CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,041 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
321,045 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2003-0143 EXP | The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authentic… | Patch early | 10.0 high | 8.6% | 2003-03-18 |
| CVE-1999-0953 EXP | WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers. | Patch early | 10.0 high | 8.6% | 1999-09-16 |
| CVE-2000-0977 EXP | mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" paramet… | Patch early | 5.0 medium | 8.6% | 2000-12-19 |
| CVE-2010-2307 EXP | Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHP… | Patch early | 5.0 medium | 8.6% | 2010-06-16 |
| CVE-2003-1148 EXP | Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and po… | Patch early | 7.5 high | 8.6% | 2003-10-25 |
| CVE-2007-0614 EXP | The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a… | Patch early | 7.8 high | 8.6% | 2007-01-31 |
| CVE-2008-6953 EXP | Buffer overflow in oovoo.exe in ooVoo 1.7.1.35, and possibly other versions before 1.7.1.59, allows remote attackers to cause a denial of service (cra… | Patch early | 9.3 high | 8.6% | 2009-08-12 |
| CVE-2007-0817 EXP | Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Ag… | Patch early | 4.3 medium | 8.6% | 2007-02-07 |
| CVE-2002-0962 EXP | Cross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via (1) the url variable in the L… | Patch early | 7.5 high | 8.6% | 2002-10-04 |
| CVE-2005-4559 EXP | mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly ini… | Patch early | 5.0 medium | 8.6% | 2005-12-28 |
| CVE-2007-2482 EXP | Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allo… | Patch early | 6.8 medium | 8.6% | 2007-05-03 |
| CVE-2008-4323 EXP | Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application crash) via a crafted .ZIP file. | Patch early | 4.3 medium | 8.6% | 2008-09-29 |
| CVE-2016-3963 EXP | Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 443. | Patch early | 5.3 medium | 8.6% | 2016-04-08 |
| CVE-2011-1143 EXP | epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (NULL pointer… | Patch early | 4.3 medium | 8.6% | 2011-03-03 |
| CVE-2000-0508 EXP | rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request. | Patch early | 5.0 medium | 8.6% | 1994-12-19 |
| CVE-2003-0651 EXP | Buffer overflow in the mylo_log logging function for mod_mylo 0.2.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET… | Patch early | 7.5 high | 8.6% | 2003-08-27 |
| CVE-2006-4877 EXP | Variable overwrite vulnerability in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to overwrite arbitrary program variables via… | Patch early | 5.0 medium | 8.6% | 2006-09-19 |
| CVE-2018-4200 EXP | An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud before 7.5 on Windows is affe… | Patch early | 8.8 high | 8.6% | 2018-06-08 |
| CVE-2009-1830 EXP | Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long search query. | Patch early | 10.0 high | 8.6% | 2009-05-29 |
| CVE-2010-1176 EXP | Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… | Patch early | 9.3 high | 8.6% | 2010-03-29 |
| CVE-2019-3999 EXP | Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to exe… | Patch early | 7.8 high | 8.6% | 2020-02-25 |
| CVE-2008-0127 EXP | The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute ar… | Patch early | 8.8 high | 8.6% | 2008-01-10 |
| CVE-2014-6389 EXP | backup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the d parameter. | Patch early | 7.5 high | 8.6% | 2014-10-06 |
| CVE-2014-9144 EXP | Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metacharacters in the ping field (s… | Patch early | 7.5 high | 8.6% | 2014-12-05 |
| CVE-2010-1685 EXP | Stack-based buffer overflow in CursorArts ZipWrangler 1.20 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing a… | Patch early | 9.3 high | 8.6% | 2010-05-04 |
| CVE-2007-6584 EXP | Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot)… | Patch early | 6.4 medium | 8.6% | 2007-12-28 |
| CVE-2008-0379 EXP | Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to c… | Patch early | 9.3 high | 8.6% | 2008-01-22 |
| CVE-2010-3306 EXP | Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%… | Patch early | 5.0 medium | 8.6% | 2010-09-24 |
| CVE-2008-6833 EXP | Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and execute arbitrary local files… | Patch early | 10.0 high | 8.6% | 2009-06-22 |
| CVE-2012-0406 EXP | The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a deni… | Patch early | 7.8 high | 8.6% | 2012-04-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt