CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,373 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
187,440 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-8352 EXP | By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed… | Patch early | 9.8 critical | 6.3% | 2019-05-20 |
| CVE-2020-25453 EXP | An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution. | Patch early | 8.8 high | 6.3% | 2020-09-15 |
| CVE-2012-4865 EXP | Buffer overflow in Oreans Themida 2.1.8.0 allows remote attackers to execute arbitrary code via a crafted .TMD file. | Patch early | 9.3 high | 6.3% | 2012-09-06 |
| CVE-2012-5324 EXP | Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange 3.60.0128 allow remote attack… | Patch early | 9.3 high | 6.3% | 2012-10-08 |
| CVE-2006-4898 EXP | PHP remote file inclusion vulnerability in include/phpxd/phpXD.php in guanxiCRM 0.9.1 and earlier allows remote attackers to execute arbitrary PHP cod… | Patch early | 7.5 high | 6.3% | 2006-09-19 |
| CVE-2006-4912 EXP | PHP remote file inclusion vulnerability in PHP DocWriter 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the script… | Patch early | 7.5 high | 6.3% | 2006-09-21 |
| CVE-2006-5292 EXP | PHP remote file inclusion vulnerability in photo_comment.php in Exhibit Engine 1.5 RC 4 and earlier allows remote attackers to execute arbitrary PHP c… | Patch early | 7.5 high | 6.3% | 2006-10-16 |
| CVE-2008-3150 EXP | Directory traversal vulnerability in index.php in Neutrino Atomic Edition 0.8.4 allows remote attackers to read and modify files, as demonstrated by m… | Patch early | 10.0 high | 6.3% | 2008-07-11 |
| CVE-2016-1531 EXP | Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument. | Patch early | 7.0 high | 6.3% | 2016-04-07 |
| CVE-2008-5663 EXP | Multiple unrestricted file upload vulnerabilities in Kusaba 1.0.4 and earlier allow remote authenticated users to execute arbitrary code by uploading… | Patch early | 9.0 high | 6.3% | 2008-12-19 |
| CVE-2007-5620 EXP | Directory traversal vulnerability in admin/inc/help.php in ZZ:FlashChat 3.1 and earlier allows remote attackers to include and execute arbitrary local… | Patch early | 7.5 high | 6.3% | 2007-10-22 |
| CVE-2012-2994 EXP | The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number, which makes it easier for re… | Patch early | 7.5 high | 6.3% | 2012-09-18 |
| CVE-2017-2457 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" compon… | Patch early | 8.8 high | 6.3% | 2017-04-02 |
| CVE-2017-2469 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 6.3% | 2017-04-02 |
| CVE-2017-2470 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 6.3% | 2017-04-02 |
| CVE-2007-6230 EXP | Directory traversal vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote attackers to include and execute arb… | Patch early | 7.5 high | 6.3% | 2007-12-04 |
| CVE-2016-3220 EXP | atmfd.dll in the Adobe Type Manager Font Driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window… | Patch early | 7.8 high | 6.3% | 2016-06-16 |
| CVE-2017-13798 EXP | An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… | Patch early | 8.8 high | 6.3% | 2017-11-13 |
| CVE-2008-3299 EXP | eSyndiCat 1.6 allows remote attackers to bypass authentication and gain administrative access by setting the admin_lng cookie value to 1. NOTE: the pr… | Patch early | 7.5 high | 6.3% | 2008-07-25 |
| CVE-2014-4034 EXP | SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the article_id param… | Patch early | 7.5 high | 6.3% | 2014-06-11 |
| CVE-2015-7986 EXP | The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a denial of service (memory corrupti… | Patch early | 7.5 high | 6.2% | 2015-10-27 |
| CVE-2000-0490 EXP | Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN request. | Patch early | 10.0 high | 6.2% | 2000-06-01 |
| CVE-2008-3166 EXP | PHP remote file inclusion vulnerability in modules/global/inc/content.inc.php in BoonEx Ray 3.5, when register_globals is enabled, allows remote attac… | Patch early | 9.3 high | 6.2% | 2008-07-14 |
| CVE-2012-4250 EXP | Stack-based buffer overflow in the RequestScreenOptimization function in the XProcessControl.ocx ActiveX control in msls31.dll in Samsung NET-i viewer… | Patch early | 9.3 high | 6.2% | 2012-08-13 |
| CVE-2015-4594 EXP | eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a n… | Patch early | 9.8 critical | 6.2% | 2017-01-10 |
| CVE-2018-7474 EXP | An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php. | Patch early | 9.8 critical | 6.2% | 2018-03-14 |
| CVE-2003-1140 EXP | Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the configuration file. | Patch early | 10.0 high | 6.2% | 2003-10-27 |
| CVE-2023-4278 EXP | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to regist… | Patch early | 7.5 high | 6.2% | 2023-09-11 |
| CVE-2014-4968 EXP | The WebView class and use of the WebView.addJavascriptInterface method in the Boat Browser application 8.0 and 8.0.1 for Android allow remote attacker… | Patch early | 8.8 high | 6.2% | 2020-02-12 |
| CVE-2023-28288 EXP | Microsoft SharePoint Server Spoofing Vulnerability | Patch early | 8.1 high | 6.2% | 2023-04-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt