CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,746 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
403,746 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-4349 EXP | admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to obtain sensitive information via an invalid db_type parameter, which… | Patch early | 5.0 medium | 8.8% | 2011-01-03 |
| CVE-2008-2214 EXP | Stack-based buffer overflow in the Network Manager in Castle Rock Computing SNMPc 7.1 and earlier allows remote attackers to cause a denial of service… | Patch early | 10.0 high | 8.8% | 2008-05-14 |
| CVE-2010-1677 EXP | MHonArc 2.6.16 allows remote attackers to cause a denial of service (CPU consumption) via start tags that are placed within other start tags, as demon… | Patch early | 5.0 medium | 8.8% | 2011-01-03 |
| CVE-2017-8311 EXP | Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to e… | Patch early | 7.8 high | 8.8% | 2017-05-23 |
| CVE-2005-4385 EXP | Cross-site scripting (XSS) vulnerability in search.htm in Cofax 2.0 RC3 and earlier allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 8.8% | 2005-12-20 |
| CVE-2017-4914 EXP | VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote at… | Patch early | 9.8 critical | 8.8% | 2017-06-07 |
| CVE-2004-0375 EXP | SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall 5.01 and 5.1.1, and Client Sec… | Patch early | 5.0 medium | 8.8% | 2004-08-18 |
| CVE-2020-8615 EXP | A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing… | Patch early | 6.5 medium | 8.8% | 2020-02-04 |
| CVE-2007-6323 EXP | Multiple directory traversal vulnerabilities in MMS Gallery PHP 1.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parame… | Patch early | 5.0 medium | 8.8% | 2007-12-13 |
| CVE-2013-2267 EXP | PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system. | Patch early | 7.2 high | 8.8% | 2020-01-27 |
| CVE-2009-1201 EXP | Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances (ASA) device with sof… | Patch early | 4.3 medium | 8.8% | 2009-06-25 |
| CVE-2004-1259 EXP | Multiple buffer overflows in the handle_directive function in abcpp.c for abcpp 1.3.0 allow remote attackers to execute arbitrary code via crafted ABC… | Patch early | 10.0 high | 8.8% | 2005-01-10 |
| CVE-2004-1261 EXP | Multiple buffer overflows in the preparse function in asp2php 0.76.23 allow remote attackers to execute arbitrary code via crafted ASP scripts. | Patch early | 10.0 high | 8.8% | 2005-01-10 |
| CVE-2004-1298 EXP | Buffer overflow in the parse function in vb2c.c for vb2c 0.02 allows remote attackers to execute arbitrary code via a crafted FRM file. | Patch early | 10.0 high | 8.8% | 2005-01-10 |
| CVE-2004-0760 EXP | Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI. | Patch early | 6.4 medium | 8.8% | 2004-08-18 |
| CVE-2009-2534 EXP | RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allow remote attackers to cause a denial of service (daemon crash) via an RTSP SETUP r… | Patch early | 5.0 medium | 8.8% | 2009-07-20 |
| CVE-2007-3157 EXP | IPSecDrv.sys 10.4.0.12 in SafeNET High Assurance Remote 1.4.0 Build 12, and SoftRemote, allows remote attackers to cause a denial of service (infinite… | Patch early | 5.0 medium | 8.8% | 2007-06-11 |
| CVE-2026-27483 EXP | MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability in… | Patch early | 8.8 high | 8.8% | 2026-02-24 |
| CVE-2008-0953 EXP | The StartApp function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote att… | Patch early | 10.0 high | 8.8% | 2008-06-04 |
| CVE-2007-5610 EXP | The DeleteSingleFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows re… | Patch early | 10.0 high | 8.8% | 2008-06-04 |
| CVE-2017-8224 EXP | Wireless IP Camera (P2P) WIFICAM devices have a backdoor root account that can be accessed with TELNET. | Patch early | 9.8 critical | 8.8% | 2017-04-25 |
| CVE-2015-7112 EXP | The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code i… | Patch early | 9.3 high | 8.8% | 2015-12-11 |
| CVE-2006-4992 EXP | Multiple PHP remote file inclusion vulnerabilities in JD-WordPress for Joomla! (com_jd-wp) 2.0-1.0 RC2 allow remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 8.8% | 2006-09-26 |
| CVE-2004-2059 EXP | Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SearchFor par… | Patch early | 5.0 medium | 8.8% | 2004-12-31 |
| CVE-2006-7136 EXP | Multiple PHP remote file inclusion vulnerabilities in PHP Poll Creator (phpPC) 1.04 and earlier allow remote attackers to execute arbitrary PHP code v… | Patch early | 10.0 high | 8.8% | 2007-03-07 |
| CVE-2002-0288 EXP | Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP req… | Patch early | 5.0 medium | 8.8% | 2002-05-31 |
| CVE-2005-3640 EXP | Multiple buffer overflows in the IMAP Groupware Mail server of Floosietek FTGate (FTGate4) 4.1 allow remote attackers to execute arbitrary code via lo… | Patch early | 10.0 high | 8.8% | 2005-11-16 |
| CVE-2017-11456 EXP | Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configura… | Patch early | 7.5 high | 8.8% | 2017-07-19 |
| CVE-2009-1092 EXP | Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR systems allows remote attackers to… | Patch early | 9.3 high | 8.8% | 2009-03-25 |
| CVE-2014-9094 EXP | Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress… | Patch early | 4.3 medium | 8.8% | 2014-11-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt