CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,558 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
169,016 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-2434 EXP | Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace… | Patch early | 5.0 medium | 32.8% | 2004-12-31 |
| CVE-2005-1184 EXP | The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the correc… | Patch early | 5.0 medium | 32.7% | 2005-05-02 |
| CVE-2009-3830 EXP | The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP… | Patch early | 5.0 medium | 32.6% | 2009-10-30 |
| CVE-2015-5471 EXP | Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allows remote attackers to read ar… | Patch early | 5.3 medium | 32.5% | 2016-01-12 |
| CVE-2013-3827 EXP | Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2; the Oracle JDeveloper componen… | Patch early | 5.0 medium | 32.4% | 2013-10-16 |
| CVE-2008-3979 EXP | Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authenticated users to affect confide… | Patch early | 5.5 medium | 32.4% | 2009-01-14 |
| CVE-2012-1153 EXP | Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers to execute arbitrary… | Patch early | 6.8 medium | 32.4% | 2012-10-06 |
| CVE-2000-0495 EXP | Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "Malformed Windows Media Encoder… | Patch early | 5.0 medium | 32.3% | 2000-05-30 |
| CVE-2000-0567 EXP | Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email heade… | Patch early | 5.0 medium | 32.3% | 2000-07-18 |
| CVE-2013-4468 EXP | VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary commands via shell… | Patch early | 6.5 medium | 32.3% | 2014-05-14 |
| CVE-2013-2160 EXP | The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of se… | Patch early | 5.0 medium | 32.3% | 2013-08-19 |
| CVE-2006-0254 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) t… | Patch early | 4.3 medium | 32.2% | 2006-01-18 |
| CVE-2023-4548 EXP | A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3. The impacted element is an unknown function of the file /search of the component GET… | Patch early | 6.3 medium | 32.2% | 2023-08-26 |
| CVE-2001-0149 EXP | Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and… | Patch early | 5.0 medium | 32.2% | 2001-06-02 |
| CVE-2009-4498 EXP | The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request. | Patch early | 6.8 medium | 31.9% | 2009-12-31 |
| CVE-2007-5511 EXP | SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 allows attackers to exec… | Patch early | 6.5 medium | 31.8% | 2007-10-17 |
| CVE-2012-5613 EXP | MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who s… | Patch early | 6.0 medium | 31.7% | 2012-12-03 |
| CVE-2013-4467 EXP | Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier a… | Patch early | 6.5 medium | 31.6% | 2014-03-11 |
| CVE-2001-0663 EXP | Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol… | Patch early | 5.0 medium | 31.6% | 2001-12-06 |
| CVE-2006-1191 EXP | Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote… | Patch early | 4.0 medium | 31.6% | 2006-04-11 |
| CVE-2009-0880 EXP | Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and exec… | Patch early | 6.8 medium | 31.6% | 2009-03-12 |
| CVE-2007-3764 EXP | The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, A… | Patch early | 5.0 medium | 31.5% | 2007-07-18 |
| CVE-2008-0376 EXP | PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 6.8 medium | 31.5% | 2008-01-22 |
| CVE-2012-3137 EXP | The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain… | Patch early | 6.4 medium | 31.4% | 2012-09-21 |
| CVE-2014-1683 EXP | The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is… | Patch early | 6.8 medium | 31.4% | 2014-01-29 |
| CVE-1999-0678 EXP | A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the e… | Patch early | 5.0 medium | 31.4% | 1999-01-17 |
| CVE-1999-0077 EXP | Predictable TCP sequence numbers allow spoofing. | Patch early | 5.0 medium | 31.4% | 1995-01-01 |
| CVE-2007-5363 EXP | PHP remote file inclusion vulnerability in admin.panoramic.php in the Panoramic Picture Viewer (com_panoramic) mambot (plugin) 1.0 for Joomla! allows… | Patch early | 6.8 medium | 31.4% | 2007-10-11 |
| CVE-2007-5841 EXP | PHP remote file inclusion vulnerability in admin/index.php in nuBoard 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the site… | Patch early | 6.8 medium | 31.4% | 2007-11-06 |
| CVE-2007-5451 EXP | PHP remote file inclusion vulnerability in admin.color.php in the com_colorlab (aka com_color) 1.0 component for Joomla! allows remote attackers to ex… | Patch early | 6.8 medium | 31.2% | 2007-10-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt