CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,899 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
320,990 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-0177 EXP | Buffer overflows in icecast 1.3.11 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request from an MP3 client. | Patch early | 7.5 high | 9.5% | 2002-04-22 |
| CVE-2010-1130 EXP | session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the sessio… | Patch early | 5.0 medium | 9.5% | 2010-03-26 |
| CVE-2007-6341 EXP | Net/DNS/RR/A.pm in Net::DNS 0.60 build 654, as used in packages such as SpamAssassin and OTRS, allows remote attackers to cause a denial of service (p… | Patch early | 5.0 medium | 9.5% | 2007-12-20 |
| CVE-2019-8820 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.… | Patch early | 8.8 high | 9.5% | 2019-12-18 |
| CVE-2017-17876 EXP | Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a user=download request with a pa… | Patch early | 7.5 high | 9.5% | 2017-12-27 |
| CVE-2020-14461 EXP | Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI. | Patch early | 8.6 high | 9.5% | 2020-06-22 |
| CVE-2006-4826 EXP | PHP remote file inclusion vulnerability in bottom.php in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 9.5% | 2006-09-15 |
| CVE-2008-1482 EXP | Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary… | Patch early | 6.8 medium | 9.5% | 2008-03-24 |
| CVE-2008-2795 EXP | Directory traversal vulnerability in the FTP and SFTP clients in IDM Computer Solutions Inc UltraEdit 14.00b allows remote FTP servers to create or ov… | Patch early | 4.3 medium | 9.5% | 2008-06-20 |
| CVE-2006-3531 EXP | includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers t… | Patch early | 7.5 high | 9.5% | 2006-07-12 |
| CVE-2025-2594 EXP | The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enable… | Patch early | 8.1 high | 9.5% | 2025-04-22 |
| CVE-2016-2087 EXP | Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a .. (dot dot) in th… | Patch early | 7.4 high | 9.5% | 2017-01-18 |
| CVE-2009-0687 EXP | The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and Midnight… | Patch early | 7.8 high | 9.5% | 2009-08-11 |
| CVE-2013-2576 EXP | Buffer overflow in Artweaver before 3.1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a craft… | Patch early | 6.8 medium | 9.5% | 2013-08-09 |
| CVE-2011-1470 EXP | The Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via a ziparchive stream that… | Patch early | 4.3 medium | 9.5% | 2011-03-20 |
| CVE-2007-2677 EXP | Multiple PHP remote file inclusion vulnerabilities in phpChess Community Edition 2.0 allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 9.5% | 2007-05-14 |
| CVE-2007-1453 EXP | Buffer underflow in the PHP_FILTER_TRIM_DEFAULT macro in the filtering extension (ext/filter) in PHP 5.2.0 allows context-dependent attackers to execu… | Patch early | 7.5 high | 9.5% | 2007-03-14 |
| CVE-2006-6740 EXP | Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 9.5% | 2006-12-26 |
| CVE-2017-7041 EXP | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… | Patch early | 8.8 high | 9.5% | 2017-07-20 |
| CVE-2002-0484 EXP | move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to uninten… | Patch early | 5.0 medium | 9.5% | 2002-08-12 |
| CVE-2006-2134 EXP | PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to exe… | Patch early | 5.1 medium | 9.5% | 2006-05-02 |
| CVE-2009-0955 EXP | Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image desc… | Patch early | 9.3 high | 9.5% | 2009-06-02 |
| CVE-2017-15276 EXP | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticat… | Patch early | 8.8 high | 9.5% | 2017-10-13 |
| CVE-2006-0513 EXP | Directory traversal vulnerability in pkmslogout in Tivoli Web Server Plug-in 5.1.0.10 in Tivoli Access Manager (TAM) 5.1 allows remote attackers to re… | Patch early | 5.0 medium | 9.5% | 2006-02-06 |
| CVE-2002-2015 EXP | PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the ca… | Patch early | 7.5 high | 9.5% | 2002-12-31 |
| CVE-2007-4504 EXP | Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allows remote attackers to read ar… | Patch early | 5.0 medium | 9.5% | 2007-08-23 |
| CVE-2018-18924 EXP | The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" because reje… | Patch early | 8.8 high | 9.5% | 2018-11-04 |
| CVE-2010-3847 EXP | elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGI… | Patch early | 6.9 medium | 9.5% | 2011-01-07 |
| CVE-2000-0639 EXP | The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbit… | Patch early | 7.5 high | 9.5% | 2000-06-11 |
| CVE-2009-2109 EXP | Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (… | Patch early | 5.0 medium | 9.5% | 2009-06-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt