CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,941 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
320,998 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-0073 EXP | Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code v… | Patch early | 6.8 medium | 9.3% | 2008-03-24 |
| CVE-2004-1888 EXP | display.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file variable. | Patch early | 7.5 high | 9.3% | 2004-12-31 |
| CVE-2008-3162 EXP | Stack-based buffer overflow in the str_read_packet function in libavformat/psxstr.c in FFmpeg before r13993 allows remote attackers to cause a denial… | Patch early | 9.3 high | 9.3% | 2008-07-14 |
| CVE-2024-12342 EXP | A vulnerability was found in TP-Link VN020 F3v(T) TT_V6.2.1021. It has been rated as critical. This issue affects some unknown processing of the file… | Patch early | 6.5 medium | 9.3% | 2024-12-08 |
| CVE-2004-2526 EXP | Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .… | Patch early | 5.0 medium | 9.3% | 2004-12-31 |
| CVE-2010-5028 EXP | SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 9.2% | 2011-11-02 |
| CVE-2002-1275 EXP | Unknown vulnerability in html2ps HTML/PostScript converter 1.0, when used within LPRng, allows remote attackers to execute arbitrary code via "unsanit… | Patch early | 7.5 high | 9.2% | 2002-11-12 |
| CVE-2023-38501 EXP | copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and… | Patch early | 6.3 medium | 9.2% | 2023-07-25 |
| CVE-2007-4821 EXP | Buffer overflow in a certain ActiveX control in officeviewer.ocx 5.2.218.1 in EDraw Office Viewer Component 5.2 allows remote attackers to execute arb… | Patch early | 9.3 high | 9.2% | 2007-09-11 |
| CVE-2002-0772 EXP | Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories via a .. (d… | Patch early | 6.4 medium | 9.2% | 2002-08-12 |
| CVE-2008-0096 EXP | Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to execute arbitrary code via a (1)… | Patch early | 7.5 high | 9.2% | 2008-01-08 |
| CVE-2010-1869 EXP | Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a cra… | Patch early | 9.3 high | 9.2% | 2010-05-12 |
| CVE-2007-1701 EXP | PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deseria… | Patch early | 6.8 medium | 9.2% | 2007-03-27 |
| CVE-2005-2006 EXP | JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a "%." (percent dot), which rev… | Patch early | 5.0 medium | 9.2% | 2005-06-17 |
| CVE-2002-1559 EXP | Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (drive letter) or (2) .. (dot-do… | Patch early | 5.0 medium | 9.2% | 2003-03-31 |
| CVE-2014-9225 EXP | The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server… | Patch early | 4.0 medium | 9.2% | 2015-01-21 |
| CVE-2003-0767 EXP | Buffer overflow in RogerWilco graphical server 1.4.1.6 and earlier, dedicated server 0.32a and earlier for Windows, and 0.27 and earlier for Linux and… | Patch early | 7.5 high | 9.2% | 2003-09-17 |
| CVE-2009-1045 EXP | requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of service (stack consumption and crash) via a long input argument in an i… | Patch early | 5.0 medium | 9.2% | 2009-03-23 |
| CVE-2001-0748 EXP | Acme.Serve 1.7, as used in Cisco Secure ACS Unix and possibly other products, allows remote attackers to read arbitrary files by prepending several /… | Patch early | 5.0 medium | 9.2% | 2001-10-18 |
| CVE-2006-2901 EXP | The web server for D-Link Wireless Access-Point (DWL-2100ap) firmware 2.10na and earlier allows remote attackers to obtain sensitive system informatio… | Patch early | 5.0 medium | 9.2% | 2006-06-07 |
| CVE-2008-0778 EXP | Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow remote attackers to cause a de… | Patch early | 7.5 high | 9.2% | 2008-02-14 |
| CVE-2016-8023 EXP | Authentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote un… | Patch early | 8.1 high | 9.2% | 2017-03-14 |
| CVE-2000-0787 EXP | IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which XC… | Patch early | 7.5 high | 9.2% | 2000-10-20 |
| CVE-2011-0678 EXP | Unrestricted file upload vulnerability in the EasyEdit module in Lomtec ActiveWeb Professional 3.0 allows remote attackers to execute arbitrary code b… | Patch early | 6.8 medium | 9.2% | 2011-01-28 |
| CVE-2008-5183 EXP | cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large numbe… | Patch early | 7.5 high | 9.2% | 2008-11-21 |
| CVE-2011-4898 EXP | wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbnam… | Patch early | 5.0 medium | 9.2% | 2012-01-30 |
| CVE-2008-4101 EXP | Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands b… | Patch early | 9.3 high | 9.2% | 2008-09-18 |
| CVE-2015-5895 EXP | Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors. | Patch early | 10.0 high | 9.2% | 2015-09-18 |
| CVE-2013-2287 EXP | Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject ar… | Patch early | 4.3 medium | 9.2% | 2014-04-04 |
| CVE-2007-1381 EXP | The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and fixed on 20070304, calls strl… | Patch early | 7.6 high | 9.2% | 2007-03-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt