CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,355 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
322,095 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-1784 EXP | Buffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long HTTP GET request. | Patch early | 7.5 high | 6.5% | 2004-01-03 |
| CVE-2004-1945 EXP | Buffer overflow in Kinesphere eXchange POP3 allows remote attackers to execute arbitrary code via a long MAIL FROM field. | Patch early | 7.5 high | 6.5% | 2004-04-20 |
| CVE-2001-0210 EXP | Directory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the page pa… | Patch early | 5.0 medium | 6.5% | 2001-06-02 |
| CVE-2001-0211 EXP | Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform paramet… | Patch early | 5.0 medium | 6.5% | 2001-06-02 |
| CVE-2005-2262 EXP | Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper"… | Patch early | 5.1 medium | 6.5% | 2005-07-13 |
| CVE-2008-7053 EXP | LogMeIn Remote Access Utility ActiveX control (RACtrl.dll) allows remote attackers to cause a denial of service (crash) by setting the fgcolor and bgc… | Patch early | 9.3 high | 6.5% | 2009-08-24 |
| CVE-2007-2585 EXP | Stack-based buffer overflow in the Verify function in the BarCodeWiz ActiveX control 2.0 and 2.52 (BarcodeWiz.dll) allows remote attackers to execute… | Patch early | 9.3 high | 6.5% | 2007-05-10 |
| CVE-2017-9122 EXP | The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumpti… | Patch early | 6.5 medium | 6.5% | 2017-06-12 |
| CVE-2009-0886 EXP | Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via a .. (dot… | Patch early | 5.0 medium | 6.5% | 2009-03-12 |
| CVE-2007-6290 EXP | Multiple directory traversal vulnerabilities in js/get_js.php in SERWeb 2.0.0 dev1 and earlier allow remote attackers to read arbitrary files via a ..… | Patch early | 5.0 medium | 6.5% | 2007-12-10 |
| CVE-2004-2130 EXP | Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbitrary script or HTML via the (… | Patch early | 4.3 medium | 6.5% | 2004-12-23 |
| CVE-2014-8770 EXP | Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a and earlier for Magento Communit… | Patch early | 9.0 high | 6.5% | 2014-11-13 |
| CVE-2017-7005 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. Th… | Patch early | 8.8 high | 6.5% | 2018-04-03 |
| CVE-2013-5673 EXP | SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attackers to execute arbitrary SQL c… | Patch early | 7.5 high | 6.5% | 2013-09-10 |
| CVE-2000-0484 EXP | Small HTTP Server ver 3.06 contains a memory corruption bug causing a memory overflow. The overflowed buffer crashes into a Structured Exception Handl… | Patch early | 5.0 medium | 6.5% | 2000-06-15 |
| CVE-2006-4828 EXP | PHP remote file inclusion vulnerability in zipndownload.php in PhotoPost 4.0 through 4.6 allows remote attackers to execute arbitrary PHP code via a U… | Patch early | 7.5 high | 6.5% | 2006-09-15 |
| CVE-2009-4186 EXP | Stack consumption vulnerability in Apple Safari 4.0.3 on Windows allows remote attackers to cause a denial of service (application crash) via a long U… | Patch early | 9.3 high | 6.5% | 2009-12-03 |
| CVE-2007-2940 EXP | Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary PHP code via a URL in the pacht… | Patch early | 6.8 medium | 6.5% | 2007-05-31 |
| CVE-2001-1009 EXP | Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibl… | Patch early | 10.0 high | 6.5% | 2001-08-31 |
| CVE-2008-6763 EXP | login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged… | Patch early | 7.5 high | 6.5% | 2009-04-28 |
| CVE-2009-1234 EXP | Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a long series of start-tags with no… | Patch early | 4.3 medium | 6.5% | 2009-04-02 |
| CVE-2012-0067 EXP | wiretap/iptrace.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via… | Patch early | 4.3 medium | 6.5% | 2012-04-11 |
| CVE-2006-3355 EXP | Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not pro… | Patch early | 7.5 high | 6.5% | 2006-07-06 |
| CVE-2018-8718 EXP | Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mai… | Patch early | 8.0 high | 6.5% | 2018-03-27 |
| CVE-2008-3320 EXP | admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbit… | Patch early | 7.5 high | 6.5% | 2008-07-25 |
| CVE-2013-7136 EXP | The UPC Ireland Cisco EPC 2425 router (aka Horizon Box) does not have a sufficiently large number of possible WPA-PSK passphrases, which makes it easi… | Patch early | 9.3 high | 6.5% | 2013-12-19 |
| CVE-2010-2375 EXP | Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware… | Patch early | 6.4 medium | 6.5% | 2010-07-13 |
| CVE-2006-0586 EXP | Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arbitrary SQL commands via multip… | Patch early | 7.5 high | 6.5% | 2006-02-08 |
| CVE-2009-2015 EXP | Directory traversal vulnerability in includes/file_includer.php in the Ideal MooFAQ (com_moofaq) component 1.0 for Joomla! allows remote attackers to… | Patch early | 7.5 high | 6.5% | 2009-06-09 |
| CVE-2012-5318 EXP | Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin 1.2 for WordPress allows remote attackers t… | Patch early | 6.8 medium | 6.5% | 2012-10-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt