CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,620 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
320,102 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-24926 EXP | The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a… | Patch early | 6.1 medium | 12.9% | 2022-02-01 |
| CVE-1999-0208 EXP | rpc.ypupdated (NIS) allows remote users to execute arbitrary commands. | Patch early | 10.0 high | 12.9% | 1995-12-12 |
| CVE-2019-8689 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watc… | Patch early | 8.8 high | 12.9% | 2019-12-18 |
| CVE-2012-2371 EXP | Cross-site scripting (XSS) vulnerability in index.php in the WP-FaceThumb plugin 0.1 for WordPress allows remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 12.8% | 2012-08-13 |
| CVE-2013-1916 EXP | In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server h… | Patch early | 8.8 high | 12.8% | 2022-06-24 |
| CVE-2005-0710 EXP | MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restricti… | Patch early | 4.6 medium | 12.8% | 2005-05-02 |
| CVE-2005-1349 EXP | Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter to a read o… | Patch early | 7.5 high | 12.8% | 2005-05-02 |
| CVE-2000-0156 EXP | Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source R… | Patch early | 5.1 medium | 12.8% | 2000-02-16 |
| CVE-1999-0281 EXP | Denial of service in IIS using long URLs. | Patch early | 5.0 medium | 12.8% | 1997-06-01 |
| CVE-2024-25832 EXP | F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous typ… | Patch early | 8.8 high | 12.8% | 2024-02-29 |
| CVE-2005-2629 EXP | Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitr… | Patch early | 5.1 medium | 12.8% | 2005-11-18 |
| CVE-2016-3376 EXP | The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R… | Patch early | 7.8 high | 12.8% | 2016-10-14 |
| CVE-2007-5607 EXP | Buffer overflow in the RegistryString function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1… | Patch early | 7.5 high | 12.8% | 2008-06-04 |
| CVE-2007-3697 EXP | PHP remote file inclusion vulnerability in phpbb/sendmsg.php in FlashBB 1.1.8 and earlier allows remote attackers to execute arbitrary code via a URL… | Patch early | 7.5 high | 12.8% | 2007-07-11 |
| CVE-1999-0896 EXP | Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and passwo… | Patch early | 10.0 high | 12.8% | 1999-11-04 |
| CVE-2004-2275 EXP | i-mall.cgi in I-Mall Commerce allows remote attackers to execute arbitrary commands via shell metacharacters via the p parameter. | Patch early | 10.0 high | 12.8% | 2004-12-31 |
| CVE-2008-0443 EXP | Heap-based buffer overflow in the FileUploader.FUploadCtl.1 ActiveX control in FileUploader.dll 2.0.0.2 in Lycos FileUploader Module allows remote att… | Patch early | 10.0 high | 12.8% | 2008-01-25 |
| CVE-2014-6043 EXP | ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote a… | Patch early | 6.5 medium | 12.8% | 2014-09-11 |
| CVE-2008-1767 EXP | Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arb… | Patch early | 7.5 high | 12.8% | 2008-05-23 |
| CVE-2008-2935 EXP | Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFuncti… | Patch early | 7.5 high | 12.8% | 2008-08-01 |
| CVE-2010-4156 EXP | The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive inform… | Patch early | 5.0 medium | 12.8% | 2010-11-10 |
| CVE-2017-12718 EXP | A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. A third-par… | Patch early | 8.1 high | 12.8% | 2018-02-15 |
| CVE-2015-2826 EXP | WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information. | Patch early | 5.3 medium | 12.8% | 2017-09-20 |
| CVE-2021-44664 EXP | An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a malicio… | Patch early | 8.8 high | 12.8% | 2022-02-24 |
| CVE-2009-0650 EXP | Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remote attackers to cause a denial… | Patch early | 10.0 high | 12.8% | 2009-02-20 |
| CVE-2009-0693 EXP | Multiple buffer overflows in Wyse Device Manager (WDM) 4.7.x allow remote attackers to execute arbitrary code via (1) the User-Agent HTTP header to hs… | Patch early | 7.5 high | 12.8% | 2012-06-19 |
| CVE-2018-7448 EXP | Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary… | Patch early | 7.5 high | 12.8% | 2018-02-26 |
| CVE-2015-0057 EXP | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wind… | Patch early | 7.2 high | 12.8% | 2015-02-11 |
| CVE-2014-8498 EXP | SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (… | Patch early | 6.5 medium | 12.7% | 2014-11-17 |
| CVE-2005-1163 EXP | Multiple buffer overflows in Yager 5.24 and earlier allow remote attackers to execute arbitrary code via (1) a crafted nickname or (2) a packet with a… | Patch early | 6.4 medium | 12.7% | 2005-05-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt