CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,557 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
187,512 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2003-1431 EXP | Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via a long host string in th… | Patch early | 7.1 high | 5.2% | 2003-12-31 |
| CVE-2009-4581 EXP | Directory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers… | Patch early | 9.8 critical | 5.2% | 2010-01-06 |
| CVE-2006-0685 EXP | The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allo… | Patch early | 10.0 high | 5.2% | 2006-02-15 |
| CVE-2015-8664 EXP | Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 47.0.2526.106 allows remote att… | Patch early | 8.8 high | 5.2% | 2015-12-24 |
| CVE-2004-1466 EXP | The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds after they have been uploaded… | Patch early | 7.5 high | 5.2% | 2004-12-31 |
| CVE-2010-4879 EXP | PHP remote file inclusion vulnerability in dompdf.php in dompdf 0.6.0 beta1 allows remote attackers to execute arbitrary PHP code via a URL in the inp… | Patch early | 7.5 high | 5.2% | 2011-10-07 |
| CVE-2008-1866 EXP | admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload… | Patch early | 9.0 high | 5.2% | 2008-04-17 |
| CVE-2022-31325 EXP | There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php. | Patch early | 7.2 high | 5.2% | 2022-06-08 |
| CVE-1999-0765 EXP | SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor. | Patch early | 10.0 high | 5.2% | 1999-05-19 |
| CVE-2016-3962 EXP | Stack-based buffer overflow in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME… | Patch early | 7.3 high | 5.2% | 2016-07-03 |
| CVE-2017-6096 EXP | A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/view-list.php (Requires auth… | Patch early | 7.2 high | 5.2% | 2017-02-21 |
| CVE-2017-6097 EXP | A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign/count_of_send.php (Requir… | Patch early | 7.2 high | 5.2% | 2017-02-21 |
| CVE-2009-2361 EXP | SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the st… | Patch early | 7.5 high | 5.2% | 2009-07-08 |
| CVE-2021-40617 EXP | An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php. | Patch early | 9.8 critical | 5.2% | 2021-10-11 |
| CVE-2019-19031 EXP | Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS by consuming resources. The c… | Patch early | 8.1 high | 5.2% | 2019-12-30 |
| CVE-2018-18805 EXP | Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb. | Patch early | 9.8 critical | 5.2% | 2018-11-16 |
| CVE-2007-0681 EXP | profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, a… | Patch early | 9.8 critical | 5.2% | 2007-02-03 |
| CVE-2007-2821 EXP | SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitrary SQL commands via the cooki… | Patch early | 7.5 high | 5.2% | 2007-05-22 |
| CVE-2000-0741 EXP | Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code vi… | Patch early | 7.5 high | 5.2% | 2000-10-20 |
| CVE-2022-3141 EXP | The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the sett… | Patch early | 8.8 high | 5.2% | 2022-09-19 |
| CVE-2012-5879 EXP | An ActiveX control in McHealthCheck.dll in McAfee Virtual Technician (MVT) and ePO-MVT 6.5.0.2101 and earlier allows remote attackers to modify or cre… | Patch early | 8.2 high | 5.2% | 2013-03-28 |
| CVE-2016-1743 EXP | The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or… | Patch early | 7.8 high | 5.2% | 2016-03-24 |
| CVE-2008-0805 EXP | Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitrary code by uploading a file w… | Patch early | 9.3 high | 5.2% | 2008-02-19 |
| CVE-2007-6453 EXP | Directory traversal vulnerability in raidenhttpd-admin/workspace.php in RaidenHTTPD 2.0.19, when the WebAdmin function is enabled, allows remote attac… | Patch early | 10.0 high | 5.2% | 2007-12-20 |
| CVE-2006-5551 EXP | Stack-based buffer overflow in QK SMTP 3.01 and earlier might allow remote attackers to execute arbitrary code via a long argument to the RCPT TO comm… | Patch early | 7.5 high | 5.2% | 2006-10-26 |
| CVE-2007-2494 EXP | Multiple stack-based buffer overflows in the PowerPointOCX ActiveX control in PowerPointViewer.ocx 3.1.0.3 allow remote attackers to cause a denial of… | Patch early | 10.0 high | 5.2% | 2007-05-04 |
| CVE-2019-16383 EXP | MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attac… | Patch early | 9.4 critical | 5.2% | 2019-09-24 |
| CVE-2017-1000364 EXP | An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped"… | Patch early | 7.4 high | 5.2% | 2017-06-19 |
| CVE-2012-1663 EXP | Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (application crash) or possibly ha… | Patch early | 7.5 high | 5.2% | 2012-03-13 |
| CVE-2004-1883 EXP | Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code by causing a large error stri… | Patch early | 7.2 high | 5.2% | 2004-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt