CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,908 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
150,376 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-5292 EXP | PHP remote file inclusion vulnerability in photo_comment.php in Exhibit Engine 1.5 RC 4 and earlier allows remote attackers to execute arbitrary PHP c… | Patch early | 7.5 high | 6.3% | 2006-10-16 |
| CVE-2008-3150 EXP | Directory traversal vulnerability in index.php in Neutrino Atomic Edition 0.8.4 allows remote attackers to read and modify files, as demonstrated by m… | Patch early | 10.0 high | 6.3% | 2008-07-11 |
| CVE-2016-1531 EXP | Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument. | Patch early | 7.0 high | 6.3% | 2016-04-07 |
| CVE-2008-5663 EXP | Multiple unrestricted file upload vulnerabilities in Kusaba 1.0.4 and earlier allow remote authenticated users to execute arbitrary code by uploading… | Patch early | 9.0 high | 6.3% | 2008-12-19 |
| CVE-2007-5620 EXP | Directory traversal vulnerability in admin/inc/help.php in ZZ:FlashChat 3.1 and earlier allows remote attackers to include and execute arbitrary local… | Patch early | 7.5 high | 6.3% | 2007-10-22 |
| CVE-2012-2994 EXP | The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number, which makes it easier for re… | Patch early | 7.5 high | 6.3% | 2012-09-18 |
| CVE-2017-2457 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" compon… | Patch early | 8.8 high | 6.3% | 2017-04-02 |
| CVE-2017-2469 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 6.3% | 2017-04-02 |
| CVE-2017-2470 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 6.3% | 2017-04-02 |
| CVE-2007-6230 EXP | Directory traversal vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote attackers to include and execute arb… | Patch early | 7.5 high | 6.3% | 2007-12-04 |
| CVE-2016-3220 EXP | atmfd.dll in the Adobe Type Manager Font Driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window… | Patch early | 7.8 high | 6.3% | 2016-06-16 |
| CVE-2017-13798 EXP | An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… | Patch early | 8.8 high | 6.3% | 2017-11-13 |
| CVE-2008-3299 EXP | eSyndiCat 1.6 allows remote attackers to bypass authentication and gain administrative access by setting the admin_lng cookie value to 1. NOTE: the pr… | Patch early | 7.5 high | 6.3% | 2008-07-25 |
| CVE-2014-4034 EXP | SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the article_id param… | Patch early | 7.5 high | 6.3% | 2014-06-11 |
| CVE-2015-7986 EXP | The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a denial of service (memory corrupti… | Patch early | 7.5 high | 6.2% | 2015-10-27 |
| CVE-2000-0490 EXP | Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN request. | Patch early | 10.0 high | 6.2% | 2000-06-01 |
| CVE-2008-3166 EXP | PHP remote file inclusion vulnerability in modules/global/inc/content.inc.php in BoonEx Ray 3.5, when register_globals is enabled, allows remote attac… | Patch early | 9.3 high | 6.2% | 2008-07-14 |
| CVE-2012-4250 EXP | Stack-based buffer overflow in the RequestScreenOptimization function in the XProcessControl.ocx ActiveX control in msls31.dll in Samsung NET-i viewer… | Patch early | 9.3 high | 6.2% | 2012-08-13 |
| CVE-2003-1140 EXP | Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the configuration file. | Patch early | 10.0 high | 6.2% | 2003-10-27 |
| CVE-2023-4278 EXP | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to regist… | Patch early | 7.5 high | 6.2% | 2023-09-11 |
| CVE-2014-4968 EXP | The WebView class and use of the WebView.addJavascriptInterface method in the Boat Browser application 8.0 and 8.0.1 for Android allow remote attacker… | Patch early | 8.8 high | 6.2% | 2020-02-12 |
| CVE-2023-28288 EXP | Microsoft SharePoint Server Spoofing Vulnerability | Patch early | 8.1 high | 6.2% | 2023-04-11 |
| CVE-2018-0952 EXP | An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hu… | Patch early | 7.8 high | 6.2% | 2018-08-15 |
| CVE-2009-3969 EXP | Stack-based buffer overflow in Faslo Player 7.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… | Patch early | 9.3 high | 6.2% | 2009-11-18 |
| CVE-2003-1313 EXP | Multiple PHP remote file inclusion vulnerabilities in EternalMart Mailing List Manager (EMLM) 1.32 allow remote attackers to execute arbitrary PHP cod… | Patch early | 7.5 high | 6.2% | 2003-12-31 |
| CVE-1999-0997 EXP | wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program… | Patch early | 7.5 high | 6.2% | 1999-12-20 |
| CVE-2007-0504 EXP | Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to execute arbitrary code via the… | Patch early | 10.0 high | 6.2% | 2007-01-26 |
| CVE-1999-0210 EXP | Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters. | Patch early | 10.0 high | 6.2% | 1997-11-26 |
| CVE-2007-2568 EXP | Multiple stack-based buffer overflows in VCDGear 3.55 allow user-assisted remote attackers to execute arbitrary code via a long (1) tag or (2) track t… | Patch early | 9.3 high | 6.2% | 2007-05-16 |
| CVE-2017-7049 EXP | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… | Patch early | 8.8 high | 6.2% | 2017-07-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt