CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,370 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
322,112 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-4234 EXP | PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP co… | Patch early | 7.5 high | 6.4% | 2006-08-18 |
| CVE-2021-27520 EXP | A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter. | Patch early | 6.1 medium | 6.4% | 2021-03-19 |
| CVE-2009-3586 EXP | Off-by-one error in src/http.c in CoreHTTP 0.5.3.1 and earlier allows remote attackers to cause a denial of service or possibly execute arbitrary code… | Patch early | 7.5 high | 6.4% | 2009-12-08 |
| CVE-2002-2219 EXP | chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow file via a long user (userid) f… | Patch early | 7.5 high | 6.4% | 2002-12-31 |
| CVE-2009-4170 EXP | WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to w… | Patch early | 5.0 medium | 6.4% | 2009-12-02 |
| CVE-2003-1091 EXP | Integer overflow in MP3Broadcaster for Apple QuickTime/Darwin Streaming Server 4.1.3 allows remote attackers to cause a denial of service (crash) and… | Patch early | 7.5 high | 6.4% | 2003-12-31 |
| CVE-1999-0848 EXP | Denial of service in BIND named via consuming more than "fdmax" file descriptors. | Patch early | 5.0 medium | 6.4% | 1999-11-10 |
| CVE-2008-5667 EXP | The scanning engine in VirusBlokAda VBA32 Personal Antivirus 3.12.8.x allows remote attackers to cause a denial of service (memory corruption and appl… | Patch early | 5.0 medium | 6.4% | 2008-12-19 |
| CVE-2006-7052 EXP | Multiple PHP remote file inclusion vulnerabilities in DotWidget For Articles (dotwidgeta) 0.2 allow remote attackers to execute arbitrary code via a U… | Patch early | 10.0 high | 6.4% | 2007-02-24 |
| CVE-2015-0555 EXP | Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote attackers to execute arbitrar… | Patch early | 6.8 medium | 6.4% | 2015-02-24 |
| CVE-2018-4089 EXP | An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safari before 11.0.3 is affected.… | Patch early | 8.8 high | 6.4% | 2018-04-03 |
| CVE-2017-15643 EXP | An active network attacker (MiTM) can achieve remote code execution on a machine that runs IKARUS Anti Virus 2.16.7. IKARUS AV for Windows uses cleart… | Patch early | 7.4 high | 6.4% | 2017-10-19 |
| CVE-2009-0961 EXP | The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the call approval dialog when another… | Patch early | 5.0 medium | 6.4% | 2009-06-19 |
| CVE-2014-2921 EXP | The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 does not properly handle an objec… | Patch early | 7.5 high | 6.4% | 2014-04-21 |
| CVE-2025-14558 EXP | The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement messages; the option body is passe… | Patch early | 7.2 high | 6.4% | 2026-03-09 |
| CVE-2010-1217 EXP | Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attack… | Patch early | 4.3 medium | 6.4% | 2010-03-30 |
| CVE-2015-3300 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plug… | Patch early | 4.3 medium | 6.4% | 2015-05-14 |
| CVE-2018-10577 EXP | An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10.… | Patch early | 8.8 high | 6.4% | 2018-05-02 |
| CVE-2002-0375 EXP | Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript via a URL with the script in t… | Patch early | 5.0 medium | 6.4% | 2002-05-29 |
| CVE-2007-1851 EXP | Multiple directory traversal vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 allow remote attackers to include and execute arbitrary l… | Patch early | 7.5 high | 6.4% | 2007-04-03 |
| CVE-2023-36348 EXP | POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter. | Patch early | 8.8 high | 6.4% | 2023-06-23 |
| CVE-2011-5172 EXP | Stack-based buffer overflow in StoryBoard Quick 6 Build 3786, and possibly StoryBoard Artist and StoryBoard Studio, allows remote attackers to execute… | Patch early | 9.3 high | 6.4% | 2012-09-15 |
| CVE-2008-0632 EXP | Unrestricted file upload vulnerability in cp_upload_image.php in LightBlog 9.5 allows remote attackers to execute arbitrary code by uploading a file w… | Patch early | 9.3 high | 6.4% | 2008-02-06 |
| CVE-2012-0025 EXP | Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for Irfan… | Patch early | 6.8 medium | 6.4% | 2012-11-02 |
| CVE-2008-6955 EXP | mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configurati… | Patch early | 7.5 high | 6.4% | 2009-08-12 |
| CVE-2008-2338 EXP | Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified scripts i… | Patch early | 7.5 high | 6.4% | 2008-05-19 |
| CVE-2008-5897 EXP | CodeAvalanche FreeWallpaper stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa… | Patch early | 7.5 high | 6.4% | 2009-01-12 |
| CVE-2008-5898 EXP | CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download th… | Patch early | 7.5 high | 6.4% | 2009-01-12 |
| CVE-2008-5899 EXP | CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download t… | Patch early | 7.5 high | 6.4% | 2009-01-12 |
| CVE-2008-5900 EXP | CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… | Patch early | 7.5 high | 6.4% | 2009-01-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt