CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,108 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
150,428 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-6096 EXP | A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/view-list.php (Requires auth… | Patch early | 7.2 high | 5.2% | 2017-02-21 |
| CVE-2017-6097 EXP | A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign/count_of_send.php (Requir… | Patch early | 7.2 high | 5.2% | 2017-02-21 |
| CVE-2009-2361 EXP | SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the st… | Patch early | 7.5 high | 5.2% | 2009-07-08 |
| CVE-2019-19031 EXP | Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS by consuming resources. The c… | Patch early | 8.1 high | 5.2% | 2019-12-30 |
| CVE-2000-0741 EXP | Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code vi… | Patch early | 7.5 high | 5.2% | 2000-10-20 |
| CVE-2007-2821 EXP | SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitrary SQL commands via the cooki… | Patch early | 7.5 high | 5.2% | 2007-05-22 |
| CVE-2022-3141 EXP | The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the sett… | Patch early | 8.8 high | 5.2% | 2022-09-19 |
| CVE-2012-5879 EXP | An ActiveX control in McHealthCheck.dll in McAfee Virtual Technician (MVT) and ePO-MVT 6.5.0.2101 and earlier allows remote attackers to modify or cre… | Patch early | 8.2 high | 5.2% | 2013-03-28 |
| CVE-2008-0805 EXP | Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitrary code by uploading a file w… | Patch early | 9.3 high | 5.2% | 2008-02-19 |
| CVE-2007-6453 EXP | Directory traversal vulnerability in raidenhttpd-admin/workspace.php in RaidenHTTPD 2.0.19, when the WebAdmin function is enabled, allows remote attac… | Patch early | 10.0 high | 5.2% | 2007-12-20 |
| CVE-2006-5551 EXP | Stack-based buffer overflow in QK SMTP 3.01 and earlier might allow remote attackers to execute arbitrary code via a long argument to the RCPT TO comm… | Patch early | 7.5 high | 5.2% | 2006-10-26 |
| CVE-2007-2494 EXP | Multiple stack-based buffer overflows in the PowerPointOCX ActiveX control in PowerPointViewer.ocx 3.1.0.3 allow remote attackers to cause a denial of… | Patch early | 10.0 high | 5.2% | 2007-05-04 |
| CVE-2017-1000364 EXP | An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped"… | Patch early | 7.4 high | 5.2% | 2017-06-19 |
| CVE-2012-1663 EXP | Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (application crash) or possibly ha… | Patch early | 7.5 high | 5.2% | 2012-03-13 |
| CVE-2004-1883 EXP | Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code by causing a large error stri… | Patch early | 7.2 high | 5.2% | 2004-12-31 |
| CVE-2017-6098 EXP | A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign_save.php (Requires authen… | Patch early | 7.2 high | 5.2% | 2017-02-21 |
| CVE-2004-0300 EXP | SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat param… | Patch early | 10.0 high | 5.2% | 2004-11-23 |
| CVE-2013-7030 EXP | The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone… | Patch early | 7.3 high | 5.2% | 2013-12-12 |
| CVE-2010-4297 EXP | The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMware Player 2.5.x bef… | Patch early | 7.2 high | 5.2% | 2010-12-06 |
| CVE-2016-0007 EXP | The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2… | Patch early | 7.8 high | 5.2% | 2016-01-13 |
| CVE-2008-3239 EXP | Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP1, when register_globals is en… | Patch early | 9.3 high | 5.2% | 2008-07-21 |
| CVE-2008-4586 EXP | Insecure method vulnerability in the MVSNCLientWebAgent61.WebAgent.1 ActiveX control (isusweb.dll 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 al… | Patch early | 9.3 high | 5.2% | 2008-10-15 |
| CVE-2008-1247 EXP | The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts, which allows remote attackers… | Patch early | 10.0 high | 5.2% | 2008-03-10 |
| CVE-2006-7012 EXP | scart.cgi in SCart 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter of a show_text action. | Patch early | 10.0 high | 5.2% | 2007-02-15 |
| CVE-2004-0238 EXP | Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME environment… | Patch early | 7.2 high | 5.2% | 2004-11-23 |
| CVE-1999-1190 EXP | Buffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long "From" header in an… | Patch early | 10.0 high | 5.2% | 1999-11-15 |
| CVE-2004-1405 EXP | MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows r… | Patch early | 7.5 high | 5.2% | 2004-12-31 |
| CVE-2016-4793 EXP | The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header. | Patch early | 7.5 high | 5.1% | 2017-01-23 |
| CVE-2010-2549 EXP | Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2 and Server 2008 Gold and SP2 allows local users to gain… | Patch early | 7.2 high | 5.1% | 2010-07-02 |
| CVE-2018-11525 EXP | The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection. | Patch early | 7.8 high | 5.1% | 2018-06-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt