CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,557 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
187,512 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-6098 EXP | A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign_save.php (Requires authen… | Patch early | 7.2 high | 5.2% | 2017-02-21 |
| CVE-2004-0300 EXP | SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat param… | Patch early | 10.0 high | 5.2% | 2004-11-23 |
| CVE-2013-7030 EXP | The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone… | Patch early | 7.3 high | 5.2% | 2013-12-12 |
| CVE-2010-4297 EXP | The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMware Player 2.5.x bef… | Patch early | 7.2 high | 5.2% | 2010-12-06 |
| CVE-2016-0007 EXP | The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2… | Patch early | 7.8 high | 5.2% | 2016-01-13 |
| CVE-2008-3239 EXP | Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP1, when register_globals is en… | Patch early | 9.3 high | 5.2% | 2008-07-21 |
| CVE-2008-4586 EXP | Insecure method vulnerability in the MVSNCLientWebAgent61.WebAgent.1 ActiveX control (isusweb.dll 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 al… | Patch early | 9.3 high | 5.2% | 2008-10-15 |
| CVE-2008-1247 EXP | The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts, which allows remote attackers… | Patch early | 10.0 high | 5.2% | 2008-03-10 |
| CVE-2006-7012 EXP | scart.cgi in SCart 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter of a show_text action. | Patch early | 10.0 high | 5.2% | 2007-02-15 |
| CVE-2021-37593 EXP | PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the… | Patch early | 9.1 critical | 5.2% | 2021-07-30 |
| CVE-2004-0238 EXP | Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME environment… | Patch early | 7.2 high | 5.2% | 2004-11-23 |
| CVE-1999-1190 EXP | Buffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long "From" header in an… | Patch early | 10.0 high | 5.2% | 1999-11-15 |
| CVE-2004-1405 EXP | MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows r… | Patch early | 7.5 high | 5.2% | 2004-12-31 |
| CVE-2016-4793 EXP | The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header. | Patch early | 7.5 high | 5.1% | 2017-01-23 |
| CVE-2010-2549 EXP | Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2 and Server 2008 Gold and SP2 allows local users to gain… | Patch early | 7.2 high | 5.1% | 2010-07-02 |
| CVE-2016-1803 EXP | CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in… | Patch early | 7.8 high | 5.1% | 2016-05-20 |
| CVE-2018-11525 EXP | The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection. | Patch early | 7.8 high | 5.1% | 2018-06-19 |
| CVE-2018-11526 EXP | The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection. | Patch early | 7.8 high | 5.1% | 2018-06-19 |
| CVE-2019-15092 EXP | The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, f… | Patch early | 7.3 high | 5.1% | 2019-08-23 |
| CVE-2009-0610 EXP | Multiple static code injection vulnerabilities in post.php in Simple PHP News 1.0 final allow remote attackers to inject arbitrary PHP code into news.… | Patch early | 7.5 high | 5.1% | 2009-02-17 |
| CVE-2017-2447 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.1 high | 5.1% | 2017-04-02 |
| CVE-2009-1087 EXP | Multiple argument injection vulnerabilities in PPLive.exe in PPLive 1.9.21 and earlier allow remote attackers to execute arbitrary code via a UNC shar… | Patch early | 9.3 high | 5.1% | 2009-03-25 |
| CVE-2002-0336 EXP | Buffer overflow in Galacticomm Worldgroup FTP server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbit… | Patch early | 7.5 high | 5.1% | 2002-06-25 |
| CVE-2009-0734 EXP | Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code via a long… | Patch early | 9.3 high | 5.1% | 2009-02-25 |
| CVE-2009-2375 EXP | Stack-based buffer overflow in Photo DVD Maker 8.02, and possibly earlier versions, allows remote attackers to execute arbitrary code via a long File_… | Patch early | 9.3 high | 5.1% | 2009-07-08 |
| CVE-2013-1744 EXP | IRIS citations management tool through 1.3 allows remote attackers to execute arbitrary commands. | Patch early | 9.8 critical | 5.1% | 2020-01-25 |
| CVE-2015-5889 EXP | rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving environment variables. | Patch early | 7.2 high | 5.1% | 2015-10-09 |
| CVE-2007-0888 EXP | Directory traversal vulnerability in the TFTP server in Kiwi CatTools before 3.2.0 beta allows remote attackers to read arbitrary files, and upload fi… | Patch early | 10.0 high | 5.1% | 2007-02-12 |
| CVE-2009-2766 EXP | httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remot… | Patch early | 7.5 high | 5.1% | 2009-08-14 |
| CVE-2006-4852 EXP | SQL injection vulnerability in browse.asp in QuadComm Q-Shop 3.5 allows remote attackers to execute arbitrary SQL commands via the OrderBy parameter. | Patch early | 7.5 high | 5.1% | 2006-09-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt