CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,891 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
321,717 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-6126 EXP | A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML… | Patch early | 8.8 high | 7.7% | 2019-01-09 |
| CVE-2015-6750 EXP | Buffer overflow in Ricoh DL FTP Server 1.1.0.6 and earlier allows remote attackers to execute arbitrary code via a long USER command. | Patch early | 7.5 high | 7.7% | 2015-08-31 |
| CVE-2010-0642 EXP | Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded characters in the filename extension… | Patch early | 5.0 medium | 7.7% | 2010-02-17 |
| CVE-2003-1341 EXP | The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.e… | Patch early | 7.5 high | 7.7% | 2003-12-31 |
| CVE-2008-2106 EXP | Call of Duty 4 (CoD4) 1.5 and earlier allows remote authenticated users to cause a denial of service (crash) via a type 7 stats packet, which triggers… | Patch early | 6.8 medium | 7.7% | 2008-05-07 |
| CVE-2012-6313 EXP | simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information via a reque… | Patch early | 5.0 medium | 7.7% | 2012-12-11 |
| CVE-2015-3693 EXP | Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates for DDR3 RAM, which might make i… | Patch early | 9.3 high | 7.7% | 2015-07-03 |
| CVE-2008-4134 EXP | PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other versions before 0.05, allows remo… | Patch early | 7.5 high | 7.7% | 2008-09-19 |
| CVE-2007-2519 EXP | Directory traversal vulnerability in the installer in PEAR 1.0 through 1.5.3 allows user-assisted remote attackers to overwrite arbitrary files via a… | Patch early | 6.8 medium | 7.7% | 2007-05-22 |
| CVE-2006-1610 EXP | PHP remote file inclusion vulnerability in lib/armygame.php in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allows… | Patch early | 5.1 medium | 7.7% | 2006-04-04 |
| CVE-2008-4509 EXP | Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows remote attackers to execute a… | Patch early | 10.0 high | 7.7% | 2008-10-09 |
| CVE-2017-6984 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. iTunes before 12.6.1 on Windows is… | Patch early | 8.8 high | 7.7% | 2017-05-22 |
| CVE-2013-3615 EXP | Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent attackers to discover clearte… | Patch early | 7.8 high | 7.7% | 2013-09-17 |
| CVE-2000-0207 EXP | SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters. | Patch early | 7.5 high | 7.7% | 2000-03-01 |
| CVE-2000-0424 EXP | The CGI counter 4.0.7 by George Burgyan allows remote attackers to execute arbitrary commands via shell metacharacters. | Patch early | 7.5 high | 7.7% | 2000-05-15 |
| CVE-2000-0432 EXP | The calender.pl and the calendar_admin.pl calendar scripts by Matt Kruse allow remote attackers to execute arbitrary commands via shell metacharacters… | Patch early | 7.5 high | 7.7% | 2000-05-16 |
| CVE-2012-1830 EXP | Stack-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 555. | Patch early | 10.0 high | 7.7% | 2012-07-05 |
| CVE-2014-7910 EXP | Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service or possibly have other impact v… | Patch early | 7.5 high | 7.7% | 2014-11-19 |
| CVE-2002-2145 EXP | Savant Web Server 3.1 and earlier allows remote attackers to bypass authentication for password protected user folders via a URL with a hex encoded sp… | Patch early | 7.5 high | 7.7% | 2002-12-31 |
| CVE-2000-0782 EXP | netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 5.0 medium | 7.7% | 2000-10-20 |
| CVE-2000-0930 EXP | Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch. | Patch early | 5.0 medium | 7.7% | 2000-12-19 |
| CVE-1999-0800 EXP | The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm. | Patch early | 5.0 medium | 7.7% | 2001-03-12 |
| CVE-2000-0240 EXP | vqSoft vqServer program allows remote attackers to read arbitrary files via a /........../ in the URL, a variation of a .. (dot dot) attack. | Patch early | 5.0 medium | 7.7% | 2000-03-21 |
| CVE-2006-0881 EXP | Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attac… | Patch early | 7.5 high | 7.7% | 2006-02-24 |
| CVE-2011-4336 EXP | Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php. | Patch early | 6.1 medium | 7.7% | 2020-01-15 |
| CVE-2005-0229 EXP | CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card informati… | Patch early | 5.0 medium | 7.7% | 2005-04-27 |
| CVE-2012-5907 EXP | Directory traversal vulnerability in json.php in TomatoCart 1.2.0 Alpha 2 and possibly earlier allows remote attackers to read arbitrary files via a .… | Patch early | 5.0 medium | 7.7% | 2012-11-17 |
| CVE-2013-2619 EXP | Directory traversal vulnerability in Aspen before 0.22 allows remote attackers to read arbitrary files via a .. (dot dot) to the default URI. | Patch early | 5.0 medium | 7.7% | 2014-03-18 |
| CVE-2014-10010 EXP | Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id… | Patch early | 5.0 medium | 7.7% | 2015-01-13 |
| CVE-2014-3806 EXP | Directory traversal vulnerability in cgi-bin/help/doIt.cgi in VMTurbo Operations Manager before 4.6 allows remote attackers to read arbitrary files vi… | Patch early | 5.0 medium | 7.7% | 2014-05-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt