CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,905 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
321,728 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-27519 EXP | A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter. | Patch early | 6.1 medium | 7.6% | 2021-03-19 |
| CVE-2010-0314 EXP | Apple Safari allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL… | Patch early | 5.0 medium | 7.6% | 2010-01-14 |
| CVE-2020-35488 EXP | The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a… | Patch early | 7.5 high | 7.6% | 2021-01-05 |
| CVE-2016-6512 EXP | epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, which allows remote attackers to… | Patch early | 5.9 medium | 7.6% | 2016-08-06 |
| CVE-2008-1762 EXP | Opera before 9.27 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted scaled image pattern… | Patch early | 9.3 high | 7.6% | 2008-04-12 |
| CVE-2008-0624 EXP | Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to execute arbitrary code via a… | Patch early | 4.3 medium | 7.6% | 2008-02-06 |
| CVE-2006-4532 EXP | PHP remote file inclusion vulnerability in articles/article.php in Yet Another Community System (YACS) CMS 6.6.1 and earlier allows remote attackers t… | Patch early | 7.5 high | 7.6% | 2006-09-01 |
| CVE-2010-4769 EXP | Directory traversal vulnerability in the Jimtawl (com_jimtawl) component 1.0.2 Joomla! allows remote attackers to read arbitrary files and possibly ha… | Patch early | 7.5 high | 7.6% | 2011-03-23 |
| CVE-2016-2279 EXP | Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote atta… | Patch early | 6.1 medium | 7.6% | 2016-03-02 |
| CVE-2007-0540 EXP | WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that cor… | Patch early | 5.0 medium | 7.6% | 2007-01-29 |
| CVE-1999-0239 EXP | Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET. | Patch early | 7.5 high | 7.6% | 1998-01-01 |
| CVE-2006-2236 EXP | Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote atta… | Patch early | 7.6 high | 7.6% | 2006-05-08 |
| CVE-2006-1688 EXP | Multiple PHP remote file inclusion vulnerabilities in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allow remote att… | Patch early | 7.5 high | 7.6% | 2006-04-11 |
| CVE-2006-2182 EXP | Multiple PHP remote file inclusion vulnerabilities in (1) eday.php, (2) eshow.php, or (3) forgot.php in albinator 2.0.8 and earlier allow remote attac… | Patch early | 6.4 medium | 7.6% | 2006-05-04 |
| CVE-2008-7080 EXP | Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obt… | Patch early | 5.0 medium | 7.6% | 2009-08-25 |
| CVE-2010-1214 EXP | Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitra… | Patch early | 9.3 high | 7.6% | 2010-07-30 |
| CVE-2007-2930 EXP | The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS query identifiers when sending… | Patch early | 4.3 medium | 7.6% | 2007-09-12 |
| CVE-2004-1903 EXP | Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an object tag. | Patch early | 10.0 high | 7.6% | 2004-12-31 |
| CVE-2004-2114 EXP | Stack-based and heap-based buffer overflows in ProxyNow! 2.75 and earlier allow remote attackers to execute arbitrary code via a GET request with a lo… | Patch early | 10.0 high | 7.6% | 2004-12-31 |
| CVE-2005-0339 EXP | Buffer overflow in Foxmail 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long MAIL FROM command. | Patch early | 10.0 high | 7.6% | 2005-05-02 |
| CVE-2008-3314 EXP | ZDaemon 1.08.07 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted type 6 command, which triggers a NULL po… | Patch early | 5.0 medium | 7.6% | 2008-07-25 |
| CVE-2008-1303 EXP | The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon crash) via a… | Patch early | 5.0 medium | 7.6% | 2008-03-12 |
| CVE-2014-5116 EXP | The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attackers to cause a denial of serv… | Patch early | 5.0 medium | 7.6% | 2014-07-29 |
| CVE-2000-0333 EXP | tcpdump, Ethereal, and other sniffer packages allow remote attackers to cause a denial of service via malformed DNS packets in which a jump offset ref… | Patch early | 5.0 medium | 7.6% | 1999-05-31 |
| CVE-2017-15920 EXP | In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability tha… | Patch early | 7.5 high | 7.6% | 2017-10-30 |
| CVE-2017-15921 EXP | In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability tha… | Patch early | 7.5 high | 7.6% | 2017-10-30 |
| CVE-2008-1411 EXP | The PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to cause a denial of service (crash) via an incomple… | Patch early | 5.0 medium | 7.6% | 2008-03-20 |
| CVE-2008-1855 EXP | FrameworkService.exe in McAfee Common Management Agent (CMA) 3.6.0.574 Patch 3 and earlier, as used by ePolicy Orchestrator (ePO) and ProtectionPilot… | Patch early | 5.0 medium | 7.6% | 2008-04-16 |
| CVE-2010-2785 EXP | The IRC Protocol component in KVIrc 3.x and 4.x before r4693 does not properly handle \ (backslash) characters, which allows remote authenticated user… | Patch early | 6.5 medium | 7.6% | 2010-08-02 |
| CVE-2006-0328 EXP | Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) G… | Patch early | 5.0 medium | 7.6% | 2006-01-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt