CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,573 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
320,066 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-4711 EXP | Double free vulnerability in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allows remote attackers to… | Patch early | 10.0 high | 13.6% | 2011-01-31 |
| CVE-2012-4415 EXP | Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of… | Patch early | 7.5 high | 13.6% | 2012-10-01 |
| CVE-2004-0277 EXP | Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via for… | Patch early | 10.0 high | 13.6% | 2004-11-23 |
| CVE-2015-6589 EXP | Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0… | Patch early | 8.8 high | 13.6% | 2020-02-13 |
| CVE-2006-0179 EXP | The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary p… | Patch early | 5.0 medium | 13.6% | 2006-01-11 |
| CVE-1999-0140 EXP | Denial of service in RAS/PPTP on NT systems. | Patch early | 5.0 medium | 13.6% | 1999-06-30 |
| CVE-2006-4227 EXP | MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine… | Patch early | 6.5 medium | 13.6% | 2006-08-18 |
| CVE-2010-3149 EXP | Untrusted search path vulnerability in Adobe Device Central CS5 3.0.0(376), 3.0.1.0 (3027), and probably other versions allows local users, and possib… | Patch early | 9.3 high | 13.6% | 2010-08-27 |
| CVE-2010-3153 EXP | Untrusted search path vulnerability in Adobe InDesign CS4 6.0, InDesign CS5 7.0.2 and earlier, Adobe InDesign Server CS5 7.0.2 and earlier, and Adobe… | Patch early | 9.3 high | 13.6% | 2010-08-27 |
| CVE-2008-4310 EXP | httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CP… | Patch early | 7.8 high | 13.6% | 2008-12-09 |
| CVE-2014-5465 EXP | Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress allows remote attackers to re… | Patch early | 5.0 medium | 13.5% | 2014-09-03 |
| CVE-2006-3210 EXP | Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers to conduct PHP remote file inc… | Patch early | 5.1 medium | 13.5% | 2006-06-24 |
| CVE-2004-2425 EXP | Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and poss… | Patch early | 7.5 high | 13.5% | 2004-12-31 |
| CVE-2007-1357 EXP | The atalk_sum_skb function in AppleTalk for Linux kernel 2.6.x before 2.6.21, and possibly 2.4.x, allows remote attackers to cause a denial of service… | Patch early | 7.8 high | 13.5% | 2007-04-11 |
| CVE-2007-1685 EXP | Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a de… | Patch early | 10.0 high | 13.5% | 2007-06-08 |
| CVE-2007-5467 EXP | Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long… | Patch early | 10.0 high | 13.5% | 2007-10-15 |
| CVE-2002-1048 EXP | HP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet services via an SNMP request to the… | Patch early | 7.5 high | 13.5% | 2002-10-04 |
| CVE-2011-0421 EXP | The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argume… | Patch early | 4.3 medium | 13.5% | 2011-03-20 |
| CVE-2019-8565 EXP | A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A malicious application may be able… | Patch early | 7.0 high | 13.5% | 2019-12-18 |
| CVE-2008-0964 EXP | Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote… | Patch early | 9.3 high | 13.5% | 2008-08-08 |
| CVE-2010-0972 EXP | Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrar… | Patch early | 7.5 high | 13.5% | 2010-03-16 |
| CVE-2005-1267 EXP | The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attacker… | Patch early | 5.0 medium | 13.5% | 2005-06-10 |
| CVE-2018-6383 EXP | Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extensio… | Patch early | 8.8 high | 13.5% | 2018-01-29 |
| CVE-2019-6967 EXP | AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF. | Patch early | 8.8 high | 13.5% | 2019-03-21 |
| CVE-2006-1618 EXP | Format string vulnerability in the (1) Con_message and (2) conPrintf functions in con_main.c in Doomsday engine 1.8.6 allows remote attackers to execu… | Patch early | 7.5 high | 13.5% | 2006-04-05 |
| CVE-2019-9581 EXP | phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP… | Patch early | 8.8 high | 13.5% | 2019-03-06 |
| CVE-2017-6444 EXP | The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows r… | Patch early | 7.5 high | 13.5% | 2017-03-12 |
| CVE-2000-0941 EXP | Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter. | Patch early | 10.0 high | 13.5% | 2000-12-19 |
| CVE-2001-0021 EXP | MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter. | Patch early | 10.0 high | 13.5% | 2001-02-16 |
| CVE-2007-1536 EXP | Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file th… | Patch early | 9.3 high | 13.5% | 2007-03-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt