CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,429 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
187,458 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-1854 EXP | SQL injection vulnerability in library/clicktracker.php in the AdRotate Pro plugin 3.9 through 3.9.5 and AdRotate Free plugin 3.9 through 3.9.4 for Wo… | Patch early | 7.5 high | 5.7% | 2014-02-27 |
| CVE-2016-8366 EXP | Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by th… | Patch early | 7.3 high | 5.7% | 2018-04-05 |
| CVE-2008-3296 EXP | Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files v… | Patch early | 7.5 high | 5.7% | 2008-07-25 |
| CVE-2000-1100 EXP | The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote att… | Patch early | 7.5 high | 5.7% | 2001-01-09 |
| CVE-2022-2070 EXP | In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf i… | Patch early | 9.8 critical | 5.7% | 2022-09-23 |
| CVE-2011-0502 EXP | Music Animation Machine MIDI Player 2006aug19 Release 035 and possibly other versions allows user-assisted remote attackers to cause a denial of servi… | Patch early | 9.3 high | 5.7% | 2011-01-20 |
| CVE-2004-2061 EXP | RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting… | Patch early | 9.8 critical | 5.7% | 2004-07-27 |
| CVE-2007-3845 EXP | Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbit… | Patch early | 9.3 high | 5.7% | 2007-08-08 |
| CVE-2009-2112 EXP | Directory traversal vulnerability in include/page_bottom.php in phpFK 7.03 allows remote attackers to include and execute arbitrary local files via di… | Patch early | 7.5 high | 5.7% | 2009-06-18 |
| CVE-2009-2183 EXP | Directory traversal vulnerability in admin-files/ad.php in Campsite 3.3.0 RC1 allows remote attackers to read and possibly execute arbitrary local fil… | Patch early | 7.5 high | 5.7% | 2009-06-23 |
| CVE-2022-37706 EXP | enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and the system library function mish… | Patch early | 7.8 high | 5.7% | 2022-12-25 |
| CVE-2005-3489 EXP | Buffer overflow in Asus Video Security 3.5.0.0 and earlier, when using authorization, allows remote attackers to execute arbitrary code via a long use… | Patch early | 7.5 high | 5.7% | 2005-11-04 |
| CVE-2006-2814 EXP | Multiple buffer overflows in the (1) vGetPost and (2) main functions in easy-scart.c through easy-scart6.c in iShopCart allow remote attackers to exec… | Patch early | 7.5 high | 5.7% | 2006-06-05 |
| CVE-2001-0187 EXP | Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands v… | Patch early | 10.0 high | 5.7% | 2001-03-26 |
| CVE-2013-3528 EXP | Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vectors, related to "object i… | Patch early | 7.5 high | 5.7% | 2013-05-10 |
| CVE-2001-0830 EXP | 6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (… | Patch early | 7.5 high | 5.7% | 2001-12-06 |
| CVE-2002-1570 EXP | Heap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execute arbitrary code via multiple… | Patch early | 7.5 high | 5.7% | 2003-11-03 |
| CVE-2006-1794 EXP | SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) th… | Patch early | 7.6 high | 5.7% | 2006-04-17 |
| CVE-2008-4157 EXP | SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 1.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter,… | Patch early | 7.5 high | 5.6% | 2008-09-22 |
| CVE-2008-7168 EXP | Insecure method vulnerability in the UUSee UUUpgrade ActiveX control (UUUpgrade.ocx 3.0.2.12) allows remote attackers to force the download and overwr… | Patch early | 9.3 high | 5.6% | 2009-09-08 |
| CVE-2005-1370 EXP | Unknown vulnerability in Radia Management Agent (RMA) in HP OpenView Radia Management Portal (RMP) 1.x and 2.x allows remote attackers to execute arbi… | Patch early | 7.5 high | 5.6% | 2005-05-03 |
| CVE-2001-1188 EXP | mailto.exe in Brian Dorricott MAILTO 1.0.9 and earlier allows remote attackers to send SPAM e-mail through remote servers by modifying the sendto, ema… | Patch early | 7.5 high | 5.6% | 2001-12-11 |
| CVE-2017-6095 EXP | A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/csvexport.php (Unauthenticat… | Patch early | 9.8 critical | 5.6% | 2017-02-21 |
| CVE-2014-3961 EXP | SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allows remote attackers to execute… | Patch early | 7.5 high | 5.6% | 2014-06-04 |
| CVE-2009-2564 EXP | NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.4… | Patch early | 7.2 high | 5.6% | 2009-07-21 |
| CVE-2008-4437 EXP | Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attack… | Patch early | 7.1 high | 5.6% | 2008-10-03 |
| CVE-2017-2483 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchO… | Patch early | 7.8 high | 5.6% | 2017-04-02 |
| CVE-2016-1825 EXP | IOHIDFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corru… | Patch early | 7.8 high | 5.6% | 2016-05-20 |
| CVE-2009-3484 EXP | Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code via a long hostname in an FTP s… | Patch early | 9.3 high | 5.6% | 2009-09-30 |
| CVE-2017-13056 EXP | The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file. | Patch early | 7.8 high | 5.6% | 2017-12-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt