| CVE-2010-3135 EXP | Untrusted search path vulnerability in Cisco Packet Tracer 5.2 allows local users, and possibly remote attackers, to execute arbitrary code and conduc… | Patch early | 9.3 high | 8.2% | 2010-08-26 |
| CVE-2016-9332 EXP | An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate input. An attacker could prov… | Patch early | 7.5 high | 8.2% | 2017-02-13 |
| CVE-2005-0316 EXP | WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which co… | Patch early | 7.5 high | 8.2% | 2005-01-28 |
| CVE-2009-4251 EXP | Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers to execute arbitrary code via… | Patch early | 9.3 high | 8.2% | 2009-12-10 |
| CVE-2007-4907 EXP | Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a URL in the xcart_dir parameter… | Patch early | 7.5 high | 8.2% | 2007-09-17 |
| CVE-2019-17080 EXP | mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickl… | Patch early | 7.8 high | 8.2% | 2019-10-02 |
| CVE-2007-2274 EXP | The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and application crash) via a malforme… | Patch early | 7.8 high | 8.2% | 2007-04-25 |
| CVE-2007-2372 EXP | admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentia… | Patch early | 10.0 high | 8.2% | 2007-04-30 |
| CVE-2017-11398 EXP | A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthe… | Patch early | 8.8 high | 8.2% | 2018-01-19 |
| CVE-2018-14336 EXP | TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets with random MAC addresses. | Patch early | 7.5 high | 8.2% | 2018-07-19 |
| CVE-2009-3625 EXP | Directory traversal vulnerability in www/index.php in Sahana 0.6.2.2 allows remote attackers to include and execute arbitrary local files via a .. (do… | Patch early | 7.5 high | 8.2% | 2009-10-26 |
| CVE-2012-4354 EXP | TCPIPS_Story.dll in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allows remote attackers to execute arbitrary c… | Patch early | 9.3 high | 8.2% | 2012-08-19 |
| CVE-2012-4355 EXP | TCPIPS_Story.dll in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 allows remote attackers to execute arbitrary c… | Patch early | 9.3 high | 8.2% | 2012-08-19 |
| CVE-2004-1118 EXP | Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.… | Patch early | 10.0 high | 8.2% | 2005-01-10 |
| CVE-2019-16645 EXP | An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostnam… | Patch early | 8.6 high | 8.2% | 2019-09-20 |
| CVE-2007-2608 EXP | PHP remote file inclusion vulnerability in lib/smarty/SmartyFU.class.php in Miplex2 Alpha 1 allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 8.2% | 2007-05-11 |
| CVE-2007-3432 EXP | Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jpg… | Patch early | 7.5 high | 8.2% | 2007-06-27 |
| CVE-2003-0339 EXP | Multiple heap-based buffer overflows in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allow remote attackers to execute arbitrary code via long HTTP reques… | Patch early | 7.5 high | 8.2% | 2003-05-22 |
| CVE-2008-6604 EXP | Directory traversal vulnerability in index.php in PicoFlat CMS 0.5.9 allows remote attackers to include and execute arbitrary local files via a .. (do… | Patch early | 10.0 high | 8.2% | 2009-04-04 |
| CVE-2006-3475 EXP | Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the qb_path pa… | Patch early | 7.5 high | 8.2% | 2006-07-10 |
| CVE-2007-2570 EXP | PHP remote file inclusion vulnerability in handlers/page/show.php in Wikivi5 allows remote attackers to execute arbitrary PHP code via a URL in the so… | Patch early | 7.5 high | 8.2% | 2007-05-09 |
| CVE-2008-4748 EXP | Format string vulnerability in the URI handler in KVirc 3.4.0, when set as the default application for processing IRC URIs, allows remote attackers to… | Patch early | 7.6 high | 8.2% | 2008-10-27 |
| CVE-2007-3621 EXP | Multiple CRLF injection vulnerabilities in callboth.php in AsteriDex 3.0 and earlier allow remote attackers to inject arbitrary shell commands via the… | Patch early | 7.5 high | 8.2% | 2007-07-09 |
| CVE-2017-5881 EXP | GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafte… | Patch early | 7.8 high | 8.2% | 2017-02-21 |
| CVE-2017-9614 EXP | The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and ap… | Patch early | 8.8 high | 8.2% | 2017-07-27 |
| CVE-2019-11369 EXP | An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensiti… | Patch early | 8.8 high | 8.1% | 2019-06-03 |
| CVE-2006-4849 EXP | PHP remote file inclusion vulnerability in header.php in MobilePublisherPHP 1.5 RC2 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 8.1% | 2006-09-19 |
| CVE-2003-0118 EXP | SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attacker… | Patch early | 7.5 high | 8.1% | 2003-05-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt