CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,734 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
403,734 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-1561 EXP | The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed i… | Patch early | 6.5 medium | 9.1% | 2015-07-14 |
| CVE-2017-15662 EXP | In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_… | Patch early | 7.5 high | 9.1% | 2018-01-10 |
| CVE-2017-15664 EXP | In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVE… | Patch early | 7.5 high | 9.1% | 2018-01-10 |
| CVE-2017-15665 EXP | In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET… | Patch early | 7.5 high | 9.1% | 2018-01-10 |
| CVE-2023-4174 EXP | A vulnerability has been found in mooSocial mooStore 3.1.6 and classified as problematic. Affected by this vulnerability is an unknown functionality.… | Patch early | 3.5 low | 9.1% | 2023-08-06 |
| CVE-2014-8997 EXP | Unrestricted file upload vulnerability in the Photo functionality in DigitalVidhya Digi Online Examination System 2.0 allows remote attackers to execu… | Patch early | 7.5 high | 9.1% | 2014-11-20 |
| CVE-2017-11120 EXP | On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor report frame to trigger an interna… | Patch early | 9.8 critical | 9.1% | 2017-09-28 |
| CVE-2010-3804 EXP | The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, use… | Patch early | 5.0 medium | 9.1% | 2010-11-22 |
| CVE-2008-5660 EXP | Format string vulnerability in the vinagre_utils_show_error function (src/vinagre-utils.c) in Vinagre 0.5.x before 0.5.2 and 2.x before 2.24.2 might a… | Patch early | 6.8 medium | 9.1% | 2008-12-17 |
| CVE-1999-0669 EXP | The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as de… | Patch early | 4.0 medium | 9.1% | 1999-09-01 |
| CVE-2018-5751 EXP | The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev2… | Patch early | 6.5 medium | 9.1% | 2018-06-16 |
| CVE-2017-13713 EXP | T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user parameter to cgi-bin/webupg. | Patch early | 8.8 high | 9.1% | 2017-09-07 |
| CVE-2006-2576 EXP | Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute ar… | Patch early | 5.1 medium | 9.1% | 2006-05-24 |
| CVE-2007-1397 EXP | Multiple stack-based buffer overflows in the (1) ExtractRnick and (2) decrypt_topic_332 functions in FiSH allow remote attackers to execute arbitrary… | Patch early | 10.0 high | 9.1% | 2007-03-10 |
| CVE-2008-7005 EXP | include/modules/top/1-random_quote.php in Minb Is Not a Blog (minb) 0.1.0 allows remote attackers to execute arbitrary PHP code via the quotes_to_edit… | Patch early | 7.5 high | 9.1% | 2009-08-19 |
| CVE-2004-1264 EXP | Buffer overflow in the simplify_path function in config.c for ChBg 1.5 allows remote attackers to execute arbitrary code via a crafted chbg scenario f… | Patch early | 10.0 high | 9.1% | 2005-01-10 |
| CVE-2004-1282 EXP | Buffer overflow in the strexpand function in string.c for LinPopUp 1.2.0 allows remote attackers to execute arbitrary code via a crafted message that… | Patch early | 10.0 high | 9.1% | 2005-01-10 |
| CVE-2004-1300 EXP | Buffer overflow in the open_aiff_file function in demux_aiff.c for xine-lib (libxine) 1-rc7 allows remote attackers to execute arbitrary code via a cr… | Patch early | 10.0 high | 9.1% | 2005-01-10 |
| CVE-2005-4211 EXP | PHP remote file inclusion vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in th… | Patch early | 7.5 high | 9.1% | 2005-12-14 |
| CVE-2015-3301 EXP | Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress b… | Patch early | 4.0 medium | 9.1% | 2015-05-14 |
| CVE-2013-4096 EXP | ServerAdmin/TestTelnetConnection.jsp in DS3 Authentication Server allows remote authenticated users to execute arbitrary commands via shell metacharac… | Patch early | 9.0 high | 9.1% | 2013-06-28 |
| CVE-2003-1396 EXP | Heap-based buffer overflow in Opera 6.05 through 7.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code… | Patch early | 6.8 medium | 9.1% | 2003-12-31 |
| CVE-2019-5788 EXP | An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allowed a remote attacker who had… | Patch early | 8.8 high | 9.1% | 2019-05-23 |
| CVE-1999-0041 EXP | Buffer overflow in NLS (Natural Language Service). | Patch early | 7.5 high | 9.1% | 1997-02-13 |
| CVE-2012-3414 EXP | Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1… | Patch early | 4.3 medium | 9.1% | 2013-07-19 |
| CVE-2009-0813 EXP | Insecure method vulnerability in the ImeraIEPlugin ActiveX control (ImeraIEPlugin.dll 1.0.2.54) in Imera TeamLinks Client allows remote attackers to f… | Patch early | 9.3 high | 9.1% | 2009-03-05 |
| CVE-2002-0813 EXP | Heap-based buffer overflow in the TFTP server capability in Cisco IOS 11.1, 11.2, and 11.3 allows remote attackers to cause a denial of service (reset… | Patch early | 7.1 high | 9.1% | 2002-08-12 |
| CVE-1999-0219 EXP | Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command. | Patch early | 7.8 high | 9.1% | 1997-07-01 |
| CVE-2007-6631 EXP | Multiple buffer overflows in LScube libnemesi 0.6.4-rc1 and earlier allow remote attackers to execute arbitrary code via (1) a reply that begins with… | Patch early | 7.5 high | 9.1% | 2008-01-04 |
| CVE-2009-4672 EXP | Directory traversal vulnerability in main.php in the WP-Lytebox plugin 1.3 for WordPress allows remote attackers to include and execute arbitrary loca… | Patch early | 7.5 high | 9.1% | 2010-03-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt