CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,011 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
321,002 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-5745 EXP | The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, d… | Patch early | 7.1 high | 8.7% | 2013-10-01 |
| CVE-1999-0176 EXP | The Webgais program allows a remote user to execute arbitrary commands. | Patch early | 7.5 high | 8.7% | 1997-07-10 |
| CVE-1999-0207 EXP | Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command. | Patch early | 7.5 high | 8.7% | 1994-06-09 |
| CVE-2012-1614 EXP | Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/i… | Patch early | 5.0 medium | 8.7% | 2012-09-04 |
| CVE-2004-1150 EXP | Stack-based buffer overflow in the in_cdda.dll plugin for Winamp 5.0 through 5.08c allows attackers to execute arbitrary code via a cda:// URL with a… | Patch early | 5.1 medium | 8.7% | 2004-12-31 |
| CVE-2005-2885 EXP | The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which… | Patch early | 7.5 high | 8.7% | 2005-09-14 |
| CVE-2004-2280 EXP | Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial of service (crash) via unknown… | Patch early | 5.0 medium | 8.7% | 2004-12-31 |
| CVE-2009-1219 EXP | Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allows remote attackers t… | Patch early | 5.0 medium | 8.7% | 2009-04-01 |
| CVE-1999-0147 EXP | The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands. | Patch early | 7.5 high | 8.7% | 1997-07-01 |
| CVE-2003-0470 EXP | Buffer overflow in the "RuFSI Utility Class" ActiveX control (aka "RuFSI Registry Information Class"), as used for the Symantec Security Check service… | Patch early | 7.5 high | 8.7% | 2003-08-07 |
| CVE-2012-5913 EXP | Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject… | Patch early | 4.3 medium | 8.7% | 2012-11-17 |
| CVE-2001-0596 EXP | Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascript. | Patch early | 7.5 high | 8.7% | 2001-08-02 |
| CVE-2010-1313 EXP | Directory traversal vulnerability in the Seber Cart (com_sebercart) component 1.0.0.12 and 1.0.0.13 for Joomla!, when magic_quotes_gpc is disabled, al… | Patch early | 4.3 medium | 8.7% | 2010-04-08 |
| CVE-2008-4343 EXP | The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to create, overwrite, and modify ar… | Patch early | 9.3 high | 8.7% | 2008-09-30 |
| CVE-2008-0493 EXP | fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which… | Patch early | 9.3 high | 8.7% | 2008-01-30 |
| CVE-2016-4313 EXP | Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a .. (dot dot) in… | Patch early | 7.8 high | 8.7% | 2017-04-24 |
| CVE-2004-1915 EXP | Buffer overflow in the parse_all_client_messages function in LCDproc 0.4.x up to 0.4.4 allows remote attackers to execute arbitrary code via a large n… | Patch early | 7.5 high | 8.7% | 2004-04-08 |
| CVE-2007-6333 EXP | The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBC… | Patch early | 5.8 medium | 8.7% | 2007-12-13 |
| CVE-2016-8024 EXP | Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows… | Patch early | 8.1 high | 8.7% | 2017-03-14 |
| CVE-2004-1897 EXP | Administration interface in Monit 1.4 through 4.2 allows remote attackers to cause a denial of service (segmentation fault) by sending a Basic Authent… | Patch early | 5.0 medium | 8.7% | 2004-12-31 |
| CVE-2009-3904 EXP | classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to… | Patch early | 7.5 high | 8.7% | 2009-11-06 |
| CVE-2007-2338 EXP | Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unauthorized b… | Patch early | 7.5 high | 8.7% | 2007-04-27 |
| CVE-2004-2116 EXP | Directory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a .. (dot dot) in the URL. | Patch early | 5.0 medium | 8.7% | 2004-12-31 |
| CVE-2009-2550 EXP | Stack-based buffer overflow in Hamster Audio Player 0.3a allows remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .hpl… | Patch early | 9.3 high | 8.7% | 2009-07-20 |
| CVE-2006-4780 EXP | PHP remote file inclusion vulnerability in includes/functions.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 8.7% | 2006-09-14 |
| CVE-2009-4413 EXP | The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remote attackers to cause a denial… | Patch early | 5.0 medium | 8.7% | 2009-12-24 |
| CVE-2009-1684 EXP | Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2… | Patch early | 4.3 medium | 8.7% | 2009-06-10 |
| CVE-2007-1735 EXP | Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute arbitrary code via a long pri… | Patch early | 9.3 high | 8.7% | 2007-03-28 |
| CVE-2001-0852 EXP | TUX HTTP server 2.1.0-2 in Red Hat Linux allows remote attackers to cause a denial of service via a long Host: header. | Patch early | 5.0 medium | 8.7% | 2001-12-06 |
| CVE-2006-4823 EXP | PHP remote file inclusion vulnerability in scripts/news_page.php in Reamday Enterprises Magic News Pro 1.0.3 and earlier allows remote attackers to ex… | Patch early | 7.5 high | 8.7% | 2006-09-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt