CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,322 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
322,063 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-7006 EXP | Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backup… | Patch early | 5.0 medium | 6.6% | 2009-08-19 |
| CVE-2008-2419 EXP | Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary co… | Patch early | 4.3 medium | 6.6% | 2008-05-23 |
| CVE-2013-4861 EXP | Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated users to read a… | Patch early | 6.5 medium | 6.6% | 2020-01-28 |
| CVE-2015-8358 EXP | Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execute arbitrar… | Patch early | 9.0 high | 6.6% | 2015-12-16 |
| CVE-2009-0659 EXP | Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 allows remote attackers to have an unknown impact via a STATS line with a… | Patch early | 5.0 medium | 6.6% | 2009-02-20 |
| CVE-2014-9597 EXP | The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause… | Patch early | 6.8 medium | 6.6% | 2015-01-21 |
| CVE-1999-1082 EXP | Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "......" (modified dot dot) att… | Patch early | 5.0 medium | 6.6% | 1999-10-08 |
| CVE-2018-19136 EXP | DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter. | Patch early | 6.1 medium | 6.6% | 2018-11-09 |
| CVE-2010-2246 EXP | feh before 1.8, when the --wget-timestamp option is enabled, might allow remote attackers to execute arbitrary commands via shell metacharacters in a… | Patch early | 5.1 medium | 6.6% | 2011-05-26 |
| CVE-2006-4827 EXP | Multiple PHP remote file inclusion vulnerabilities in Vmist Downstat 1.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 5.1 medium | 6.6% | 2006-09-15 |
| CVE-2010-2102 EXP | Buffer overflow in Webby Webserver 1.01 allows remote attackers to execute arbitrary code via a long HTTP GET request. | Patch early | 10.0 high | 6.6% | 2010-05-27 |
| CVE-2008-2382 EXP | The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to ca… | Patch early | 5.0 medium | 6.6% | 2008-12-24 |
| CVE-2017-16787 EXP | The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read arbitrary files by leveraging… | Patch early | 6.5 medium | 6.6% | 2017-12-15 |
| CVE-2007-1522 EXP | Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal cha… | Patch early | 6.8 medium | 6.6% | 2007-03-20 |
| CVE-2015-2071 EXP | Directory traversal vulnerability in cm/newui/blog/export.jsp in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote authenticated users to r… | Patch early | 4.0 medium | 6.6% | 2015-02-24 |
| CVE-2002-0588 EXP | PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters t… | Patch early | 5.0 medium | 6.6% | 2002-06-18 |
| CVE-2002-1422 EXP | admbrowse.php in FUDforum before 2.2.0 allows remote attackers to create or delete files via URL-encoded pathnames in the cur and dest parameters. | Patch early | 5.0 medium | 6.6% | 2003-04-11 |
| CVE-2002-1429 EXP | Cross-site scripting vulnerability in board.php of endity.com ShoutBOX allows remote attackers to inject arbitrary HTML into the shoutbox page via the… | Patch early | 5.0 medium | 6.6% | 2003-04-11 |
| CVE-2022-48197 EXP | Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, TreeView component and the YUI Jav… | Patch early | 6.1 medium | 6.6% | 2023-01-02 |
| CVE-2021-25160 EXP | A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x… | Patch early | 4.9 medium | 6.6% | 2021-03-30 |
| CVE-2007-0344 EXP | Multiple format string vulnerabilities in (1) _invitedToRoom: and (2) _invitedToDirectChat: in Colloquy 2.1 and earlier allow remote attackers to caus… | Patch early | 7.5 high | 6.6% | 2007-01-18 |
| CVE-2016-1595 EXP | LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to con… | Patch early | 6.5 medium | 6.6% | 2016-04-22 |
| CVE-2014-0999 EXP | Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and hijack sessio… | Patch early | 5.0 medium | 6.6% | 2015-06-02 |
| CVE-2017-11332 EXP | The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and applicat… | Patch early | 5.5 medium | 6.6% | 2017-07-31 |
| CVE-2017-11359 EXP | The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and applic… | Patch early | 5.5 medium | 6.6% | 2017-07-31 |
| CVE-2008-3322 EXP | admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrar… | Patch early | 7.5 high | 6.6% | 2008-07-25 |
| CVE-2006-5762 EXP | PHP remote file inclusion vulnerability in forgot_pass.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 5.1 medium | 6.6% | 2006-11-06 |
| CVE-2016-6504 EXP | epan/dissectors/packet-ncp2222.inc in the NDS dissector in Wireshark 1.12.x before 1.12.13 does not properly maintain a ptvc data structure, which all… | Patch early | 5.9 medium | 6.6% | 2016-08-06 |
| CVE-2009-3041 EXP | SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allo… | Patch early | 7.5 high | 6.6% | 2009-09-01 |
| CVE-2009-4089 EXP | telepark.wiki 2.4.23 and earlier allows remote attackers to bypass authorization and (1) delete arbitrary pages via a modified pageID parameter to aja… | Patch early | 5.0 medium | 6.6% | 2009-11-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt