CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,413 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
150,516 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-2090 EXP | SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for Wordpress allows remote atta… | Patch early | 7.5 high | 4.6% | 2015-02-26 |
| CVE-2014-10013 EXP | SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 4.6% | 2015-01-13 |
| CVE-2014-5189 EXP | SQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin for WordPress allows remote attackers to execute arbitrary SQL comm… | Patch early | 7.5 high | 4.6% | 2014-08-07 |
| CVE-2014-5201 EXP | SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the viewid p… | Patch early | 7.5 high | 4.6% | 2014-08-12 |
| CVE-2020-15238 EXP | Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-mechanism is prone to an argumen… | Patch early | 7.1 high | 4.6% | 2020-10-27 |
| CVE-2000-0026 EXP | Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password authorization string. | Patch early | 10.0 high | 4.6% | 1999-12-21 |
| CVE-2016-6754 EXP | A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote at… | Patch early | 8.8 high | 4.6% | 2016-11-25 |
| CVE-2007-6176 EXP | kb_whois.cgi in K+B-Bestellsystem (aka KB-Bestellsystem) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) dom… | Patch early | 10.0 high | 4.6% | 2007-11-30 |
| CVE-2017-2472 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchO… | Patch early | 7.8 high | 4.6% | 2017-04-02 |
| CVE-2004-2715 EXP | edituser.php3 in PHPMyChat 0.14.5 allow remote attackers to bypass authentication and gain administrative privileges by setting the do_not_login param… | Patch early | 7.5 high | 4.6% | 2004-12-31 |
| CVE-2010-0619 EXP | Stack-based buffer overflow in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE components on certain Lexmark laser pr… | Patch early | 7.3 high | 4.6% | 2010-03-24 |
| CVE-2006-6865 EXP | Directory traversal vulnerability in SAFileUpSamples/util/viewsrc.asp in SoftArtisans FileUp (SAFileUp) 5.0.14 allows remote attackers to read arbitra… | Patch early | 7.8 high | 4.6% | 2006-12-31 |
| CVE-2016-1337 EXP | Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requests during the early part of… | Patch early | 8.1 high | 4.6% | 2016-07-03 |
| CVE-2003-0496 EXP | Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored… | Patch early | 7.2 high | 4.6% | 2003-08-18 |
| CVE-2018-5752 EXP | The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev2… | Patch early | 8.8 high | 4.6% | 2018-06-16 |
| CVE-2021-31950 EXP | Microsoft SharePoint Server Spoofing Vulnerability | Patch early | 7.6 high | 4.6% | 2021-06-08 |
| CVE-2004-1875 EXP | Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) emai… | Patch early | 9.3 high | 4.6% | 2004-03-30 |
| CVE-2006-5911 EXP | Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 4.6% | 2006-11-15 |
| CVE-2018-17980 EXP | NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file located in the same directory as… | Patch early | 7.8 high | 4.6% | 2018-10-15 |
| CVE-2012-4991 EXP | Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated users to (1) read, (2) delete, or… | Patch early | 8.5 high | 4.6% | 2012-12-13 |
| CVE-2006-2646 EXP | Buffer overflow in Alt-N MDaemon, possibly 9.0.1 and earlier, allows remote attackers to execute arbitrary code via a long A0001 argument that begins… | Patch early | 7.5 high | 4.6% | 2006-05-30 |
| CVE-2019-19032 EXP | XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an XML File is validated. The com… | Patch early | 8.1 high | 4.5% | 2019-12-30 |
| CVE-2007-2775 EXP | AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote at… | Patch early | 10.0 high | 4.5% | 2007-05-21 |
| CVE-2009-0602 EXP | Unrestricted file upload vulnerability in upload.php in WikkiTikkiTavi 1.11 allows remote attackers to execute arbitrary code by uploading a file with… | Patch early | 7.5 high | 4.5% | 2009-02-16 |
| CVE-2009-1152 EXP | Siemens Gigaset SE461 WiMAX router 1.5-BL024.9.6401, and possibly other versions, allows remote attackers to cause a denial of service (device restart… | Patch early | 7.3 high | 4.5% | 2009-03-26 |
| CVE-2005-0280 EXP | Format string vulnerability in Soldner Secret Wars 30830 and earlier allows remote attackers to cause a denial of service (server crash) and possibly… | Patch early | 7.5 high | 4.5% | 2005-01-04 |
| CVE-2023-24217 EXP | AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability. | Patch early | 8.8 high | 4.5% | 2023-03-06 |
| CVE-2005-4714 EXP | Format string vulnerability in the vmps_log function in OpenVMPS (VLAN Management Policy Server) 1.3 allows remote attackers to execute arbitrary code… | Patch early | 7.5 high | 4.5% | 2005-12-31 |
| CVE-2006-0171 EXP | PHP remote file include vulnerability in index.php in OrjinWeb E-commerce allows remote attackers to execute arbitrary code via a URL in the page para… | Patch early | 7.5 high | 4.5% | 2006-01-11 |
| CVE-2006-0710 EXP | Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP request, as… | Patch early | 7.5 high | 4.5% | 2006-02-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt