CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,587 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
169,049 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-3605 EXP | Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Transition property on an uninitialized DXIm… | Patch early | 5.0 medium | 24.3% | 2006-07-18 |
| CVE-2006-3898 EXP | Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the Click method… | Patch early | 5.0 medium | 24.3% | 2006-07-27 |
| CVE-2006-3512 EXP | Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) by setting the Enabled property of a DXTFilter ActiveX… | Patch early | 5.0 medium | 24.3% | 2006-07-11 |
| CVE-2006-3427 EXP | Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL attribute on an uninitialized Di… | Patch early | 5.0 medium | 24.3% | 2006-07-07 |
| CVE-2002-1700 EXP | Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary scri… | Patch early | 4.3 medium | 24.3% | 2002-12-31 |
| CVE-2016-5725 EXP | Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write… | Patch early | 5.9 medium | 24.1% | 2017-01-19 |
| CVE-2006-3101 EXP | Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 24% | 2006-06-21 |
| CVE-2012-5611 EXP | Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.… | Patch early | 6.5 medium | 24% | 2012-12-03 |
| CVE-2020-9467 EXP | Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function. | Patch early | 5.4 medium | 23.8% | 2020-03-26 |
| CVE-2001-0205 EXP | Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by inserting "..." into the requested p… | Patch early | 5.0 medium | 23.6% | 2001-05-03 |
| CVE-2008-1126 EXP | PHP remote file inclusion vulnerability in main.php in Barryvan Compo Manager 0.3 allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 6.8 medium | 23.6% | 2008-03-03 |
| CVE-2013-3585 EXP | Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information v… | Patch early | 5.0 medium | 23.5% | 2013-08-28 |
| CVE-2010-4476 EXP | The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and ear… | Patch early | 5.0 medium | 23.5% | 2011-02-17 |
| CVE-2008-0566 EXP | PHP remote file inclusion vulnerability in includes/smarty.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary… | Patch early | 6.8 medium | 23.5% | 2008-02-05 |
| CVE-2018-8533 EXP | An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a refere… | Patch early | 5.5 medium | 23.4% | 2018-10-10 |
| CVE-2018-8532 EXP | An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a refere… | Patch early | 5.5 medium | 23.4% | 2018-10-10 |
| CVE-2018-8527 EXP | An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a referen… | Patch early | 5.5 medium | 23.4% | 2018-10-10 |
| CVE-2005-0452 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or… | Patch early | 4.3 medium | 23.4% | 2005-02-16 |
| CVE-2011-4106 EXP | TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute… | Patch early | 6.8 medium | 23.3% | 2013-10-26 |
| CVE-2006-3897 EXP | Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating a… | Patch early | 5.0 medium | 23.3% | 2006-07-27 |
| CVE-2003-0002 EXP | Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to exec… | Patch early | 6.8 medium | 23.3% | 2003-02-07 |
| CVE-2013-5528 EXP | Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users… | Patch early | 4.0 medium | 23.3% | 2013-10-11 |
| CVE-1999-0980 EXP | Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration reque… | Patch early | 5.0 medium | 23.2% | 2000-05-16 |
| CVE-2008-0503 EXP | Eval injection vulnerability in admin/op/disp.php in Netwerk Smart Publisher 1.0.1 allows remote attackers to execute arbitrary PHP code via the filed… | Patch early | 6.8 medium | 23.2% | 2008-01-31 |
| CVE-2009-1287 EXP | Cross-site scripting (XSS) vulnerability in Cisco Subscriber Edge Services Manager (SESM) allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 23.1% | 2009-04-13 |
| CVE-2006-2094 EXP | Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, u… | Patch early | 5.1 medium | 23.1% | 2006-04-29 |
| CVE-2011-2007 EXP | Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service ou… | Patch early | 5.0 medium | 23% | 2011-10-12 |
| CVE-2003-0446 EXP | Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote atta… | Patch early | 4.3 medium | 23% | 2003-07-24 |
| CVE-2021-44848 EXP | In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the us… | Patch early | 5.3 medium | 23% | 2021-12-13 |
| CVE-2017-0118 EXP | Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT… | Patch early | 4.3 medium | 23% | 2017-03-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt