CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,893 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
150,370 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2003-1227 EXP | PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remot… | Patch early | 7.5 high | 6.7% | 2003-12-31 |
| CVE-2013-3613 EXP | Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a repla… | Patch early | 7.8 high | 6.7% | 2013-09-17 |
| CVE-2002-1885 EXP | PHP remote file inclusion vulnerability in showhits.php3 for PowerPhlogger (PPhlogger) 2.0.9 through 2.2.2 allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 6.7% | 2002-12-31 |
| CVE-2008-1886 EXP | The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for a KeyCode that blocks unautho… | Patch early | 7.5 high | 6.7% | 2008-04-18 |
| CVE-2006-6661 EXP | Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execut… | Patch early | 7.5 high | 6.7% | 2006-12-20 |
| CVE-2007-0462 EXP | The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote att… | Patch early | 10.0 high | 6.7% | 2007-01-26 |
| CVE-2014-6607 EXP | M/Monit 3.3.2 and earlier does not verify the original password before changing passwords, which allows remote attackers to change the password of oth… | Patch early | 7.5 high | 6.6% | 2014-10-06 |
| CVE-2006-4869 EXP | PHP remote file inclusion vulnerability in phpunity-postcard.php in phpunity.postcard allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 6.6% | 2006-09-19 |
| CVE-2008-7086 EXP | Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie cookie to a… | Patch early | 7.5 high | 6.6% | 2009-08-26 |
| CVE-2004-2026 EXP | Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format str… | Patch early | 7.5 high | 6.6% | 2004-12-31 |
| CVE-2017-15013 EXP | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticat… | Patch early | 8.8 high | 6.6% | 2017-10-13 |
| CVE-2007-0355 EXP | Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly r… | Patch early | 7.2 high | 6.6% | 2007-01-19 |
| CVE-2015-8358 EXP | Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execute arbitrar… | Patch early | 9.0 high | 6.6% | 2015-12-16 |
| CVE-2010-2102 EXP | Buffer overflow in Webby Webserver 1.01 allows remote attackers to execute arbitrary code via a long HTTP GET request. | Patch early | 10.0 high | 6.6% | 2010-05-27 |
| CVE-2007-0344 EXP | Multiple format string vulnerabilities in (1) _invitedToRoom: and (2) _invitedToDirectChat: in Colloquy 2.1 and earlier allow remote attackers to caus… | Patch early | 7.5 high | 6.6% | 2007-01-18 |
| CVE-2007-1455 EXP | Multiple absolute path traversal vulnerabilities in Fantastico, as used with cPanel 10.x, allow remote authenticated users to include and execute arbi… | Patch early | 9.0 high | 6.6% | 2007-03-14 |
| CVE-2008-3322 EXP | admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrar… | Patch early | 7.5 high | 6.6% | 2008-07-25 |
| CVE-2009-3041 EXP | SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allo… | Patch early | 7.5 high | 6.6% | 2009-09-01 |
| CVE-2005-4316 EXP | HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via a "Rose Attack" that involves sending a subset o… | Patch early | 7.8 high | 6.6% | 2005-12-17 |
| CVE-2002-2251 EXP | Buffer overflow in the changevalue function in libcgi.h for Marcos Luiz Onisto Lib CGI 0.1 allows remote attackers to execute arbitrary code via a lon… | Patch early | 10.0 high | 6.6% | 2002-12-31 |
| CVE-2002-1135 EXP | modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_prefix para… | Patch early | 7.5 high | 6.6% | 2002-10-04 |
| CVE-2005-1222 EXP | cat_for_gen.php in Annuaire Netref 4.2 allows remote attackers to execute arbitrary PHP code by setting the ad_direct parameter to reference cat_for_g… | Patch early | 7.5 high | 6.6% | 2005-05-02 |
| CVE-2007-1446 EXP | Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1beta allow remote attackers to execute arbitrary PHP code via a U… | Patch early | 7.5 high | 6.6% | 2007-03-14 |
| CVE-2013-4978 EXP | Stack-based buffer overflow in AloahaPDFViewer 5.0.0.7 and earlier in Aloaha PDF Suite FREE allows remote attackers to execute arbitrary code via a cr… | Patch early | 9.3 high | 6.6% | 2014-02-05 |
| CVE-2010-0364 EXP | Stack-based buffer overflow in VideoLAN VLC Media Player 0.8.6 allows user-assisted remote attackers to execute arbitrary code via an ogg file with a… | Patch early | 9.3 high | 6.6% | 2010-01-21 |
| CVE-2004-1441 EXP | Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary web script or HTML via the actio… | Patch early | 9.3 high | 6.6% | 2004-12-31 |
| CVE-2003-0833 EXP | Stack-based buffer overflow in webfs before 1.20 allows attackers to execute arbitrary code by creating directories that result in a long pathname. | Patch early | 7.5 high | 6.6% | 2003-11-17 |
| CVE-2000-0038 EXP | glFtpD includes a default glftpd user account with a default password and a UID of 0. | Patch early | 7.5 high | 6.6% | 1999-12-23 |
| CVE-2017-2531 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. Th… | Patch early | 8.8 high | 6.6% | 2017-05-22 |
| CVE-2017-6980 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. Th… | Patch early | 8.8 high | 6.6% | 2017-05-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt