CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,851 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
187,224 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-6515 EXP | support/dispatch.cgi in SiteScape Forum allows remote attackers to execute arbitrary TCL code via code separator characters in the query string. | Patch early | 7.5 high | 7.9% | 2007-12-21 |
| CVE-2018-6610 EXP | Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request. | Patch early | 7.5 high | 7.9% | 2018-02-05 |
| CVE-2018-7317 EXP | Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/. | Patch early | 7.5 high | 7.9% | 2018-02-22 |
| CVE-2014-2927 EXP | The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and 1… | Patch early | 9.3 high | 7.9% | 2014-10-15 |
| CVE-2007-1581 EXP | The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file funct… | Patch early | 9.3 high | 7.9% | 2007-03-21 |
| CVE-2007-1867 EXP | Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file. | Patch early | 10.0 high | 7.9% | 2007-04-04 |
| CVE-2000-0446 EXP | Buffer overflow in MDBMS database server allows remote attackers to execute arbitrary commands via a long string. | Patch early | 7.5 high | 7.9% | 2000-05-24 |
| CVE-2000-1116 EXP | Buffer overflow in TransSoft Broker FTP Server before 4.3.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary comm… | Patch early | 7.5 high | 7.9% | 2001-01-09 |
| CVE-2003-1364 EXP | Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) v… | Patch early | 8.5 high | 7.9% | 2003-12-31 |
| CVE-2007-2539 EXP | The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadata) via uns… | Patch early | 7.8 high | 7.9% | 2007-05-09 |
| CVE-2006-6692 EXP | Multiple format string vulnerabilities in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute… | Patch early | 7.5 high | 7.9% | 2006-12-21 |
| CVE-2017-14086 EXP | Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the Office… | Patch early | 7.5 high | 7.9% | 2017-10-06 |
| CVE-2006-6488 EXP | Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used by ICONICS… | Patch early | 7.5 high | 7.9% | 2006-12-31 |
| CVE-2006-4254 EXP | Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 allows local users to gain privileges via unspecified vectors. | Patch early | 7.5 high | 7.9% | 2006-08-21 |
| CVE-2005-4171 EXP | The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbi… | Patch early | 7.5 high | 7.9% | 2005-12-11 |
| CVE-2006-3845 EXP | Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a L… | Patch early | 9.3 high | 7.9% | 2006-07-25 |
| CVE-2006-5289 EXP | Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 7.9% | 2006-10-13 |
| CVE-2006-3019 EXP | Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPCMS_INC… | Patch early | 7.5 high | 7.9% | 2006-06-15 |
| CVE-2023-39115 EXP | install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document. | Patch early | 9.8 critical | 7.9% | 2023-08-16 |
| CVE-2006-4834 EXP | PHP remote file inclusion vulnerability in index.php in Jule Slootbeek phpQuiz 0.01 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 7.9% | 2006-09-15 |
| CVE-2016-3986 EXP | Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a crafted PE file, related to a… | Patch early | 7.8 high | 7.9% | 2016-04-12 |
| CVE-2016-6256 EXP | SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcelle… | Patch early | 9.6 critical | 7.9% | 2017-05-26 |
| CVE-2016-9349 EXP | An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system and extract files that can re… | Patch early | 7.5 high | 7.9% | 2017-02-13 |
| CVE-2001-0857 EXP | Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users… | Patch early | 7.5 high | 7.9% | 2001-12-06 |
| CVE-2008-6947 EXP | Collabtive 0.4.8 allows remote attackers to bypass authentication and create new users, including administrators, via unspecified vectors associated w… | Patch early | 7.5 high | 7.9% | 2009-08-12 |
| CVE-2001-0307 EXP | Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP req… | Patch early | 7.5 high | 7.9% | 2001-05-03 |
| CVE-2009-4679 EXP | Directory traversal vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.5 for Joomla! allows remote attackers to include a… | Patch early | 7.5 high | 7.9% | 2010-03-08 |
| CVE-2022-39290 EXP | ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by mod… | Patch early | 8.0 high | 7.9% | 2022-10-07 |
| CVE-2016-4469 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to hijack the authentication of… | Patch early | 8.8 high | 7.9% | 2016-07-28 |
| CVE-2007-3266 EXP | Directory traversal vulnerability in webif.cgi in ifnet WEBIF allows remote attackers to include and execute arbitrary local files a .. (dot dot) in t… | Patch early | 9.0 high | 7.9% | 2007-06-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt