CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,922 CVEs
1,739 on KEV
17,301 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
321,744 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-3212 EXP | vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execut… | Patch early | 8.1 high | 7.5% | 2020-01-28 |
| CVE-2008-0149 EXP | TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls the phpinfo function. | Patch early | 5.0 medium | 7.5% | 2008-01-09 |
| CVE-2004-1533 EXP | Buffer overflow in pop3svr.exe for DMS POP3 1.5.3.27 and earlier allows remote attackers to cause a denial of service (service crash) via a long (1) u… | Patch early | 5.0 medium | 7.5% | 2004-12-31 |
| CVE-2002-1905 EXP | Buffer overflow in the web server of Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (crash) via a long HTTP GET req… | Patch early | 5.0 medium | 7.5% | 2002-12-31 |
| CVE-2017-6412 EXP | In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310. | Patch early | 8.1 high | 7.5% | 2017-03-30 |
| CVE-2006-2483 EXP | PHP remote file inclusion vulnerability in cart_content.php in Squirrelcart 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code vi… | Patch early | 6.4 medium | 7.5% | 2006-05-19 |
| CVE-2011-4881 EXP | The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly check return values from functions, which allows remote attackers… | Patch early | 5.0 medium | 7.5% | 2012-04-13 |
| CVE-2019-8558 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1,… | Patch early | 8.8 high | 7.5% | 2019-12-18 |
| CVE-2010-1239 EXP | Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Action /S /Launch" sequence, and… | Patch early | 9.3 high | 7.5% | 2010-04-05 |
| CVE-2008-1613 EXP | SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and 7.0, allows remote attackers t… | Patch early | 7.5 high | 7.5% | 2008-04-22 |
| CVE-2006-5031 EXP | Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read… | Patch early | 5.0 medium | 7.5% | 2006-09-27 |
| CVE-1999-0467 EXP | The Webcom CGI Guestbook programs wguest.exe and rguest.exe allow a remote attacker to read arbitrary files using the "template" parameter. | Patch early | 5.0 medium | 7.5% | 1999-04-01 |
| CVE-2009-1807 EXP | Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the Se… | Patch early | 9.3 high | 7.5% | 2009-05-28 |
| CVE-2008-5753 EXP | Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary code via a bookmark file entry… | Patch early | 9.3 high | 7.5% | 2008-12-30 |
| CVE-2007-1411 EXP | Buffer overflow in PHP 4.4.6 and earlier, and unspecified PHP 5 versions, allows local and possibly remote attackers to execute arbitrary code via lon… | Patch early | 6.8 medium | 7.5% | 2007-03-10 |
| CVE-2019-6279 EXP | ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnerability via the cgi-bin/webproc… | Patch early | 8.8 high | 7.5% | 2019-03-21 |
| CVE-2006-7157 EXP | Buffer overflow in Google Earth v4.0.2091 (beta) allows remote user-assisted attackers to cause a denial of service (crash) via a KML or KMZ file with… | Patch early | 7.1 high | 7.5% | 2007-03-07 |
| CVE-2007-6369 EXP | Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow remote attackers to read arbit… | Patch early | 5.0 medium | 7.5% | 2007-12-15 |
| CVE-2010-0462 EXP | Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impa… | Patch early | 6.5 medium | 7.5% | 2010-01-28 |
| CVE-2023-3219 EXP | The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allo… | Patch early | 5.3 medium | 7.5% | 2023-07-10 |
| CVE-2006-7128 EXP | PHP remote file inclusion vulnerability in forum/forum.php JAF CMS 4.0 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the webs… | Patch early | 7.5 high | 7.5% | 2007-03-06 |
| CVE-2017-7037 EXP | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… | Patch early | 8.8 high | 7.5% | 2017-07-20 |
| CVE-2022-40946 EXP | On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via the sys_token parameter in a cg… | Patch early | 7.5 high | 7.5% | 2023-04-16 |
| CVE-2005-0430 EXP | The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash… | Patch early | 5.0 medium | 7.5% | 2005-02-12 |
| CVE-2011-4644 EXP | Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally does… | Patch early | 9.3 high | 7.5% | 2012-01-03 |
| CVE-2014-8949 EXP | The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metacha… | Patch early | 6.0 medium | 7.5% | 2014-11-16 |
| CVE-2011-5002 EXP | Multiple stack-based buffer overflows in Final Draft 8 before 8.02 allow remote attackers to execute arbitrary code via a .fdx or .fdxt file with long… | Patch early | 10.0 high | 7.5% | 2011-12-25 |
| CVE-2007-3702 EXP | Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier allows remote attackers to re… | Patch early | 5.0 medium | 7.5% | 2007-07-11 |
| CVE-2008-5680 EXP | Multiple buffer overflows in Opera before 9.63 might allow (1) remote attackers to execute arbitrary code via a crafted text area, or allow (2) user-a… | Patch early | 9.3 high | 7.5% | 2008-12-19 |
| CVE-2011-0538 EXP | Wireshark 1.2.0 through 1.2.14, 1.4.0 through 1.4.3, and 1.5.0 frees an uninitialized pointer during processing of a .pcap file in the pcap-ng format,… | Patch early | 6.8 medium | 7.5% | 2011-02-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt