CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,367 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
322,109 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-0569 EXP | Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka Wi-Fi) driver for the Linux ker… | Patch early | 7.8 high | 6.5% | 2016-05-09 |
| CVE-2010-1748 EXP | The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before… | Patch early | 4.3 medium | 6.5% | 2010-06-17 |
| CVE-2003-0755 EXP | Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory names and list… | Patch early | 10.0 high | 6.5% | 2003-10-20 |
| CVE-2002-0968 EXP | Buffer overflow in AnalogX SimpleServer:WWW 1.16 and earlier allows remote attackers to cause a denial of service (crash) and execute code via a long… | Patch early | 7.5 high | 6.5% | 2002-10-04 |
| CVE-2019-2413 EXP | Vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware (subcomponent: Valid Session). The supported version that is affec… | Patch early | 6.1 medium | 6.5% | 2019-01-16 |
| CVE-2007-4328 EXP | Multiple PHP remote file inclusion vulnerabilities in Mapos Bilder Galerie 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the c… | Patch early | 6.8 medium | 6.5% | 2007-08-14 |
| CVE-2004-1559 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirec… | Patch early | 4.3 medium | 6.5% | 2004-12-31 |
| CVE-2008-3963 EXP | MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-… | Patch early | 4.0 medium | 6.5% | 2008-09-11 |
| CVE-2007-2791 EXP | Unspecified vulnerability in the Secure Shell (SSH) in HP Tru64 UNIX 5.1B-4 and 5.1B-3 allows remote attackers to identify valid users via unspecified… | Patch early | 10.0 high | 6.5% | 2007-05-22 |
| CVE-2008-3167 EXP | Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbitr… | Patch early | 9.3 high | 6.5% | 2008-07-14 |
| CVE-2013-1950 EXP | The svc_dg_getargs function in libtirpc 0.2.3 and earlier allows remote attackers to cause a denial of service (rpcbind crash) via a Sun RPC request w… | Patch early | 4.3 medium | 6.5% | 2013-07-09 |
| CVE-2006-4848 EXP | Multiple PHP remote file inclusion vulnerabilities in Brian Fraval Hitweb 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the RE… | Patch early | 7.5 high | 6.5% | 2006-09-19 |
| CVE-2009-3318 EXP | Directory traversal vulnerability in the Roland Breedveld Album (com_album) component 1.14 for Joomla! allows remote attackers to access arbitrary dir… | Patch early | 7.5 high | 6.5% | 2009-09-23 |
| CVE-2001-0383 EXP | banners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which does not requ… | Patch early | 5.0 medium | 6.5% | 2001-06-18 |
| CVE-2006-3015 EXP | Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double… | Patch early | 7.1 high | 6.5% | 2006-06-14 |
| CVE-2019-12137 EXP | Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note. | Patch early | 7.8 high | 6.5% | 2019-05-16 |
| CVE-2004-0683 EXP | Symantec Norton AntiVirus 2002 and 2003 allows remote attackers to cause a denial of service (CPU consumption) via a compressed archive that contains… | Patch early | 5.0 medium | 6.5% | 2004-08-06 |
| CVE-2004-1805 EXP | Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash) and possibly… | Patch early | 5.0 medium | 6.4% | 2004-12-31 |
| CVE-2011-0962 EXP | Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/com.cisco.nm.help.ServerHelpEngine in the Common Services Device Center in Cisco Unified Op… | Patch early | 4.3 medium | 6.4% | 2011-05-20 |
| CVE-2018-4366 EXP | A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1. | Patch early | 7.5 high | 6.4% | 2019-04-03 |
| CVE-2007-4256 EXP | Directory traversal vulnerability in showpage.cgi in YNP Portal System 2.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the… | Patch early | 5.0 medium | 6.4% | 2007-08-08 |
| CVE-2018-9106 EXP | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via… | Patch early | 8.8 high | 6.4% | 2018-03-28 |
| CVE-2016-6503 EXP | The CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platforms do not properly interact with Visual C++ compiler options, which al… | Patch early | 5.9 medium | 6.4% | 2016-08-06 |
| CVE-2009-1621 EXP | Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the route param… | Patch early | 5.0 medium | 6.4% | 2009-05-12 |
| CVE-2017-5227 EXP | QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format… | Patch early | 7.5 high | 6.4% | 2017-03-23 |
| CVE-2012-2997 EXP | XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 through 10.2.4 and 11.0.0 through 11.2.1 allows re… | Patch early | 4.0 medium | 6.4% | 2014-01-21 |
| CVE-2000-0482 EXP | Check Point Firewall-1 allows remote attackers to cause a denial of service by sending a large number of malformed fragmented IP packets. | Patch early | 5.0 medium | 6.4% | 2000-06-06 |
| CVE-2006-6558 EXP | Crob FTP Server 3.6.1 b.263 allows remote attackers to cause a denial of service via a long series of "?A" sequences in the (1) LIST and possibly (2)… | Patch early | 5.0 medium | 6.4% | 2006-12-14 |
| CVE-2009-3272 EXP | Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2, allows remote attackers to ca… | Patch early | 5.0 medium | 6.4% | 2009-09-21 |
| CVE-2020-27423 EXP | Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legiti… | Patch early | 7.5 high | 6.4% | 2020-11-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt