CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,829 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
320,901 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2000-0594 EXP | BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a… | Patch early | 5.0 medium | 9.9% | 2000-07-04 |
| CVE-2005-0523 EXP | Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the Loca… | Patch early | 7.5 high | 9.9% | 2005-05-02 |
| CVE-2004-0613 EXP | osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to t… | Patch early | 7.5 high | 9.9% | 2004-12-06 |
| CVE-2015-5161 EXP | The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PH… | Patch early | 6.8 medium | 9.9% | 2015-08-25 |
| CVE-2004-1389 EXP | Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5, DataCenter 3.4, 3.4… | Patch early | 6.0 medium | 9.9% | 2004-12-31 |
| CVE-2006-2744 EXP | PHP remote file inclusion vulnerability in p-popupgallery.php in F@cile Interactive Web 0.8.41 through 0.8.5 allows remote attackers to execute arbitr… | Patch early | 7.5 high | 9.9% | 2006-06-01 |
| CVE-2006-4196 EXP | PHP remote file inclusion vulnerability in index.php in WEBInsta CMS 0.3.1 and possibly earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 9.9% | 2006-08-17 |
| CVE-2007-2424 EXP | PHP remote file inclusion vulnerability in help/index.php in The Merchant (themerchant) 2.2 allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 9.9% | 2007-05-02 |
| CVE-2012-4988 EXP | Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attackers to… | Patch early | 9.3 high | 9.9% | 2014-07-09 |
| CVE-2019-11374 EXP | 74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI. | Patch early | 8.8 high | 9.9% | 2019-04-20 |
| CVE-2008-5120 EXP | Stack-based buffer overflow in the Process Software MultiNet finger service (aka FINGERD) for HP OpenVMS 8.3 allows remote attackers to execute arbitr… | Patch early | 10.0 high | 9.9% | 2008-11-18 |
| CVE-2010-3879 EXP | FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a s… | Patch early | 5.8 medium | 9.8% | 2011-01-22 |
| CVE-2009-4623 EXP | Multiple PHP remote file inclusion vulnerabilities in Advanced Comment System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in th… | Patch early | 7.5 high | 9.8% | 2010-01-18 |
| CVE-2006-2323 EXP | Multiple PHP remote file inclusion vulnerabilities in SmartISoft phpListPro 2.01 and earlier allow remote attackers to execute arbitrary PHP code via… | Patch early | 5.1 medium | 9.8% | 2006-05-12 |
| CVE-2001-1343 EXP | ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the k… | Patch early | 7.5 high | 9.8% | 2001-06-12 |
| CVE-2016-5399 EXP | The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of serv… | Patch early | 7.8 high | 9.8% | 2017-04-21 |
| CVE-2019-8390 EXP | qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter. | Patch early | 6.1 medium | 9.8% | 2019-05-14 |
| CVE-2019-16294 EXP | SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file… | Patch early | 7.8 high | 9.8% | 2019-09-14 |
| CVE-2010-0071 EXP | Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to… | Patch early | 10.0 high | 9.8% | 2010-01-13 |
| CVE-2011-0708 EXP | exif.c in the Exif extension in PHP before 5.3.6 on 64-bit platforms performs an incorrect cast, which allows remote attackers to cause a denial of se… | Patch early | 4.3 medium | 9.8% | 2011-03-20 |
| CVE-2006-2894 EXP | Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and ear… | Patch early | 4.0 medium | 9.8% | 2006-06-07 |
| CVE-2006-1781 EXP | PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 9.8% | 2006-04-13 |
| CVE-1999-1110 EXP | Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote mal… | Patch early | 5.0 medium | 9.8% | 1999-11-14 |
| CVE-2016-8526 EXP | Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to… | Patch early | 8.8 high | 9.8% | 2018-08-06 |
| CVE-2020-24609 EXP | TechKshetra Info Solutions Pvt. Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the XSS payload in the User Registr… | Patch early | 6.1 medium | 9.8% | 2020-08-25 |
| CVE-2019-1674 EXP | A vulnerability in the update service of Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools for Windows could allow an authenticated,… | Patch early | 7.8 high | 9.8% | 2019-02-28 |
| CVE-2009-3705 EXP | PHP remote file inclusion vulnerability in debugger.php in Achievo before 1.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 9.8% | 2009-10-16 |
| CVE-2008-3680 EXP | The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of service (NULL pointer dereferen… | Patch early | 5.0 medium | 9.8% | 2008-08-14 |
| CVE-1999-0935 EXP | classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form. | Patch early | 10.0 high | 9.8% | 1999-12-15 |
| CVE-2006-3955 EXP | Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a allow remote attackers to execute arbitrary PHP code via a URL in the absolute… | Patch early | 7.5 high | 9.8% | 2006-08-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt