CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,769 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
320,864 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-0599 EXP | Blahz-DNS 0.2 and earlier allows remote attackers to bypass authentication and modify configuration by directly requesting CGI programs such as dostuf… | Patch early | 10.0 high | 11.5% | 2002-06-18 |
| CVE-2000-1014 EXP | Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute arbitrary command… | Patch early | 7.5 high | 11.5% | 2000-12-11 |
| CVE-2004-0816 EXP | Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service (application c… | Patch early | 7.5 high | 11.5% | 2004-12-23 |
| CVE-2000-0909 EXP | Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long Fro… | Patch early | 7.5 high | 11.5% | 2000-12-19 |
| CVE-2011-2543 EXP | Buffer overflow in the cuil component in Cisco Telepresence System Integrator C Series 4.x before TC4.2.0 allows remote authenticated users to cause a… | Patch early | 9.0 high | 11.5% | 2011-09-23 |
| CVE-2016-1610 EXP | Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows re… | Patch early | 7.5 high | 11.5% | 2016-08-01 |
| CVE-2018-15120 EXP | libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application cras… | Patch early | 6.5 medium | 11.5% | 2018-08-24 |
| CVE-2008-6222 EXP | Directory traversal vulnerability in the Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 for Joomla! allows remote attackers to read arbi… | Patch early | 5.0 medium | 11.5% | 2009-02-20 |
| CVE-2016-0070 EXP | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT… | Patch early | 5.5 medium | 11.5% | 2016-10-14 |
| CVE-2006-2849 EXP | PHP remote file inclusion vulnerability in includes/webdav/server.php in Bytehoard 2.1 Epsilon/Delta allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 11.5% | 2006-06-06 |
| CVE-2003-1425 EXP | guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter. | Patch early | 10.0 high | 11.5% | 2003-12-31 |
| CVE-2005-3486 EXP | Multiple format string vulnerabilities in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole… | Patch early | 7.5 high | 11.5% | 2005-11-03 |
| CVE-2009-4112 EXP | Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memor… | Patch early | 9.0 high | 11.5% | 2009-11-30 |
| CVE-2018-18428 EXP | TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg URI. | Patch early | 7.5 high | 11.5% | 2018-10-19 |
| CVE-2021-3337 EXP | The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on repl… | Patch early | 7.5 high | 11.5% | 2021-01-28 |
| CVE-2019-2697 EXP | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Diffic… | Patch early | 8.1 high | 11.5% | 2019-04-23 |
| CVE-2000-0165 EXP | The Delegate application proxy has several buffer overflows which allow a remote attacker to execute commands. | Patch early | 7.5 high | 11.5% | 1999-11-13 |
| CVE-2007-1912 EXP | Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file. | Patch early | 6.8 medium | 11.5% | 2007-04-10 |
| CVE-2005-2616 EXP | Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.ph… | Patch early | 7.5 high | 11.5% | 2005-08-17 |
| CVE-2010-3682 EXP | Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXP… | Patch early | 4.0 medium | 11.4% | 2011-01-11 |
| CVE-2006-4832 EXP | Buffer overflow in the telnet service in Verso NetPerformer FRAD ACT SDM-95xx 7.xx (R1) and earlier, SDM-93xx 10.x.x (R2) and earlier, and SDM-92xx 9.… | Patch early | 7.5 high | 11.4% | 2006-09-15 |
| CVE-2012-3574 EXP | Unrestricted file upload vulnerability in includes/doajaxfileupload.php in the MM Forms Community plugin 2.2.5 and 2.2.6 for WordPress allows remote a… | Patch early | 7.5 high | 11.4% | 2012-06-16 |
| CVE-2001-1022 EXP | Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option… | Patch early | 7.5 high | 11.4% | 2001-07-26 |
| CVE-2015-3221 EXP | OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated use… | Patch early | 4.0 medium | 11.4% | 2015-08-26 |
| CVE-2014-9147 EXP | Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/. | Patch early | 7.5 high | 11.4% | 2017-10-16 |
| CVE-2010-1878 EXP | Directory traversal vulnerability in the OrgChart (com_orgchart) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a ..… | Patch early | 7.5 high | 11.4% | 2010-05-12 |
| CVE-2013-4788 EXP | The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the ra… | Patch early | 5.1 medium | 11.4% | 2013-10-04 |
| CVE-2019-9189 EXP | Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central c… | Patch early | 8.8 high | 11.4% | 2019-06-05 |
| CVE-2007-0107 EXP | WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers… | Patch early | 6.8 medium | 11.4% | 2007-01-09 |
| CVE-2002-0644 EXP | Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members… | Patch early | 7.5 high | 11.4% | 2002-08-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt