CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,567 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
320,061 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-8870 EXP | Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file. | Patch early | 7.8 high | 13.7% | 2017-07-27 |
| CVE-2002-1603 EXP | GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /),… | Patch early | 5.0 medium | 13.7% | 2002-02-13 |
| CVE-2007-3536 EXP | Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers to execute arbitrary code via… | Patch early | 7.6 high | 13.7% | 2007-07-03 |
| CVE-2007-0562 EXP | Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (applicat… | Patch early | 4.3 medium | 13.7% | 2007-01-30 |
| CVE-2008-3657 EXP | The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of input… | Patch early | 7.5 high | 13.7% | 2008-08-13 |
| CVE-2009-1759 EXP | Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent) 3.3.2 and probably earlier, a… | Patch early | 9.3 high | 13.7% | 2009-05-22 |
| CVE-2010-4254 EXP | Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote a… | Patch early | 7.5 high | 13.6% | 2010-12-06 |
| CVE-2012-3577 EXP | Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to ex… | Patch early | 7.5 high | 13.6% | 2012-06-17 |
| CVE-2025-50286 EXP | A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct… | Patch early | 8.1 high | 13.6% | 2025-08-06 |
| CVE-2022-30286 EXP | pyscriptjs (aka PyScript Demonstrator) in PyScript through 2022-05-04 allows a remote user to read Python source code. | Patch early | 7.5 high | 13.6% | 2022-05-09 |
| CVE-2010-3144 EXP | Untrusted search path vulnerability in the Internet Connection Signup Wizard in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local user… | Patch early | 9.3 high | 13.6% | 2010-08-27 |
| CVE-2010-3148 EXP | Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the curr… | Patch early | 9.3 high | 13.6% | 2010-08-27 |
| CVE-2007-2052 EXP | Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the… | Patch early | 5.0 medium | 13.6% | 2007-04-16 |
| CVE-2002-1487 EXP | The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by sending the raw messages (1) 2… | Patch early | 5.0 medium | 13.6% | 2003-04-02 |
| CVE-2002-1522 EXP | Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute ar… | Patch early | 5.0 medium | 13.6% | 2003-04-02 |
| CVE-2024-11728 EXP | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter… | Patch early | 7.5 high | 13.6% | 2024-12-06 |
| CVE-2006-2686 EXP | PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[AA_INC_PAT… | Patch early | 6.4 medium | 13.6% | 2006-05-31 |
| CVE-2020-11027 EXP | In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to… | Patch early | 6.1 medium | 13.6% | 2020-04-30 |
| CVE-2010-1312 EXP | Directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote attackers to read arbitrary f… | Patch early | 5.0 medium | 13.6% | 2010-04-08 |
| CVE-2010-1340 EXP | Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote attackers to read arbitrary f… | Patch early | 5.0 medium | 13.6% | 2010-04-09 |
| CVE-2010-1534 EXP | Directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (d… | Patch early | 5.0 medium | 13.6% | 2010-04-26 |
| CVE-2010-1858 EXP | Directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote attackers to read arbitrary files… | Patch early | 5.0 medium | 13.6% | 2010-05-07 |
| CVE-2008-4787 EXP | Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a URL with a hostname containing… | Patch early | 5.8 medium | 13.6% | 2008-10-29 |
| CVE-2007-5849 EXP | Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute… | Patch early | 9.3 high | 13.6% | 2007-12-19 |
| CVE-2019-7391 EXP | ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF. | Patch early | 8.8 high | 13.6% | 2019-03-21 |
| CVE-2002-0189 EXP | Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that explo… | Patch early | 7.5 high | 13.6% | 2002-05-29 |
| CVE-2010-1352 EXP | Directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote attackers to read arbitrary fi… | Patch early | 5.0 medium | 13.6% | 2010-04-12 |
| CVE-2010-1491 EXP | Directory traversal vulnerability in the MMS Blog (com_mmsblog) component 2.3.0 for Joomla! allows remote attackers to read arbitrary files and possib… | Patch early | 5.0 medium | 13.6% | 2010-04-23 |
| CVE-2002-0682 EXP | Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /s… | Patch early | 7.5 high | 13.6% | 2002-07-23 |
| CVE-2006-3121 EXP | The peel_netstring function in cl_netstring.c in the heartbeat subsystem in High-Availability Linux before 1.2.5, and 2.0 before 2.0.7, allows remote… | Patch early | 5.0 medium | 13.6% | 2006-08-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt