CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,146 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
321,918 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-1611 EXP | Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 257 reply to a CWD comman… | Patch early | 10.0 high | 7.2% | 2009-05-11 |
| CVE-2002-0319 EXP | Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other… | Patch early | 7.5 high | 7.2% | 2002-06-25 |
| CVE-2002-1481 EXP | savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbi… | Patch early | 7.5 high | 7.2% | 2003-04-22 |
| CVE-2010-0388 EXP | Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a den… | Patch early | 7.5 high | 7.2% | 2010-01-25 |
| CVE-2006-3074 EXP | klif.sys in Kaspersky Internet Security 6.0 and 7.0, Kaspersky Anti-Virus (KAV) 6.0 and 7.0, KAV 6.0 for Windows Workstations, and KAV 6.0 for Windows… | Patch early | 5.0 medium | 7.2% | 2006-06-19 |
| CVE-2009-1357 EXP | CRLF injection vulnerability in da/DA/Login in Sun Java System Delegated Administrator 6.2 through 6.4 allows remote attackers to inject arbitrary HTT… | Patch early | 6.8 medium | 7.2% | 2009-04-23 |
| CVE-2009-1496 EXP | Directory traversal vulnerability in the Cmi Marketplace (com_cmimarketplace) component 0.1 for Joomla! allows remote attackers to list arbitrary dire… | Patch early | 5.0 medium | 7.2% | 2009-05-01 |
| CVE-2006-6797 EXP | The Client Server Run-Time Subsystem (CSRSS) in Microsoft Windows allows local users to cause a denial of service (crash) or read arbitrary memory fro… | Patch early | 6.6 medium | 7.2% | 2006-12-28 |
| CVE-2017-6087 EXP | EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the selected_events[] pa… | Patch early | 8.8 high | 7.2% | 2017-03-24 |
| CVE-2015-6402 EXP | Cross-site scripting (XSS) vulnerability in the management interface on Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allows remote attack… | Patch early | 4.3 medium | 7.2% | 2015-12-14 |
| CVE-2009-2257 EXP | The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to… | Patch early | 7.8 high | 7.2% | 2009-06-30 |
| CVE-2002-0451 EXP | filemanager_forms.php in PHProjekt 3.1 and 3.1a allows remote attackers to execute arbitrary PHP code by specifying the URL to the code in the lib_pat… | Patch early | 7.5 high | 7.2% | 2002-08-12 |
| CVE-2002-0959 EXP | Cross-site scripting vulnerability in Splatt Forum 3.0 allows remote attackers to execute arbitrary script as other users via an [img] tag with a clos… | Patch early | 7.5 high | 7.2% | 2002-10-04 |
| CVE-2002-1036 EXP | Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to execute web scrip… | Patch early | 7.5 high | 7.2% | 2002-10-04 |
| CVE-2000-0696 EXP | The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts,… | Patch early | 7.5 high | 7.2% | 2000-10-20 |
| CVE-2001-0987 EXP | Cross-site scripting vulnerability in CGIWrap before 3.7 allows remote attackers to execute arbitrary Javascript on other web clients by causing the J… | Patch early | 7.5 high | 7.2% | 2001-07-22 |
| CVE-2018-10258 EXP | A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be… | Patch early | 8.8 high | 7.2% | 2018-05-01 |
| CVE-2003-1239 EXP | Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in the album par… | Patch early | 5.0 medium | 7.2% | 2003-12-31 |
| CVE-2005-2577 EXP | Wyse Winterm 1125SE running firmware 4.2.09f or 4.4.061f allows remote attackers to cause a denial of service (device crash) via a packet with a zero… | Patch early | 5.0 medium | 7.2% | 2005-08-16 |
| CVE-2004-1678 EXP | Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary… | Patch early | 5.0 medium | 7.2% | 2004-09-13 |
| CVE-2004-1742 EXP | Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a .. (dot dot) in the viewcat parameter. | Patch early | 5.0 medium | 7.2% | 2004-08-24 |
| CVE-2006-1103 EXP | engine/server.cpp in Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (segmentation fault… | Patch early | 5.0 medium | 7.2% | 2006-03-09 |
| CVE-2003-1176 EXP | post_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or write to private forums by modif… | Patch early | 6.4 medium | 7.2% | 2003-12-31 |
| CVE-2010-4055 EXP | Stack consumption vulnerability in solid.exe in IBM solidDB 6.5.0.3 and earlier allows remote attackers to cause a denial of service (memory consumpti… | Patch early | 5.0 medium | 7.2% | 2010-10-23 |
| CVE-2010-4057 EXP | solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing ma… | Patch early | 5.0 medium | 7.2% | 2010-10-23 |
| CVE-2007-2856 EXP | Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used, allows u… | Patch early | 9.3 high | 7.2% | 2007-05-24 |
| CVE-2014-9350 EXP | TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attackers to cause a denial of servi… | Patch early | 5.0 medium | 7.2% | 2014-12-08 |
| CVE-2014-3418 EXP | config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the skipj… | Patch early | 10.0 high | 7.2% | 2014-07-15 |
| CVE-2012-4939 EXP | Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance… | Patch early | 4.3 medium | 7.2% | 2012-10-31 |
| CVE-2005-3893 EXP | Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attac… | Patch early | 7.5 high | 7.2% | 2005-11-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt