CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,941 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
150,376 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-1610 EXP | admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator password and gain administrator priv… | Patch early | 7.5 high | 6.1% | 2009-05-11 |
| CVE-2009-0457 EXP | Multiple directory traversal vulnerabilities in AJA Portal 1.2 allow remote attackers to include and execute arbitrary local files via directory trave… | Patch early | 7.5 high | 6.1% | 2009-02-10 |
| CVE-2002-0855 EXP | Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscript… | Patch early | 7.5 high | 6.1% | 2002-09-05 |
| CVE-2000-1046 EXP | Multiple buffer overflows in the ESMTP service of Lotus Domino 5.0.2c and earlier allow remote attackers to cause a denial of service and possibly exe… | Patch early | 10.0 high | 6.1% | 2000-12-11 |
| CVE-2009-2363 EXP | Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls playlist file with a playlist… | Patch early | 9.3 high | 6.1% | 2009-07-08 |
| CVE-2009-1652 EXP | admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and add… | Patch early | 7.5 high | 6.1% | 2009-05-16 |
| CVE-2006-7068 EXP | PHP remote file inclusion vulnerability in CliServ Web Community 0.65 and earlier allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 7.5 high | 6.1% | 2007-03-02 |
| CVE-2001-0029 EXP | Buffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrary commands via a long host or… | Patch early | 10.0 high | 6.1% | 2001-02-12 |
| CVE-2018-6221 EXP | An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle attacker to tamper with an up… | Patch early | 8.1 high | 6.1% | 2018-03-15 |
| CVE-2002-2420 EXP | site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter. | Patch early | 7.5 high | 6.1% | 2002-12-31 |
| CVE-2007-4838 EXP | Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via a long string in a (1) 0x21,… | Patch early | 7.5 high | 6.1% | 2007-09-12 |
| CVE-2012-2998 EXP | SQL injection vulnerability in the ad hoc query module in Trend Micro Control Manager (TMCM) before 5.5.0.1823 and 6.0 before 6.0.0.1449 allows remote… | Patch early | 7.5 high | 6.1% | 2012-09-28 |
| CVE-2007-1992 EXP | Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote attackers to execute arbitrary… | Patch early | 7.5 high | 6.1% | 2007-04-12 |
| CVE-2007-2301 EXP | Multiple PHP remote file inclusion vulnerabilities in audioCMS arash 0.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the arash… | Patch early | 7.5 high | 6.1% | 2007-04-26 |
| CVE-2007-2313 EXP | PHP remote file inclusion vulnerability in getinfo1.php in the Shotcast 1.0 RC2 module for mxBB allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 6.1% | 2007-04-26 |
| CVE-2007-2345 EXP | PHP remote file inclusion vulnerability in include/include_stream.inc.php in CodeWand phpBrowse allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 6.1% | 2007-04-27 |
| CVE-2007-5771 EXP | Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie. | Patch early | 7.5 high | 6.1% | 2007-11-01 |
| CVE-2009-3428 EXP | Stack-based buffer overflow in Easy Music Player 1.0.0.2 allows remote attackers to execute arbitrary code via a crafted .wav file. | Patch early | 9.3 high | 6.1% | 2009-09-25 |
| CVE-2017-2369 EXP | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. Th… | Patch early | 8.8 high | 6.1% | 2017-02-20 |
| CVE-2017-2373 EXP | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. Th… | Patch early | 8.8 high | 6.1% | 2017-02-20 |
| CVE-2013-0526 EXP | ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remo… | Patch early | 8.5 high | 6.1% | 2013-08-21 |
| CVE-2007-2865 EXP | Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the ser… | Patch early | 9.3 high | 6.1% | 2007-05-25 |
| CVE-2014-100014 EXP | Multiple stack-based buffer overflows in pdmwService.exe in SolidWorks Workgroup PDM 2014 SP2 allow remote attackers to execute arbitrary code via a l… | Patch early | 7.5 high | 6.1% | 2015-01-13 |
| CVE-2009-0423 EXP | Directory traversal vulnerability in index.php in Php Photo Album (PHPPA) 0.8 BETA allows remote attackers to include and execute arbitrary local file… | Patch early | 7.5 high | 6.1% | 2009-02-05 |
| CVE-2009-1445 EXP | Multiple directory traversal vulnerabilities in WebPortal CMS 0.8-beta allow remote attackers to (1) read arbitrary files via directory traversal sequ… | Patch early | 7.5 high | 6.1% | 2009-04-27 |
| CVE-2005-0636 EXP | Format string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via… | Patch early | 10.0 high | 6.1% | 2005-03-02 |
| CVE-2017-17593 EXP | Simple Chatting System 1.0 allows Arbitrary File Upload via view/my_profile.php, which places files under uploads/. | Patch early | 7.5 high | 6.1% | 2017-12-13 |
| CVE-2009-3188 EXP | PHP remote file inclusion vulnerability in save.php in phpSANE 0.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the file_save… | Patch early | 7.5 high | 6.1% | 2009-09-15 |
| CVE-2010-4613 EXP | Multiple directory traversal vulnerabilities in Hycus CMS 1.0.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot)… | Patch early | 7.5 high | 6.1% | 2010-12-29 |
| CVE-2014-2579 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers to hijack the authentication o… | Patch early | 7.6 high | 6% | 2014-04-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt