CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,620 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
320,102 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-2227 EXP | GLPI 0.83.7 has Local File Inclusion in common.tabs.php. | Patch early | 7.5 high | 13% | 2019-11-01 |
| CVE-2013-4117 EXP | Cross-site scripting (XSS) vulnerability in includes/CatGridPost.php in the Category Grid View Gallery plugin 2.3.1 for WordPress allows remote attack… | Patch early | 4.3 medium | 13% | 2013-07-16 |
| CVE-2010-0157 EXP | Directory traversal vulnerability in the Bible Study (com_biblestudy) component 6.1 for Joomla! allows remote attackers to include and execute arbitra… | Patch early | 7.5 high | 13% | 2010-01-06 |
| CVE-2000-1035 EXP | Buffer overflows in TYPSoft FTP Server 0.78 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands v… | Patch early | 10.0 high | 13% | 2000-12-11 |
| CVE-2001-0280 EXP | Buffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command. | Patch early | 10.0 high | 13% | 2001-05-03 |
| CVE-2007-4034 EXP | Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPC… | Patch early | 9.3 high | 13% | 2007-07-27 |
| CVE-2009-2511 EXP | Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, a… | Patch early | 7.5 high | 13% | 2009-10-14 |
| CVE-2010-2626 EXP | index.pl in Miyabi CGI Tools SEO Links 1.02 allows remote attackers to execute arbitrary commands via shell metacharacters in the fn command. NOTE: so… | Patch early | 7.5 high | 12.9% | 2010-07-02 |
| CVE-2002-1209 EXP | Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (d… | Patch early | 5.0 medium | 12.9% | 2002-11-04 |
| CVE-2005-4466 EXP | Heap-based buffer overflow in the SIPParser function in i3sipmsg.dll in Interaction SIP Proxy before 3.0.011 allows remote attackers to cause a denial… | Patch early | 7.5 high | 12.9% | 2005-12-22 |
| CVE-2019-9491 EXP | Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the… | Patch early | 7.8 high | 12.9% | 2019-10-21 |
| CVE-2005-2277 EXP | Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file… | Patch early | 10.0 high | 12.9% | 2005-07-15 |
| CVE-2021-43062 EXP | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 an… | Patch early | 6.1 medium | 12.9% | 2022-02-02 |
| CVE-2007-6244 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote attackers to inject a… | Patch early | 4.3 medium | 12.9% | 2007-12-20 |
| CVE-2003-1177 EXP | Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute a… | Patch early | 7.5 high | 12.9% | 2003-12-31 |
| CVE-2009-4653 EXP | Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to cause a denial of servic… | Patch early | 9.0 high | 12.9% | 2010-02-26 |
| CVE-2015-7258 EXP | ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by displaying u… | Patch early | 8.8 high | 12.9% | 2017-08-24 |
| CVE-2017-16929 EXP | The remote management interface on the Claymore Dual GPU miner 10.1 is vulnerable to an authenticated directory traversal vulnerability exploited by i… | Patch early | 8.1 high | 12.9% | 2017-12-05 |
| CVE-2021-46354 EXP | Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Ad… | Patch early | 7.5 high | 12.9% | 2022-02-09 |
| CVE-2003-0720 EXP | Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type. | Patch early | 7.5 high | 12.9% | 2003-09-17 |
| CVE-1999-1576 EXP | Buffer overflow in Adobe Acrobat ActiveX control (pdf.ocx, PDF.PdfCtrl.1) 1.3.188 for Acrobat Reader 4.0 allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 12.9% | 1999-09-27 |
| CVE-2019-1245 EXP | An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosu… | Patch early | 6.5 medium | 12.9% | 2019-09-11 |
| CVE-2020-29395 EXP | The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field. | Patch early | 6.1 medium | 12.9% | 2020-11-30 |
| CVE-2011-2505 EXP | libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns valu… | Patch early | 6.4 medium | 12.9% | 2011-07-14 |
| CVE-2000-0065 EXP | Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request. | Patch early | 10.0 high | 12.9% | 2000-01-17 |
| CVE-2000-0091 EXP | Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password. | Patch early | 10.0 high | 12.9% | 2000-01-21 |
| CVE-2003-1505 EXP | Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a textarea in… | Patch early | 4.3 medium | 12.9% | 2003-12-31 |
| CVE-2008-5587 EXP | Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers… | Patch early | 4.3 medium | 12.9% | 2008-12-16 |
| CVE-2002-2073 EXP | Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arb… | Patch early | 4.3 medium | 12.9% | 2002-12-31 |
| CVE-2012-2619 EXP | The Broadcom BCM4325 and BCM4329 Wi-Fi chips, as used in certain Acer, Apple, Asus, Ford, HTC, Kyocera, LG, Malata, Motorola, Nokia, Pantech, Samsung,… | Patch early | 7.8 high | 12.9% | 2012-11-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt