CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,660 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
320,712 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-23839 EXP | A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote attackers to… | Patch early | 6.1 medium | 10.5% | 2020-09-01 |
| CVE-2007-2200 EXP | Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and possibly delete arbitrary files vi… | Patch early | 10.0 high | 10.5% | 2007-04-24 |
| CVE-2020-35754 EXP | OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via t… | Patch early | 7.2 high | 10.5% | 2021-01-28 |
| CVE-2000-1061 EXP | Microsoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to create and use ActiveX controls, which allows a remote at… | Patch early | 5.1 medium | 10.5% | 2000-12-11 |
| CVE-2012-4768 EXP | Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web s… | Patch early | 4.3 medium | 10.5% | 2014-09-04 |
| CVE-2009-4663 EXP | Heap-based buffer overflow in the Quiksoft EasyMail Objects 6 ActiveX control allows remote attackers to execute arbitrary code via a long argument to… | Patch early | 9.3 high | 10.5% | 2010-03-03 |
| CVE-2008-0352 EXP | The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6 packet, possibly involving th… | Patch early | 7.8 high | 10.4% | 2008-01-18 |
| CVE-2005-3591 EXP | Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause… | Patch early | 7.5 high | 10.4% | 2005-11-16 |
| CVE-2010-1152 EXP | memcached.c in memcached before 1.4.3 allows remote attackers to cause a denial of service (daemon hang or crash) via a long line that triggers excess… | Patch early | 5.0 medium | 10.4% | 2010-04-12 |
| CVE-2013-1596 EXP | An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP packets to TCP port 554. | Patch early | 5.3 medium | 10.4% | 2020-01-24 |
| CVE-2004-1256 EXP | Multiple buffer overflows in the (1) event_text and (2) event_specific functions in abc2midi 2004.12.04 allow remote attackers to execute arbitrary co… | Patch early | 10.0 high | 10.4% | 2005-01-10 |
| CVE-2004-1288 EXP | Buffer overflow in the parse_html function in o3read.c for o3read 0.0.3 allows remote attackers to execute arbitrary code via a crafted SXW file. | Patch early | 10.0 high | 10.4% | 2005-01-10 |
| CVE-2020-35737 EXP | In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidat… | Patch early | 7.5 high | 10.4% | 2020-12-30 |
| CVE-2015-5149 EXP | Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to write to arbitrary files via a ..… | Patch early | 5.5 medium | 10.4% | 2015-06-30 |
| CVE-2015-6830 EXP | libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass… | Patch early | 5.0 medium | 10.4% | 2015-09-14 |
| CVE-2007-0887 EXP | axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial of service (NULL dereference a… | Patch early | 7.8 high | 10.4% | 2007-02-12 |
| CVE-2011-5181 EXP | Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to in… | Patch early | 4.3 medium | 10.4% | 2012-09-20 |
| CVE-2018-15685 EXP | GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true"… | Patch early | 8.1 high | 10.4% | 2018-08-23 |
| CVE-2008-1770 EXP | CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of… | Patch early | 9.3 high | 10.4% | 2008-06-04 |
| CVE-2000-0833 EXP | Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2) HELO command. | Patch early | 10.0 high | 10.4% | 2000-11-14 |
| CVE-2009-1944 EXP | Stack-based buffer overflow in AIMP 2.51 build 330 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag. | Patch early | 9.3 high | 10.4% | 2009-06-05 |
| CVE-2007-4982 EXP | Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Technologies QRCode ActiveX 3.0.0.1… | Patch early | 10.0 high | 10.4% | 2007-09-19 |
| CVE-2006-4844 EXP | PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products,… | Patch early | 5.1 medium | 10.4% | 2006-09-19 |
| CVE-2008-5748 EXP | Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1)… | Patch early | 8.1 high | 10.4% | 2008-12-29 |
| CVE-2007-1376 EXP | The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which… | Patch early | 7.5 high | 10.4% | 2007-03-10 |
| CVE-2004-0270 EXP | libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail message with an invalid line leng… | Patch early | 5.0 medium | 10.4% | 2004-11-23 |
| CVE-2009-0751 EXP | Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers. | Patch early | 5.0 medium | 10.4% | 2009-03-02 |
| CVE-2011-5009 EXP | The CmpWebServer.dll module in the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to cause a denial of service (NULL pointer de… | Patch early | 5.0 medium | 10.4% | 2011-12-25 |
| CVE-2018-12293 EXP | The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior… | Patch early | 8.8 high | 10.4% | 2018-06-19 |
| CVE-2007-2715 EXP | Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password… | Patch early | 10.0 high | 10.4% | 2007-05-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt