CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,769 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
320,864 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-20523 EXP | Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a t… | Patch early | 5.3 medium | 10% | 2019-06-07 |
| CVE-2013-2474 EXP | Directory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' parameter. | Patch early | 7.5 high | 10% | 2020-01-27 |
| CVE-2008-2511 EXP | Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEventCli.dll in CA Internet Secu… | Patch early | 9.3 high | 10% | 2008-06-02 |
| CVE-2006-2460 EXP | Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESS… | Patch early | 6.4 medium | 10% | 2006-05-19 |
| CVE-2018-19042 EXP | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters o… | Patch early | 5.3 medium | 10% | 2019-01-31 |
| CVE-2018-19043 EXP | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename) via a ../ directory traversal… | Patch early | 5.3 medium | 10% | 2019-01-31 |
| CVE-2000-0213 EXP | The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacha… | Patch early | 5.0 medium | 10% | 2000-02-23 |
| CVE-2009-4427 EXP | Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbitrary local files via a .. (do… | Patch early | 7.5 high | 10% | 2009-12-28 |
| CVE-2021-34370 EXP | Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags an… | Patch early | 6.1 medium | 10% | 2021-06-09 |
| CVE-2006-1777 EXP | Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execute arbitra… | Patch early | 7.5 high | 10% | 2006-04-13 |
| CVE-1999-0951 EXP | Buffer overflow in OmniHTTPd CGI program imagemap.exe allows remote attackers to execute commands. | Patch early | 10.0 high | 10% | 1999-10-22 |
| CVE-2006-1149 EXP | PHP remote file inclusion vulnerability in lib/OWL_API.php in OWL Intranet Engine 0.82, when register_globals is enabled, allows remote attackers to i… | Patch early | 7.5 high | 10% | 2006-03-10 |
| CVE-2008-1322 EXP | The File Check Utility (fcheck.exe) in ASG-Sentry Network Manager 7.0.0 and earlier allows remote attackers to cause a denial of service (CPU consumpt… | Patch early | 7.8 high | 10% | 2008-03-13 |
| CVE-2006-0899 EXP | Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot… | Patch early | 7.5 high | 10% | 2006-02-27 |
| CVE-2016-1464 EXP | Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code via a crafted file, aka Bug ID… | Patch early | 7.8 high | 10% | 2016-09-03 |
| CVE-2018-17961 EXP | Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this is… | Patch early | 8.6 high | 10% | 2018-10-15 |
| CVE-2013-6283 EXP | VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a lon… | Patch early | 7.5 high | 10% | 2013-10-25 |
| CVE-2007-2807 EXP | Stack-based buffer overflow in mod/server.mod/servrmsg.c in Eggdrop 1.6.18, and possibly earlier, allows user-assisted, remote IRC servers to execute… | Patch early | 6.8 medium | 10% | 2007-05-22 |
| CVE-2006-4019 EXP | Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variabl… | Patch early | 6.4 medium | 10% | 2006-08-11 |
| CVE-2010-2939 EXP | Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and possibly ot… | Patch early | 4.3 medium | 10% | 2010-08-17 |
| CVE-2021-33904 EXP | In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are conf… | Patch early | 6.1 medium | 10% | 2021-06-07 |
| CVE-2020-25538 EXP | An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web pa… | Patch early | 8.8 high | 10% | 2020-11-13 |
| CVE-2020-25557 EXP | In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs… | Patch early | 8.8 high | 10% | 2020-11-13 |
| CVE-2012-4552 EXP | Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute arbitrary code via a crafted 3… | Patch early | 6.8 medium | 10% | 2012-11-18 |
| CVE-2005-1666 EXP | Multiple buffer overflows in Orenosv HTTP/FTP Server 0.8.1 allow remote authenticated users to cause a denial of service (server crash) and possibly e… | Patch early | 7.5 high | 10% | 2005-05-18 |
| CVE-2007-4582 EXP | Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ACTi Network Video Recorder (NVR) SP2 2.… | Patch early | 7.5 high | 10% | 2007-08-29 |
| CVE-2011-5265 EXP | Cross-site scripting (XSS) vulnerability in cached_image.php in the Featurific For WordPress plugin 1.6.2 for WordPress allows remote attackers to inj… | Patch early | 4.3 medium | 10% | 2013-02-12 |
| CVE-2013-0238 EXP | The try_parse_v4_netmask function in hostmask.c in IRCD-Hybrid before 8.0.6 does not properly validate masks, which allows remote attackers to cause a… | Patch early | 5.0 medium | 10% | 2013-02-13 |
| CVE-2003-1247 EXP | Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile,… | Patch early | 7.5 high | 10% | 2003-12-31 |
| CVE-2008-7170 EXP | GSC build 2067 and earlier relies on the client to enforce administrator privileges, which allows remote attackers to execute arbitrary administrator… | Patch early | 10.0 high | 9.9% | 2009-09-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt