CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,237 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
321,944 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-0658 EXP | Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload an… | Patch early | 5.0 medium | 6.9% | 2006-02-13 |
| CVE-1999-0174 EXP | The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 6.4 medium | 6.9% | 1997-02-01 |
| CVE-2011-2201 EXP | The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of d… | Patch early | 4.3 medium | 6.9% | 2011-09-14 |
| CVE-2016-8017 EXP | Special element injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers… | Patch early | 4.1 medium | 6.9% | 2017-03-14 |
| CVE-2014-9436 EXP | Absolute path traversal vulnerability in SysAid On-Premise before 14.4.2 allows remote attackers to read arbitrary files via a \\\\ (four backslashes)… | Patch early | 5.0 medium | 6.9% | 2015-01-02 |
| CVE-2014-3975 EXP | Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via a full pathname in the viewdir… | Patch early | 5.0 medium | 6.9% | 2014-06-05 |
| CVE-2008-6280 EXP | Cross-site scripting (XSS) vulnerability in apply.cgi on the Linksys WRT160N allows remote attackers to inject arbitrary web script or HTML via the ac… | Patch early | 4.3 medium | 6.9% | 2009-02-25 |
| CVE-2003-1240 EXP | PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in… | Patch early | 7.5 high | 6.9% | 2003-12-31 |
| CVE-2012-0550 EXP | Unspecified vulnerability in the GlassFish Enterprise Server component in Oracle Sun Products Suite GlassFish Enterprise Server 3.1.1 allows remote at… | Patch early | 6.8 medium | 6.9% | 2012-05-03 |
| CVE-2019-8624 EXP | An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5.3. A remote attacker may be able to leak memory. | Patch early | 7.5 high | 6.9% | 2019-12-18 |
| CVE-2008-4048 EXP | Heap-based buffer overflow in a certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remot… | Patch early | 6.8 medium | 6.9% | 2008-09-11 |
| CVE-2008-4729 EXP | Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Control 13.0 and earlier allows re… | Patch early | 6.8 medium | 6.9% | 2008-10-24 |
| CVE-2015-7248 EXP | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password hashes by reading the cgi-bin/we… | Patch early | 7.5 high | 6.9% | 2015-12-30 |
| CVE-2009-0812 EXP | Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions allows remote attackers to execut… | Patch early | 9.3 high | 6.9% | 2009-03-04 |
| CVE-2009-3812 EXP | Heap-based buffer overflow in OtsAV DJ trial version 1.85.64.0, Radio trial version 1.85.64.0, TV trial version 1.85.64.0, and Free version 1.77.001 a… | Patch early | 9.3 high | 6.9% | 2009-10-27 |
| CVE-2010-2932 EXP | Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary code via a long argument to t… | Patch early | 9.3 high | 6.9% | 2010-08-05 |
| CVE-2013-2642 EXP | Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to t… | Patch early | 9.3 high | 6.9% | 2014-03-18 |
| CVE-2010-0315 EXP | WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a sp… | Patch early | 5.0 medium | 6.9% | 2010-01-14 |
| CVE-2018-6064 EXP | Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploi… | Patch early | 8.8 high | 6.9% | 2018-11-14 |
| CVE-2006-4858 EXP | PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier component for Mambo allows remo… | Patch early | 6.8 medium | 6.9% | 2006-09-19 |
| CVE-2010-0166 EXP | The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when t… | Patch early | 5.1 medium | 6.9% | 2010-03-25 |
| CVE-2013-4093 EXP | The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to obtain sensitive information vi… | Patch early | 5.0 medium | 6.9% | 2013-06-28 |
| CVE-2005-0731 EXP | PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to Fi… | Patch early | 5.0 medium | 6.9% | 2005-03-10 |
| CVE-2002-0098 EXP | Buffer overflow in index.cgi administration interface for Boozt! Standard 0.9.8 allows local users to execute arbitrary code via a long name field whe… | Patch early | 7.5 high | 6.9% | 2002-03-25 |
| CVE-2004-1381 EXP | Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported… | Patch early | 5.0 medium | 6.9% | 2004-10-20 |
| CVE-2003-0766 EXP | Multiple heap-based buffer overflows in FTP Desktop client 3.5, and possibly earlier versions, allow remote malicious servers to execute arbitrary cod… | Patch early | 7.5 high | 6.9% | 2003-09-17 |
| CVE-2014-8604 EXP | The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which a… | Patch early | 5.0 medium | 6.9% | 2015-06-10 |
| CVE-2014-8605 EXP | The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient… | Patch early | 5.0 medium | 6.9% | 2015-06-10 |
| CVE-2016-5309 EXP | The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud;… | Patch early | 5.5 medium | 6.9% | 2017-04-14 |
| CVE-2016-0075 EXP | The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain p… | Patch early | 5.5 medium | 6.9% | 2016-10-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt