CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,108 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
187,325 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-0682 EXP | comersus_gatewayPayPal.asp in Comersus Cart 5.09, and possibly other versions before 5.098, allows remote attackers to change the prices of items by d… | Patch early | 7.5 high | 6.9% | 2004-08-06 |
| CVE-2008-1727 EXP | KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin accou… | Patch early | 7.5 high | 6.9% | 2008-04-11 |
| CVE-2008-5219 EXP | The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require k… | Patch early | 7.5 high | 6.9% | 2008-11-25 |
| CVE-2015-0104 EXP | IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 an… | Patch early | 8.8 high | 6.8% | 2017-04-24 |
| CVE-2013-5657 EXP | AultWare pwStore 2010.8.30.0 has DoS via an empty HTTP request | Patch early | 7.5 high | 6.8% | 2020-01-07 |
| CVE-2004-2614 EXP | Buffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET requ… | Patch early | 7.5 high | 6.8% | 2004-12-31 |
| CVE-2004-1214 EXP | Format string vulnerability in Kreed 1.05 and earlier allows remote attackers to execute arbitrary code via format specifiers in (1) a nickname or (2)… | Patch early | 10.0 high | 6.8% | 2005-01-10 |
| CVE-2011-5162 EXP | Stack-based buffer overflow in GOM Player 2.1.33.5071 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI… | Patch early | 9.3 high | 6.8% | 2012-09-15 |
| CVE-2002-1435 EXP | class.atkdateattribute.js.php in Achievo 0.7.0 through 0.9.1, except 0.8.2, allows remote attackers to execute arbitrary PHP code when the 'allow_url_… | Patch early | 7.5 high | 6.8% | 2003-04-11 |
| CVE-2007-6550 EXP | form.php in PMOS Help Desk 2.4 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct eval inject… | Patch early | 7.5 high | 6.8% | 2007-12-28 |
| CVE-2017-2466 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 6.8% | 2017-04-02 |
| CVE-2007-6489 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 7.5 high | 6.8% | 2007-12-20 |
| CVE-2007-6088 EXP | PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBBViet 02.03.07 and earlier allows remote attackers to execute arbitr… | Patch early | 9.3 high | 6.8% | 2007-11-22 |
| CVE-2000-0136 EXP | The Cart32 shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | Patch early | 7.5 high | 6.8% | 2000-02-01 |
| CVE-2006-1159 EXP | Format string vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote attackers to cause a denial of service (server crash) and possibly… | Patch early | 7.8 high | 6.8% | 2006-03-12 |
| CVE-2007-2187 EXP | Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long DNS response. NOTE: this might… | Patch early | 10.0 high | 6.8% | 2007-04-24 |
| CVE-2008-4588 EXP | Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a denial of service (daemon crash) a… | Patch early | 10.0 high | 6.8% | 2008-10-15 |
| CVE-2017-2527 EXP | An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "CoreAnimation" component. It allows remot… | Patch early | 9.8 critical | 6.8% | 2017-05-22 |
| CVE-2008-3592 EXP | Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers… | Patch early | 8.5 high | 6.8% | 2008-08-11 |
| CVE-2005-2846 EXP | PHP remote file inclusion vulnerability in lang.php in CMS Made Simple 0.10 and earlier allows remote attackers to execute arbitrary PHP code via the… | Patch early | 7.5 high | 6.8% | 2005-09-08 |
| CVE-2012-6509 EXP | Unrestricted file upload vulnerability in NetArt Media Car Portal 3.0 allows remote attackers to execute arbitrary PHP code by uploading a file a doub… | Patch early | 7.5 high | 6.8% | 2013-01-24 |
| CVE-2006-6767 EXP | oftpd before 0.3.7 allows remote attackers to cause a denial of service (daemon abort) via a (1) LPRT or (2) LPASV command with an unsupported address… | Patch early | 7.5 high | 6.8% | 2007-01-16 |
| CVE-2018-10653 EXP | There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | Patch early | 9.8 critical | 6.8% | 2018-05-23 |
| CVE-2017-6060 EXP | Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to have unspecified impact via… | Patch early | 7.8 high | 6.8% | 2017-03-15 |
| CVE-2026-34156 EXP | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's W… | Patch early | 9.9 critical | 6.8% | 2026-03-31 |
| CVE-2017-1274 EXP | IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated attacker to execute arbitrary… | Patch early | 8.8 high | 6.8% | 2017-04-25 |
| CVE-2017-2460 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 6.8% | 2017-04-02 |
| CVE-2008-1136 EXP | The Utils::runScripts function in src/utils.cpp in vdccm 0.92 through 0.10.0 in SynCE (SynCE-dccm) allows remote attackers to execute arbitrary comman… | Patch early | 9.3 high | 6.8% | 2008-03-04 |
| CVE-2006-2875 EXP | Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remote attacker… | Patch early | 7.5 high | 6.8% | 2006-06-07 |
| CVE-2006-5308 EXP | Multiple PHP remote file inclusion vulnerabilities in Open Conference Systems (OCS) before 1.1.6 allow remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 6.8% | 2006-10-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt