CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,413 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
321,359 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-2184 EXP | Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write arbitrary files via "../" or "..… | Patch early | 6.4 medium | 8.1% | 2004-12-31 |
| CVE-2004-1699 EXP | SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter… | Patch early | 5.0 medium | 8.1% | 2004-09-21 |
| CVE-2004-0269 EXP | SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive inf… | Patch early | 6.4 medium | 8.1% | 2004-11-23 |
| CVE-2001-0183 EXP | ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag in a TCP packet, which makes t… | Patch early | 7.5 high | 8.1% | 2001-03-26 |
| CVE-2016-9018 EXP | Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlaye… | Patch early | 5.5 medium | 8.1% | 2016-10-28 |
| CVE-2001-0192 EXP | Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions. | Patch early | 10.0 high | 8.1% | 2001-05-03 |
| CVE-2006-4955 EXP | Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via… | Patch early | 5.0 medium | 8.1% | 2006-09-23 |
| CVE-2004-0286 EXP | Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a… | Patch early | 10.0 high | 8.1% | 2004-11-23 |
| CVE-2007-3006 EXP | Buffer overflow in Acoustica MP3 CD Burner 4.32 allows user-assisted remote attackers to execute arbitrary code via a .asx playlist file with a REF el… | Patch early | 6.8 medium | 8.1% | 2007-06-04 |
| CVE-2010-1128 EXP | The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attack… | Patch early | 6.4 medium | 8.1% | 2010-03-26 |
| CVE-2000-0242 EXP | WindMail allows remote attackers to read arbitrary files or execute commands via shell metacharacters. | Patch early | 5.0 medium | 8.1% | 2000-03-25 |
| CVE-2002-0006 EXP | XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as other clien… | Patch early | 7.5 high | 8.1% | 2002-06-25 |
| CVE-2014-9633 EXP | The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device handle, which triggers a NULL po… | Patch early | 7.5 high | 8.1% | 2015-02-03 |
| CVE-2006-5395 EXP | Buffer overflow in Microsoft Class Package Export Tool (aka clspack.exe) allows context-dependent attackers to execute arbitrary code via a long strin… | Patch early | 7.5 high | 8.1% | 2006-10-18 |
| CVE-2007-6189 EXP | A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitr… | Patch early | 9.3 high | 8.1% | 2007-11-30 |
| CVE-2010-4323 EXP | Heap-based buffer overflow in novell-tftp.exe in Novell ZENworks Configuration Manager (ZCM) 10.3.1, 10.3.2, and 11.0, and earlier versions, allows re… | Patch early | 7.5 high | 8.1% | 2011-02-19 |
| CVE-2008-7248 EXP | Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to… | Patch early | 6.8 medium | 8.1% | 2009-12-16 |
| CVE-2018-10077 EXP | XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to read arbitrary files via crafted… | Patch early | 4.9 medium | 8.1% | 2018-04-20 |
| CVE-2017-9742 EXP | The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and appl… | Patch early | 7.8 high | 8.1% | 2017-06-19 |
| CVE-2017-9750 EXP | opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers to cause a denial of service (b… | Patch early | 7.8 high | 8.1% | 2017-06-19 |
| CVE-2017-9756 EXP | The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overf… | Patch early | 7.8 high | 8.1% | 2017-06-19 |
| CVE-2005-3405 EXP | ATutor 1.4.1 through 1.5.1-pl1 allows remote attackers to execute arbitrary PHP functions via a direct request to forum.inc.php with a modified addsla… | Patch early | 7.5 high | 8.1% | 2005-11-01 |
| CVE-2008-0729 EXP | Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion and device crash) via certain Ja… | Patch early | 7.1 high | 8.1% | 2008-02-12 |
| CVE-2009-5029 EXP | Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possib… | Patch early | 6.8 medium | 8.1% | 2013-05-02 |
| CVE-2006-1749 EXP | PHP remote file inclusion vulnerability in config.php in phpListPro 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the retu… | Patch early | 7.5 high | 8.1% | 2006-04-12 |
| CVE-2007-3947 EXP | request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as… | Patch early | 5.8 medium | 8.1% | 2007-07-24 |
| CVE-2005-0698 EXP | PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) G_PA… | Patch early | 4.6 medium | 8.1% | 2005-03-07 |
| CVE-2014-8493 EXP | ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to Forms/access_cwmp_1. | Patch early | 5.0 medium | 8.1% | 2014-11-20 |
| CVE-2008-5062 EXP | Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read arbitrary files via directory tr… | Patch early | 5.0 medium | 8.1% | 2008-11-13 |
| CVE-2003-0304 EXP | one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Ins… | Patch early | 10.0 high | 8.1% | 2003-06-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt