CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,941 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
402,941 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-3127 EXP | Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5 allows local users, and possibly remote attackers, to execute arbitrary code an… | Patch early | 9.3 high | 13.9% | 2010-08-26 |
| CVE-2010-3426 EXP | Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and ex… | Patch early | 7.5 high | 13.9% | 2010-09-16 |
| CVE-2018-12463 EXP | An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to… | Patch early | 9.8 critical | 13.8% | 2018-07-12 |
| CVE-2007-1562 EXP | The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to ot… | Patch early | 6.8 medium | 13.8% | 2007-03-21 |
| CVE-2011-4875 EXP | Stack-based buffer overflow in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP,… | Patch early | 9.3 high | 13.8% | 2012-02-03 |
| CVE-2002-1076 EXP | Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET reque… | Patch early | 7.5 high | 13.8% | 2002-10-04 |
| CVE-2017-9347 EXP | In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/asn1/ros/packet-ros-… | Patch early | 7.5 high | 13.8% | 2017-06-02 |
| CVE-2007-1492 EXP | winmm.dll in Microsoft Windows XP allows user-assisted remote attackers to cause a denial of service (infinite loop) via a large cch argument value to… | Patch early | 7.1 high | 13.8% | 2007-03-16 |
| CVE-2017-18001 EXP | Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys dat… | Patch early | 9.8 critical | 13.8% | 2017-12-31 |
| CVE-2007-3997 EXP | The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir res… | Patch early | 7.5 high | 13.8% | 2007-09-04 |
| CVE-2004-0189 EXP | The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") charact… | Patch early | 7.5 high | 13.8% | 2004-03-15 |
| CVE-2019-8660 EXP | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3.… | Patch early | 9.8 critical | 13.8% | 2019-12-18 |
| CVE-2006-1510 EXP | Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 a… | Patch early | 4.0 medium | 13.8% | 2006-03-30 |
| CVE-2015-0002 EXP | The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, W… | Patch early | 7.2 high | 13.8% | 2015-01-13 |
| CVE-2009-1675 EXP | Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 227 reply to a PASV comma… | Patch early | 9.3 high | 13.8% | 2009-05-18 |
| CVE-2017-7478 EXP | OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue… | Patch early | 7.5 high | 13.8% | 2017-05-15 |
| CVE-2010-4300 EXP | Heap-based buffer overflow in the dissect_ldss_transfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector in Wireshark 1.2.0 through 1.2.… | Patch early | 7.5 high | 13.8% | 2010-11-26 |
| CVE-2019-6973 EXP | Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is conf… | Patch early | 7.5 high | 13.8% | 2019-03-21 |
| CVE-2021-33216 EXP | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer… | Patch early | 9.8 critical | 13.8% | 2021-07-07 |
| CVE-2014-9473 EXP | Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arb… | Patch early | 7.5 high | 13.8% | 2015-01-08 |
| CVE-2022-23409 EXP | The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php. | Patch early | 4.9 medium | 13.8% | 2022-01-31 |
| CVE-2007-4498 EXP | The Grandstream SIP Phone GXV-3000 with firmware 1.0.1.7, Loader 1.0.0.6, and Boot 1.0.0.18 allows remote attackers to force silent call completion, e… | Patch early | 7.8 high | 13.8% | 2007-08-23 |
| CVE-2012-5321 EXP | tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks… | Patch early | 5.8 medium | 13.8% | 2012-10-08 |
| CVE-2018-4237 EXP | An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchO… | Patch early | 7.8 high | 13.7% | 2018-06-08 |
| CVE-2019-11415 EXP | An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. A malformed login request allows remote attackers to cause a denial of service (reboot),… | Patch early | 7.5 high | 13.7% | 2019-04-22 |
| CVE-2009-1902 EXP | The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request… | Patch early | 5.0 medium | 13.7% | 2009-06-03 |
| CVE-2006-3109 EXP | Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), al… | Patch early | 4.3 medium | 13.7% | 2006-06-21 |
| CVE-2013-3631 EXP | NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.php, aka the "Advanced | Execut… | Patch early | 6.0 medium | 13.7% | 2013-11-02 |
| CVE-2001-0522 EXP | Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in th… | Patch early | 7.5 high | 13.7% | 2001-08-14 |
| CVE-2013-3724 EXP | The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash and service… | Patch early | 5.0 medium | 13.7% | 2013-08-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt