CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,769 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
207,393 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-7097 EXP | Directory traversal vulnerability in 7 Media Web Solutions eduTrac before 1.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in… | Patch early | 5.0 medium | 3.5% | 2014-01-08 |
| CVE-2002-0227 EXP | KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message. | Patch early | 5.0 medium | 3.5% | 2002-05-16 |
| CVE-2009-3038 EXP | A certain ActiveX control in lnresobject.dll 7.1.1.119 in the Research In Motion (RIM) Lotus Notes connector for BlackBerry Desktop Manager 5.0.0.11 a… | Patch early | 4.3 medium | 3.5% | 2009-09-01 |
| CVE-2009-3247 EXP | Cross-site scripting (XSS) vulnerability in the Activities module in vtiger CRM 5.0.4 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 3.5% | 2009-09-18 |
| CVE-2009-4521 EXP | Cross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT) before 2.5.0, as used in KonaK… | Patch early | 4.3 medium | 3.5% | 2009-12-31 |
| CVE-2010-2147 EXP | Cross-site scripting (XSS) vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 3.5% | 2010-06-03 |
| CVE-2020-7108 EXP | The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field. | Patch early | 5.4 medium | 3.5% | 2020-01-16 |
| CVE-2006-5568 EXP | FtpXQ Server 3.0.1 allows remote attackers to cause a denial of service (CPU exhaustion) via a long MKD command. | Patch early | 5.0 medium | 3.5% | 2006-10-27 |
| CVE-2008-3210 EXP | rutil/dns/DnsStub.cxx in ReSIProcate 1.3.2, as used by repro, allows remote attackers to cause a denial of service (daemon crash) via a SIP (1) INVITE… | Patch early | 5.0 medium | 3.5% | 2008-07-18 |
| CVE-2007-0297 EXP | Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.47.11 and 8.48.06 has unknown impact and attack vectors in Pe… | Patch early | 4.0 medium | 3.5% | 2007-01-17 |
| CVE-2012-4960 EXP | The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605, S9300, S7700, S2300, S3300,… | Patch early | 6.5 medium | 3.5% | 2013-06-20 |
| CVE-2002-1423 EXP | tmp_view.php in FUDforum before 2.2.0 allows remote attackers to read arbitrary files via an absolute pathname in the file parameter. | Patch early | 5.0 medium | 3.5% | 2003-04-11 |
| CVE-2004-1493 EXP | Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (server crash) via multiple connections with long nicknames… | Patch early | 5.0 medium | 3.5% | 2004-12-31 |
| CVE-2004-1542 EXP | Buffer overflow in Soldier of Fortune II 1.03 Gold and earlier allows remote attackers to cause a denial of service (server or client crash) via a lon… | Patch early | 5.0 medium | 3.5% | 2004-12-31 |
| CVE-2009-3730 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the ReqWeb Help feature (aka the Web Client Help system) in IBM Rational RequisitePro 7.1.0 all… | Patch early | 4.3 medium | 3.5% | 2009-10-20 |
| CVE-2006-3850 EXP | PHP remote file inclusion vulnerability in upgrader.php in Vanilla CMS 1.0.1 and earlier, when /conf/old_settings.php exists, allows remote attackers… | Patch early | 5.1 medium | 3.4% | 2006-07-25 |
| CVE-1999-1028 EXP | Symantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631. | Patch early | 5.0 medium | 3.4% | 1999-05-28 |
| CVE-2004-0268 EXP | Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP… | Patch early | 5.0 medium | 3.4% | 2004-11-23 |
| CVE-2007-6403 EXP | Stack-based buffer overflow in Nullsoft Winamp 5.32 allows user-assisted remote attackers to execute arbitrary code via crafted unicode in a .mp4 file… | Patch early | 6.8 medium | 3.4% | 2007-12-17 |
| CVE-2006-6703 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Oracle Portal 9i and 10g allow remote attackers to inject arbitrary JavaScript via the tc param… | Patch early | 6.8 medium | 3.4% | 2006-12-23 |
| CVE-2018-0969 EXP | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel… | Patch early | 5.5 medium | 3.4% | 2018-04-12 |
| CVE-2018-0970 EXP | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel… | Patch early | 5.5 medium | 3.4% | 2018-04-12 |
| CVE-2018-0971 EXP | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel… | Patch early | 5.5 medium | 3.4% | 2018-04-12 |
| CVE-2018-0972 EXP | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel… | Patch early | 5.5 medium | 3.4% | 2018-04-12 |
| CVE-2018-0973 EXP | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel… | Patch early | 5.5 medium | 3.4% | 2018-04-12 |
| CVE-2018-0974 EXP | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel… | Patch early | 5.5 medium | 3.4% | 2018-04-12 |
| CVE-2017-18344 EXP | The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly validate the sigevent->sigev_… | Patch early | 5.5 medium | 3.4% | 2018-07-26 |
| CVE-2007-1487 EXP | Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote attackers to read arbitrary f… | Patch early | 5.0 medium | 3.4% | 2007-03-16 |
| CVE-2007-2050 EXP | Multiple directory traversal vulnerabilities in header.php in RicarGBooK 1.2.1 allow remote attackers to include and execute arbitrary local files via… | Patch early | 5.0 medium | 3.4% | 2007-04-16 |
| CVE-2007-0177 EXP | Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2, wh… | Patch early | 5.1 medium | 3.4% | 2007-01-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt