CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,069 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
321,842 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-5495 EXP | Multiple PHP remote file inclusion vulnerabilities in Trawler Web CMS 1.8.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 7.4% | 2006-10-25 |
| CVE-2006-2531 EXP | Ipswitch WhatsUp Professional 2006 only verifies the user's identity via HTTP headers, which allows remote attackers to spoof being a trusted console… | Patch early | 7.5 high | 7.4% | 2006-05-22 |
| CVE-2014-5300 EXP | Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 allows remote attackers to bypass the signature check, impersonate arbitrary users, and execut… | Patch early | 5.0 medium | 7.4% | 2014-10-08 |
| CVE-2008-1054 EXP | Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlier, and b… | Patch early | 6.4 medium | 7.4% | 2008-02-27 |
| CVE-2000-0204 EXP | The Trend Micro OfficeScan client allows remote attackers to cause a denial of service by making 5 connections to port 12345, which raises CPU utiliza… | Patch early | 5.0 medium | 7.4% | 2000-02-28 |
| CVE-2003-0510 EXP | Format string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command. | Patch early | 7.5 high | 7.4% | 2003-08-07 |
| CVE-2004-2124 EXP | The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a… | Patch early | 5.0 medium | 7.4% | 2004-12-31 |
| CVE-2007-0613 EXP | The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does not check for duplicate entrie… | Patch early | 5.0 medium | 7.4% | 2007-01-31 |
| CVE-2014-9619 EXP | Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x befo… | Patch early | 7.2 high | 7.4% | 2017-09-19 |
| CVE-2012-4357 EXP | Array index error in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 might allow remote attackers to execute arbit… | Patch early | 9.3 high | 7.4% | 2012-08-19 |
| CVE-2008-5904 EXP | The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via inpu… | Patch early | 7.5 high | 7.4% | 2009-01-15 |
| CVE-2021-43579 EXP | A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linkin… | Patch early | 7.8 high | 7.3% | 2022-01-10 |
| CVE-2016-1839 EXP | The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2… | Patch early | 5.5 medium | 7.3% | 2016-05-20 |
| CVE-2019-13237 EXP | In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resource… | Patch early | 4.3 medium | 7.3% | 2019-08-27 |
| CVE-2004-1554 EXP | PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by modifying the… | Patch early | 7.5 high | 7.3% | 2004-12-31 |
| CVE-2010-2809 EXP | The default configuration of the <Button2> binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assist… | Patch early | 6.8 medium | 7.3% | 2010-08-19 |
| CVE-2008-5280 EXP | The Local ZIM Server in Zilab Chat and Instant Messaging (ZIM) Server 2.0 and 2.1 allows remote attackers to cause a denial of service (NULL pointer d… | Patch early | 5.0 medium | 7.3% | 2008-11-29 |
| CVE-2008-1278 EXP | The RemotelyAnywhere.exe service in the Remotely Anywhere Server and Workstation 8.0.668 and earlier allows remote attackers to cause a denial of serv… | Patch early | 5.0 medium | 7.3% | 2008-03-10 |
| CVE-2000-0766 EXP | Buffer overflow in vqSoft vqServer 1.4.49 allows remote attackers to cause a denial of service or possibly gain privileges via a long HTTP GET request… | Patch early | 7.5 high | 7.3% | 2000-10-20 |
| CVE-2000-0400 EXP | The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to do… | Patch early | 7.5 high | 7.3% | 2000-05-13 |
| CVE-2008-1218 EXP | Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to byp… | Patch early | 6.8 medium | 7.3% | 2008-03-10 |
| CVE-2011-4800 EXP | Directory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and write arbitrary files, and list a… | Patch early | 9.0 high | 7.3% | 2011-12-14 |
| CVE-2001-1195 EXP | Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager, which allows remote attackers… | Patch early | 7.5 high | 7.3% | 2001-12-15 |
| CVE-2007-3151 EXP | rpttop.htm in the web management interface in Packeteer PacketShaper 7.3.0g2 and 7.5.0g1 allows remote attackers to cause a denial of service (device… | Patch early | 5.0 medium | 7.3% | 2007-06-11 |
| CVE-2004-0605 EXP | Non-registered IRC users using (1) ircd-hybrid 7.0.1 and earlier, (2) ircd-ratbox 1.5.1 and earlier, or (3) ircd-ratbox 2.0rc6 and earlier do not have… | Patch early | 5.0 medium | 7.3% | 2004-12-06 |
| CVE-2013-1594 EXP | An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wireless keys and 3rd party creden… | Patch early | 7.5 high | 7.3% | 2020-01-24 |
| CVE-2005-3811 EXP | Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to overwrite arb… | Patch early | 5.0 medium | 7.3% | 2005-11-25 |
| CVE-2002-0300 EXP | gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly re… | Patch early | 5.0 medium | 7.3% | 2002-05-31 |
| CVE-2009-1627 EXP | Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbitrary code via a long .asf URL… | Patch early | 9.3 high | 7.3% | 2009-05-12 |
| CVE-2005-4086 EXP | Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier all… | Patch early | 5.0 medium | 7.3% | 2005-12-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt