CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,573 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
149,897 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-0222 EXP | Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and exe… | Patch early | 7.5 high | 7.7% | 2008-01-10 |
| CVE-2010-0387 EXP | Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to cau… | Patch early | 7.5 high | 7.7% | 2010-01-25 |
| CVE-2007-2988 EXP | A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administrative credentials are missing,… | Patch early | 7.5 high | 7.7% | 2007-06-01 |
| CVE-2020-12351 EXP | Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. | Patch early | 8.8 high | 7.7% | 2020-11-23 |
| CVE-2023-25289 EXP | Directory Traversal vulnerability in virtualreception Digital Receptie version win7sp1_rtm.101119-1850 6.1.7601.1.0.65792 in embedded web server, allo… | Patch early | 7.5 high | 7.7% | 2023-05-04 |
| CVE-2017-0569 EXP | An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the c… | Patch early | 7.0 high | 7.7% | 2017-04-07 |
| CVE-2014-1202 EXP | The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a… | Patch early | 9.3 high | 7.7% | 2014-01-25 |
| CVE-2017-7115 EXP | An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It… | Patch early | 8.1 high | 7.7% | 2017-10-23 |
| CVE-2005-0735 EXP | newsscript.pl for NewsScript allows remote attackers to gain privileges by setting the mode parameter to admin. | Patch early | 10.0 high | 7.7% | 2005-05-02 |
| CVE-2018-6126 EXP | A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML… | Patch early | 8.8 high | 7.7% | 2019-01-09 |
| CVE-2015-6750 EXP | Buffer overflow in Ricoh DL FTP Server 1.1.0.6 and earlier allows remote attackers to execute arbitrary code via a long USER command. | Patch early | 7.5 high | 7.7% | 2015-08-31 |
| CVE-2003-1341 EXP | The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.e… | Patch early | 7.5 high | 7.7% | 2003-12-31 |
| CVE-2015-3693 EXP | Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates for DDR3 RAM, which might make i… | Patch early | 9.3 high | 7.7% | 2015-07-03 |
| CVE-2008-4134 EXP | PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other versions before 0.05, allows remo… | Patch early | 7.5 high | 7.7% | 2008-09-19 |
| CVE-2008-4509 EXP | Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows remote attackers to execute a… | Patch early | 10.0 high | 7.7% | 2008-10-09 |
| CVE-2017-6984 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. iTunes before 12.6.1 on Windows is… | Patch early | 8.8 high | 7.7% | 2017-05-22 |
| CVE-2013-3615 EXP | Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent attackers to discover clearte… | Patch early | 7.8 high | 7.7% | 2013-09-17 |
| CVE-2000-0207 EXP | SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters. | Patch early | 7.5 high | 7.7% | 2000-03-01 |
| CVE-2000-0424 EXP | The CGI counter 4.0.7 by George Burgyan allows remote attackers to execute arbitrary commands via shell metacharacters. | Patch early | 7.5 high | 7.7% | 2000-05-15 |
| CVE-2000-0432 EXP | The calender.pl and the calendar_admin.pl calendar scripts by Matt Kruse allow remote attackers to execute arbitrary commands via shell metacharacters… | Patch early | 7.5 high | 7.7% | 2000-05-16 |
| CVE-2012-1830 EXP | Stack-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 555. | Patch early | 10.0 high | 7.7% | 2012-07-05 |
| CVE-2002-2145 EXP | Savant Web Server 3.1 and earlier allows remote attackers to bypass authentication for password protected user folders via a URL with a hex encoded sp… | Patch early | 7.5 high | 7.7% | 2002-12-31 |
| CVE-2014-7910 EXP | Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service or possibly have other impact v… | Patch early | 7.5 high | 7.7% | 2014-11-19 |
| CVE-2006-0881 EXP | Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attac… | Patch early | 7.5 high | 7.7% | 2006-02-24 |
| CVE-2002-2400 EXP | Buffer overflow in the httpdProcessRequest function in LibHTTPD 1.2 allows remote attackers to cause a denial of service (crash) and possibly execute… | Patch early | 10.0 high | 7.7% | 2002-12-31 |
| CVE-2014-3085 EXP | systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute arb… | Patch early | 7.1 high | 7.6% | 2014-08-17 |
| CVE-2011-4162 EXP | The (1) AddUser, (2) AddUserEx, (3) RemoveUser, (4) RemoveUserByGuide, (5) RemoveUserEx, and (6) RemoveUserRegardless methods in HP Protect Tools Devi… | Patch early | 7.5 high | 7.6% | 2011-12-05 |
| CVE-2007-3606 EXP | Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCII versions, allows remote atta… | Patch early | 7.6 high | 7.6% | 2007-07-06 |
| CVE-2002-0948 EXP | Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute server-side includes (SSI) as t… | Patch early | 7.5 high | 7.6% | 2002-10-04 |
| CVE-2015-6401 EXP | Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication requirement and execute unspecif… | Patch early | 7.5 high | 7.6% | 2015-12-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt