CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,145 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
321,918 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-3130 EXP | Untrusted search path vulnerability in TechSmith Snagit all versions 10.x and 11.x allows local users, and possibly remote attackers, to execute arbit… | Patch early | 9.3 high | 7.8% | 2010-08-26 |
| CVE-2006-2330 EXP | PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary… | Patch early | 6.4 medium | 7.8% | 2006-05-12 |
| CVE-2026-46368 EXP | luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt commun… | Patch early | 8.8 high | 7.8% | 2026-05-26 |
| CVE-2007-1362 EXP | Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to cause a denial of service via… | Patch early | 4.3 medium | 7.8% | 2007-06-01 |
| CVE-2007-4244 EXP | PHP remote file inclusion vulnerability in langset.php in J! Reactions (com_jreactions) 1.8.1 and earlier, a Joomla! component, allows remote attacker… | Patch early | 7.5 high | 7.8% | 2007-08-08 |
| CVE-2010-3126 EXP | Untrusted search path vulnerability in avast! Free Antivirus version 5.0.594 and earlier allows local users, and possibly remote attackers, to execute… | Patch early | 9.3 high | 7.8% | 2010-08-26 |
| CVE-2010-3137 EXP | Untrusted search path vulnerability in Nullsoft Winamp 5.581, and probably other versions, allows local users, and possibly remote attackers, to execu… | Patch early | 9.3 high | 7.8% | 2010-08-26 |
| CVE-2007-2425 EXP | Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the album par… | Patch early | 5.0 medium | 7.8% | 2007-05-02 |
| CVE-2013-6343 EXP | Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow remote attackers to execute a… | Patch early | 10.0 high | 7.8% | 2014-01-22 |
| CVE-2002-0982 EXP | Microsoft SQL Server 2000 SP2, when configured as a distributor, allows attackers to execute arbitrary code via the @scriptfile parameter to the sp_MS… | Patch early | 7.5 high | 7.8% | 2002-09-24 |
| CVE-2018-10608 EXP | SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects to a malicious FTP server, wh… | Patch early | 7.5 high | 7.8% | 2018-07-24 |
| CVE-2007-2611 EXP | Multiple PHP remote file inclusion vulnerabilities in CGX 20050314 allow remote attackers to execute arbitrary PHP code via a URL in the pathCGX param… | Patch early | 6.8 medium | 7.8% | 2007-05-11 |
| CVE-2012-3816 EXP | WinRadius Server 2009 allows remote attackers to cause a denial of service (crash) via a long password in an Access-Request packet. | Patch early | 7.8 high | 7.8% | 2012-06-27 |
| CVE-2005-3293 EXP | Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory contents via a… | Patch early | 5.0 medium | 7.8% | 2005-10-23 |
| CVE-2008-6178 EXP | Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4 CMS, Nuke… | Patch early | 7.5 high | 7.8% | 2009-02-19 |
| CVE-2008-1488 EXP | Stack-based buffer overflow in apc.c in Alternative PHP Cache (APC) 3.0.11 through 3.0.16 allows remote attackers to execute arbitrary code via a long… | Patch early | 6.8 medium | 7.8% | 2008-03-24 |
| CVE-2000-0688 EXP | Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for t… | Patch early | 7.5 high | 7.8% | 2000-10-20 |
| CVE-2000-0689 EXP | Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges fo… | Patch early | 7.5 high | 7.8% | 2000-10-20 |
| CVE-2019-19142 EXP | Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmware.cfg URI. | Patch early | 7.5 high | 7.8% | 2020-01-17 |
| CVE-2008-3360 EXP | Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code via a long URL in the HREF att… | Patch early | 9.3 high | 7.8% | 2008-07-29 |
| CVE-2012-3549 EXP | The SCTP implementation in FreeBSD 8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted… | Patch early | 7.8 high | 7.8% | 2012-10-09 |
| CVE-2009-2478 EXP | Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors, rel… | Patch early | 5.0 medium | 7.8% | 2009-07-16 |
| CVE-2019-11446 EXP | An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files se… | Patch early | 8.8 high | 7.8% | 2019-04-22 |
| CVE-2021-27825 EXP | A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL. | Patch early | 7.5 high | 7.8% | 2023-05-29 |
| CVE-2013-3956 EXP | The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2 on Windows Vista and Windows… | Patch early | 7.2 high | 7.8% | 2013-07-31 |
| CVE-2006-5196 EXP | The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with… | Patch early | 7.8 high | 7.8% | 2006-10-10 |
| CVE-2017-6805 EXP | Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read arbitrary files via a .. (dot d… | Patch early | 5.3 medium | 7.8% | 2017-03-20 |
| CVE-2012-6470 EXP | Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a denial of serv… | Patch early | 9.3 high | 7.8% | 2013-01-02 |
| CVE-2009-1353 EXP | Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause a denial of service (daemon cr… | Patch early | 5.0 medium | 7.8% | 2009-04-21 |
| CVE-2005-2719 EXP | Ventrilo 2.1.2 through 2.3.0 allows remote attackers to cause a denial of service (application crash) via a status packet that contains less data than… | Patch early | 5.0 medium | 7.8% | 2005-08-30 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt