CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,957 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
150,003 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-2257 EXP | The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to… | Patch early | 7.8 high | 7.2% | 2009-06-30 |
| CVE-2002-0451 EXP | filemanager_forms.php in PHProjekt 3.1 and 3.1a allows remote attackers to execute arbitrary PHP code by specifying the URL to the code in the lib_pat… | Patch early | 7.5 high | 7.2% | 2002-08-12 |
| CVE-2002-0959 EXP | Cross-site scripting vulnerability in Splatt Forum 3.0 allows remote attackers to execute arbitrary script as other users via an [img] tag with a clos… | Patch early | 7.5 high | 7.2% | 2002-10-04 |
| CVE-2002-1036 EXP | Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to execute web scrip… | Patch early | 7.5 high | 7.2% | 2002-10-04 |
| CVE-2000-0696 EXP | The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts,… | Patch early | 7.5 high | 7.2% | 2000-10-20 |
| CVE-2001-0987 EXP | Cross-site scripting vulnerability in CGIWrap before 3.7 allows remote attackers to execute arbitrary Javascript on other web clients by causing the J… | Patch early | 7.5 high | 7.2% | 2001-07-22 |
| CVE-2012-0242 EXP | Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers… | Patch early | 10.0 high | 7.2% | 2012-02-21 |
| CVE-2007-2856 EXP | Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used, allows u… | Patch early | 9.3 high | 7.2% | 2007-05-24 |
| CVE-2014-3418 EXP | config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the skipj… | Patch early | 10.0 high | 7.2% | 2014-07-15 |
| CVE-2005-3893 EXP | Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attac… | Patch early | 7.5 high | 7.2% | 2005-11-29 |
| CVE-2015-5533 EXP | SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators t… | Patch early | 7.2 high | 7.2% | 2017-10-23 |
| CVE-2002-1436 EXP | The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary Perl code via an HTTP POST request. | Patch early | 7.5 high | 7.2% | 2003-04-11 |
| CVE-2022-24707 EXP | Anuko Time Tracker is an open source, web-based time tracking application written in PHP. UNION SQL injection and time-based blind injection vulnerabi… | Patch early | 7.4 high | 7.2% | 2022-02-24 |
| CVE-2002-0902 EXP | Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including a http:// a… | Patch early | 7.5 high | 7.2% | 2002-10-04 |
| CVE-2025-29471 EXP | Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email f… | Patch early | 8.3 high | 7.2% | 2025-04-15 |
| CVE-2011-4835 EXP | Directory traversal vulnerability in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to access arbitrary files via unspecified vect… | Patch early | 7.5 high | 7.2% | 2011-12-15 |
| CVE-2008-4923 EXP | Multiple insecure method vulnerabilities in MW6 Technologies Aztec ActiveX control (AZTECLib.MW6Aztec, Aztec.dll) 3.0.0.1 allow remote attackers to ov… | Patch early | 9.0 high | 7.1% | 2008-11-04 |
| CVE-2008-4924 EXP | Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.dll) 3.0.0.1 allow remote atta… | Patch early | 9.0 high | 7.1% | 2008-11-04 |
| CVE-2008-4925 EXP | Multiple insecure method vulnerabilities in MW6 Technologies DataMatrix ActiveX control (DATAMATRIXLib.MW6DataMatrix, DataMatrix.dll) 3.0.0.1 allow re… | Patch early | 9.0 high | 7.1% | 2008-11-04 |
| CVE-2006-2233 EXP | Buffer overflow in BankTown Client Control (aka BtCxCtl20Com) 1.4.2.51817, and possibly 1.5.2.50209, allows remote attackers to execute arbitrary code… | Patch early | 7.5 high | 7.1% | 2006-05-05 |
| CVE-2017-13261 EXP | In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote infor… | Patch early | 7.5 high | 7.1% | 2018-04-04 |
| CVE-2007-0639 EXP | Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject arbitrary PHP code into a .in… | Patch early | 7.5 high | 7.1% | 2007-01-31 |
| CVE-2015-5353 EXP | Directory traversal vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to include and execute arbitrary local files via a .. (dot dot) i… | Patch early | 7.5 high | 7.1% | 2015-07-01 |
| CVE-2008-4771 EXP | Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-Link MPEG4… | Patch early | 9.3 high | 7.1% | 2008-10-28 |
| CVE-2003-0203 EXP | Buffer overflow in moxftp 2.2 and earlier allows remote malicious FTP servers to execute arbitrary code via a long FTP banner. | Patch early | 7.5 high | 7.1% | 2003-04-11 |
| CVE-2008-7078 EXP | Multiple buffer overflows in Rumpus before 6.0.1 allow remote attackers to (1) cause a denial of service (segmentation fault) via a long HTTP verb in… | Patch early | 9.0 high | 7.1% | 2009-08-25 |
| CVE-2001-0028 EXP | Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute arbitrary commands via a large… | Patch early | 10.0 high | 7.1% | 2001-02-12 |
| CVE-2005-4456 EXP | Multiple buffer overflows in MailEnable Professional 1.71 and Enterprise 1.1 before patch ME-10009 allow remote attackers to cause a denial of service… | Patch early | 7.8 high | 7.1% | 2005-12-21 |
| CVE-2009-1325 EXP | Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file. | Patch early | 9.3 high | 7.1% | 2009-04-17 |
| CVE-2009-1326 EXP | Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u)… | Patch early | 9.3 high | 7.1% | 2009-04-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt