CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,546 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
149,895 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-1999-1508 EXP | Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented UR… | Patch early | 10.0 high | 8.1% | 1999-11-16 |
| CVE-2015-1371 EXP | Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code by uploading a file with an exe… | Patch early | 7.5 high | 8.1% | 2015-01-27 |
| CVE-2000-1093 EXP | Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command. | Patch early | 7.5 high | 8.1% | 2001-01-09 |
| CVE-1999-1521 EXP | Computalynx CMail 2.4 and CMail 2.3 SP2 SMTP servers are vulnerable to a buffer overflow attack in the MAIL FROM command that may allow a remote attac… | Patch early | 10.0 high | 8.1% | 1999-09-12 |
| CVE-2008-0763 EXP | Stack-based buffer overflow in NPSpcSVR.exe in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier allows remote attackers to execute arb… | Patch early | 10.0 high | 8.1% | 2008-02-13 |
| CVE-2002-1656 EXP | X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via sniffing or th… | Patch early | 7.5 high | 8.1% | 2002-12-31 |
| CVE-2017-14523 EXP | WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that ex… | Patch early | 7.5 high | 8% | 2018-01-26 |
| CVE-2017-6823 EXP | Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action. | Patch early | 8.8 high | 8% | 2017-03-12 |
| CVE-2007-0873 EXP | nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) config_ed… | Patch early | 7.5 high | 8% | 2007-02-12 |
| CVE-2017-2491 EXP | Use after free vulnerability in the String.replace method JavaScriptCore in Apple Safari in iOS before 10.3 allows remote attackers to execute arbitra… | Patch early | 8.8 high | 8% | 2017-06-27 |
| CVE-2007-2371 EXP | admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows re… | Patch early | 10.0 high | 8% | 2007-04-30 |
| CVE-2013-1638 EXP | Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document. | Patch early | 9.3 high | 8% | 2013-02-08 |
| CVE-2007-2317 EXP | Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other products, allow… | Patch early | 7.5 high | 8% | 2007-04-26 |
| CVE-2007-2891 EXP | Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_da… | Patch early | 7.5 high | 8% | 2007-05-30 |
| CVE-2002-0733 EXP | Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, whi… | Patch early | 7.5 high | 8% | 2002-08-12 |
| CVE-2007-2429 EXP | ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for t… | Patch early | 10.0 high | 8% | 2007-05-02 |
| CVE-2017-7056 EXP | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… | Patch early | 8.8 high | 8% | 2017-07-20 |
| CVE-2008-3317 EXP | admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrar… | Patch early | 7.5 high | 8% | 2008-07-25 |
| CVE-2008-2888 EXP | Multiple PHP remote file inclusion vulnerabilities in MiGCMS 2.0.5, when register_globals is enabled, allow remote attackers to execute arbitrary PHP… | Patch early | 10.0 high | 8% | 2008-06-27 |
| CVE-2018-8002 EXP | In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack… | Patch early | 8.8 high | 8% | 2018-03-09 |
| CVE-2006-2020 EXP | Asterisk Recording Interface (ARI) in Asterisk@Home before 2.8 stores recordings/includes/main.conf under the web document root with insufficient acce… | Patch early | 7.8 high | 8% | 2006-04-25 |
| CVE-2005-3519 EXP | Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and include arbitrary local files… | Patch early | 7.5 high | 8% | 2005-11-06 |
| CVE-2000-0133 EXP | Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD, XRMD, APPE, SIZE, and RNFR co… | Patch early | 10.0 high | 8% | 2000-02-01 |
| CVE-2007-5156 EXP | Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS,… | Patch early | 7.5 high | 8% | 2007-10-01 |
| CVE-2017-16902 EXP | On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or loginUsername field to goform/logi… | Patch early | 7.5 high | 8% | 2017-11-20 |
| CVE-2014-5287 EXP | A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI)… | Patch early | 8.8 high | 8% | 2020-01-08 |
| CVE-2018-18865 EXP | The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13) allow Credentials Disclosure… | Patch early | 8.1 high | 8% | 2018-11-20 |
| CVE-2004-2286 EXP | Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary… | Patch early | 7.5 high | 8% | 2004-12-31 |
| CVE-2006-4329 EXP | Multiple PHP remote file inclusion vulnerabilities in Shadows Rising RPG (Pre-Alpha) 0.0.5b and earlier allow remote attackers to execute arbitrary PH… | Patch early | 7.5 high | 8% | 2006-08-24 |
| CVE-2011-3493 EXP | Multiple stack-based buffer overflows in the DH_OneSecondTick function in Cogent DataHub 7.1.1.63 and earlier allow remote attackers to cause a denial… | Patch early | 10.0 high | 8% | 2011-09-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt