CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,932 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
321,751 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-5877 EXP | Nero MediaHome 4.5.8.0 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an HTTP header withou… | Patch early | 5.0 medium | 7.5% | 2014-05-30 |
| CVE-2002-1527 EXP | emumail.cgi in EMU Webmail 5.0 allows remote attackers to determine the full pathname for emumail.cgi via a malformed string containing script, which… | Patch early | 5.0 medium | 7.5% | 2003-04-02 |
| CVE-2001-0215 EXP | ROADS search.pl program allows remote attackers to read arbitrary files by specifying the file name in the form parameter and terminating the filename… | Patch early | 5.0 medium | 7.5% | 2001-06-02 |
| CVE-2002-0215 EXP | Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existe… | Patch early | 5.0 medium | 7.5% | 2002-05-16 |
| CVE-1999-0842 EXP | Symantec Mail-Gear 1.0 web interface server allows remote users to read arbitrary files via a .. (dot dot) attack. | Patch early | 5.0 medium | 7.5% | 1999-11-29 |
| CVE-2006-5850 EXP | Stack-based buffer overflow in Essentia Web Server 2.15 for Windows allows remote attackers to execute arbitrary code via a long URI, as demonstrated… | Patch early | 7.5 high | 7.5% | 2006-11-10 |
| CVE-2010-2153 EXP | Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attackers to execu… | Patch early | 6.8 medium | 7.5% | 2010-06-03 |
| CVE-2006-5633 EXP | Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange… | Patch early | 5.0 medium | 7.5% | 2006-10-31 |
| CVE-2006-7236 EXP | The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attacke… | Patch early | 9.3 high | 7.5% | 2009-01-02 |
| CVE-2001-0262 EXP | Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL. | Patch early | 7.5 high | 7.5% | 2001-07-02 |
| CVE-2009-1557 EXP | Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allow remote… | Patch early | 4.3 medium | 7.5% | 2009-05-06 |
| CVE-2004-1926 EXP | Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4)… | Patch early | 7.5 high | 7.5% | 2004-04-11 |
| CVE-2011-1984 EXP | WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over th… | Patch early | 7.2 high | 7.5% | 2011-09-15 |
| CVE-2007-3360 EXP | hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data containing NICK and EXEC strings,… | Patch early | 9.3 high | 7.5% | 2007-06-22 |
| CVE-2021-43116 EXP | An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and th… | Patch early | 8.8 high | 7.5% | 2022-07-05 |
| CVE-2017-0220 EXP | The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gold allows authenticated attackers to obtain sensiti… | Patch early | 4.7 medium | 7.5% | 2017-05-12 |
| CVE-1999-0347 EXP | Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which caus… | Patch early | 10.0 high | 7.5% | 1999-01-26 |
| CVE-2005-2033 EXP | Directory traversal vulnerability in folderview.asp for Blue-Collar Productions i-Gallery 3.3 allows remote attackers to read arbitrary files and dire… | Patch early | 5.0 medium | 7.5% | 2005-06-20 |
| CVE-2010-0655 EXP | Use-after-free vulnerability in Google Chrome before 4.0.249.78 allows user-assisted remote attackers to cause a denial of service (application crash)… | Patch early | 9.3 high | 7.5% | 2010-02-18 |
| CVE-2007-1842 EXP | Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a ..… | Patch early | 7.5 high | 7.5% | 2007-04-03 |
| CVE-2002-1991 EXP | PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php. | Patch early | 7.5 high | 7.5% | 2002-12-31 |
| CVE-2014-5370 EXP | Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDragon before 7.1.1.18527 allows… | Patch early | 7.5 high | 7.5% | 2015-04-21 |
| CVE-2014-8555 EXP | Directory traversal vulnerability in report/reportViewAction.jsp in Progress Software OpenEdge 11.2 allows remote attackers to read arbitrary files vi… | Patch early | 5.0 medium | 7.5% | 2014-11-12 |
| CVE-2001-0780 EXP | Directory traversal vulnerability in cosmicpro.cgi in Cosmicperl Directory Pro 2.0 allows remote attackers to gain sensitive information via a .. (dot… | Patch early | 5.0 medium | 7.5% | 2001-10-18 |
| CVE-2004-1206 EXP | Directory traversal vulnerability in codebrowserpntm.php in pnTresMailer 6.0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in t… | Patch early | 5.0 medium | 7.5% | 2005-01-10 |
| CVE-2012-0282 EXP | Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitra… | Patch early | 6.8 medium | 7.5% | 2012-07-17 |
| CVE-2007-1471 EXP | admin/default.asp in Orion-Blog 2.0 allows remote attackers to bypass authentication controls and gain privileges via a direct URL request for admin/A… | Patch early | 7.5 high | 7.4% | 2007-03-16 |
| CVE-2009-1391 EXP | Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly oth… | Patch early | 6.8 medium | 7.4% | 2009-06-16 |
| CVE-2005-0635 EXP | Buffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command. | Patch early | 10.0 high | 7.4% | 2005-05-02 |
| CVE-2007-3222 EXP | PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 7.4% | 2007-06-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt