CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,415 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
150,518 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-1763 EXP | Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows local users to gain privileges… | Patch early | 7.2 high | 4.2% | 2013-02-28 |
| CVE-2008-2478 EXP | scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with reseller privileges to exe… | Patch early | 8.5 high | 4.2% | 2008-05-28 |
| CVE-2007-1017 EXP | PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows remote attackers to execute arbi… | Patch early | 9.3 high | 4.2% | 2007-02-21 |
| CVE-2002-0575 EXP | Buffer overflow in OpenSSH before 2.9.9, and 3.x before 3.2.1, with Kerberos/AFS support and KerberosTgtPassing or AFSTokenPassing enabled, allows rem… | Patch early | 7.5 high | 4.2% | 2002-06-18 |
| CVE-2006-4741 EXP | PHP remote file inclusion vulnerability in bits_listings.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute arbitrary code via the… | Patch early | 7.5 high | 4.2% | 2006-09-13 |
| CVE-2008-4767 EXP | Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploading a file w… | Patch early | 9.0 high | 4.2% | 2008-10-28 |
| CVE-2021-29995 EXP | A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in u… | Patch early | 8.8 high | 4.2% | 2021-06-09 |
| CVE-2007-1621 EXP | PHP remote file inclusion vulnerability in templates/head.php in Active PHP Bookmark Notes (APB) 0.2.5 and earlier allows remote attackers to execute… | Patch early | 10.0 high | 4.2% | 2007-03-23 |
| CVE-2007-1778 EXP | PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remote attackers to execute arbitra… | Patch early | 10.0 high | 4.2% | 2007-03-30 |
| CVE-2007-3980 EXP | PHP remote file inclusion vulnerability in page.php in RCMS Pro RGameScript Pro allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 10.0 high | 4.2% | 2007-07-25 |
| CVE-1999-0944 EXP | IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections. | Patch early | 10.0 high | 4.2% | 1999-10-24 |
| CVE-2021-27946 EXP | SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3). | Patch early | 8.8 high | 4.2% | 2021-03-15 |
| CVE-2006-4974 EXP | Buffer overflow in Ipswitch WS_FTP Limited Edition (LE) 5.08 allows remote FTP servers to execute arbitrary code via a long response to a PASV command… | Patch early | 7.5 high | 4.2% | 2006-09-25 |
| CVE-2010-2744 EXP | The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2… | Patch early | 7.2 high | 4.2% | 2010-10-13 |
| CVE-2006-2487 EXP | Multiple PHP remote file inclusion vulnerabilities in ScozNews 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 4.2% | 2006-05-19 |
| CVE-2017-2360 EXP | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. wa… | Patch early | 7.8 high | 4.2% | 2017-02-20 |
| CVE-2007-5187 EXP | SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remote attack… | Patch early | 7.5 high | 4.2% | 2007-10-03 |
| CVE-2017-2501 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… | Patch early | 7.0 high | 4.2% | 2017-05-22 |
| CVE-2006-2507 EXP | Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing 0.2.0 through 0.7.0, as used with phpBB, allow remote attackers to execute arb… | Patch early | 7.5 high | 4.2% | 2006-05-22 |
| CVE-2015-1318 EXP | The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport fi… | Patch early | 7.2 high | 4.2% | 2015-04-17 |
| CVE-2002-2417 EXP | acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or mi… | Patch early | 10.0 high | 4.2% | 2002-12-31 |
| CVE-2005-4216 EXP | The Administration Service (FMSAdmin.exe) in Macromedia Flash Media Server 2.0 r1145 allows remote attackers to cause a denial of service (application… | Patch early | 7.8 high | 4.2% | 2005-12-14 |
| CVE-2010-0552 EXP | Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via mu… | Patch early | 7.5 high | 4.2% | 2010-02-04 |
| CVE-2010-4232 EXP | The web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allo… | Patch early | 10.0 high | 4.2% | 2010-11-17 |
| CVE-2015-8284 EXP | SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions. | Patch early | 8.8 high | 4.2% | 2017-04-13 |
| CVE-2007-1076 EXP | Multiple directory traversal vulnerabilities in phpTrafficA 1.4.1, and possibly earlier, allow remote attackers to include arbitrary local files via a… | Patch early | 7.5 high | 4.2% | 2007-02-22 |
| CVE-2006-6376 EXP | Multiple directory traversal vulnerabilities in fm.php in Simple File Manager (SFM) 0.24a allow remote attackers to use ".." sequences to (1) read arb… | Patch early | 7.5 high | 4.2% | 2006-12-07 |
| CVE-2014-1204 EXP | SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated users to execute arbitrary SQL com… | Patch early | 7.5 high | 4.2% | 2014-01-31 |
| CVE-2015-2878 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of admini… | Patch early | 8.8 high | 4.2% | 2017-10-23 |
| CVE-2005-0185 EXP | Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap packet that con… | Patch early | 7.5 high | 4.2% | 2005-05-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt