CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,247 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
321,999 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-6105 EXP | Multiple PHP remote file inclusion vulnerabilities in TalkBack 2.2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) languag… | Patch early | 6.8 medium | 6.7% | 2007-11-23 |
| CVE-2015-4668 EXP | Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attack… | Patch early | 6.1 medium | 6.7% | 2017-09-25 |
| CVE-2008-2898 EXP | Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and execute arbitrary local files via… | Patch early | 9.3 high | 6.7% | 2008-06-27 |
| CVE-2017-13794 EXP | An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… | Patch early | 8.8 high | 6.7% | 2017-11-13 |
| CVE-2015-7257 EXP | ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin pa… | Patch early | 7.5 high | 6.7% | 2017-08-24 |
| CVE-2004-1752 EXP | Stack-based buffer overflow in Gaucho 1.4 Build 145 allows remote attackers to execute arbitrary code via a POP3 email with a long Content-Type header… | Patch early | 7.5 high | 6.7% | 2004-08-24 |
| CVE-2004-1868 EXP | Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag. | Patch early | 7.5 high | 6.7% | 2004-03-25 |
| CVE-2009-4654 EXP | Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to execute arbitrary code v… | Patch early | 9.0 high | 6.7% | 2010-02-26 |
| CVE-2013-6234 EXP | Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by… | Patch early | 8.0 high | 6.7% | 2019-11-22 |
| CVE-2018-7706 EXP | Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via a ..… | Patch early | 6.5 medium | 6.7% | 2018-03-15 |
| CVE-2001-0206 EXP | Directory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by inserting a .. (dot dot) or ... into… | Patch early | 5.0 medium | 6.7% | 2001-06-02 |
| CVE-2015-6996 EXP | IOAcceleratorFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code or cause a denia… | Patch early | 6.8 medium | 6.7% | 2015-10-23 |
| CVE-2007-1446 EXP | Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1beta allow remote attackers to execute arbitrary PHP code via a U… | Patch early | 7.5 high | 6.7% | 2007-03-14 |
| CVE-2006-6445 EXP | Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files vi… | Patch early | 7.5 high | 6.7% | 2006-12-10 |
| CVE-2008-6843 EXP | Directory traversal vulnerability in index.php in Fantastico, as used with cPanel 11.x, allows remote attackers to read arbitrary files via a .. (dot… | Patch early | 5.0 medium | 6.7% | 2009-07-02 |
| CVE-2015-1560 EXP | SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (… | Patch early | 7.5 high | 6.7% | 2015-07-14 |
| CVE-2002-2190 EXP | ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords v… | Patch early | 7.5 high | 6.7% | 2002-12-31 |
| CVE-2018-6889 EXP | An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the w… | Patch early | 8.8 high | 6.7% | 2018-02-12 |
| CVE-2009-2258 EXP | Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attac… | Patch early | 7.8 high | 6.7% | 2009-06-30 |
| CVE-2007-1718 EXP | CRLF injection vulnerability in the mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows remote attackers to inject arbitrary e-mai… | Patch early | 7.8 high | 6.7% | 2007-03-28 |
| CVE-2010-2006 EXP | Directory traversal vulnerability in op/op.Login.php in LetoDMS (formerly MyDMS) 1.7.2 and earlier allows remote authenticated users to include and ex… | Patch early | 6.5 medium | 6.7% | 2010-05-20 |
| CVE-2019-8663 EXP | This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6. A remote attacker may be able to leak memory. | Patch early | 5.3 medium | 6.7% | 2019-12-18 |
| CVE-2007-5636 EXP | Buffer overflow in the Nortel UNIStim IP Softphone 2050 allows remote attackers to cause a denial of service (application abort) and possibly execute… | Patch early | 7.5 high | 6.7% | 2007-10-23 |
| CVE-2002-2295 EXP | Buffer overflow in Pico Server (pServ) 2.0 beta 1 through beta 5 allows remote attackers to cause a denial of service (crash) and possibly execute arb… | Patch early | 7.5 high | 6.7% | 2002-12-31 |
| CVE-2002-1986 EXP | Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP request with a trailing dot ("."). | Patch early | 5.0 medium | 6.7% | 2002-12-31 |
| CVE-2004-2385 EXP | EMU Webmail 5.2.7 allows remote attackers to obtain sensitive path information (home directory) via an HTTP request for init.emu. | Patch early | 5.0 medium | 6.7% | 2004-12-31 |
| CVE-2006-0700 EXP | imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists f… | Patch early | 5.0 medium | 6.7% | 2006-02-15 |
| CVE-2017-6191 EXP | Buffer overflow in APNGDis 2.8 and below allows a remote attacker to execute arbitrary code via a crafted filename. | Patch early | 7.8 high | 6.7% | 2017-03-23 |
| CVE-2014-3008 EXP | Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm parameter to re… | Patch early | 10.0 high | 6.7% | 2014-04-28 |
| CVE-2007-2005 EXP | Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary P… | Patch early | 6.8 medium | 6.7% | 2007-04-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt