CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,733 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
169,103 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-0448 EXP | Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many "C:/" sequ… | Patch early | 5.0 medium | 14.9% | 2002-07-26 |
| CVE-2008-0782 EXP | Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the MOIN_ID… | Patch early | 5.0 medium | 14.9% | 2008-02-14 |
| CVE-2006-3193 EXP | Multiple PHP remote file inclusion vulnerabilities in Grayscale BandSite CMS 1.1.1, when register_globals is enabled, allow remote attackers to execut… | Patch early | 5.1 medium | 14.8% | 2006-06-23 |
| CVE-2020-8512 EXP | In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter. | Patch early | 6.1 medium | 14.8% | 2020-02-01 |
| CVE-1999-0819 EXP | NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it. | Patch early | 5.0 medium | 14.8% | 1999-12-01 |
| CVE-2007-0464 EXP | The _CFNetConnectionWillEnqueueRequests function in CFNetwork 129.19 on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial… | Patch early | 5.0 medium | 14.8% | 2007-01-30 |
| CVE-2007-4288 EXP | Microsoft Windows Media Player 11 (wmplayer.exe) allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted… | Patch early | 4.3 medium | 14.8% | 2007-08-09 |
| CVE-2012-5615 EXP | Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different err… | Patch early | 5.0 medium | 14.8% | 2012-12-03 |
| CVE-2013-5962 EXP | Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows r… | Patch early | 5.1 medium | 14.8% | 2013-09-30 |
| CVE-2014-8791 EXP | project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object in… | Patch early | 6.0 medium | 14.8% | 2014-12-02 |
| CVE-1999-0294 EXP | All records in a WINS database can be deleted through SNMP for a denial of service. | Patch early | 5.0 medium | 14.7% | 1997-10-01 |
| CVE-2011-1511 EXP | Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Products Suite 2.1.1 and 3.0.1 allows remote attackers to execute arb… | Patch early | 6.4 medium | 14.6% | 2011-07-20 |
| CVE-2010-2089 EXP | The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-depend… | Patch early | 5.0 medium | 14.6% | 2010-05-27 |
| CVE-2007-5728 EXP | Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 14.6% | 2007-10-30 |
| CVE-2017-3528 EXP | Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (lists of values, datepicker, etc… | Patch early | 5.4 medium | 14.6% | 2017-04-24 |
| CVE-2010-5300 EXP | Stack-based buffer overflow in Jzip 1.3 through 2.0.0.132900 allows remote attackers to cause a denial of service (crash) and possibly execute arbitra… | Patch early | 6.8 medium | 14.6% | 2014-06-11 |
| CVE-2006-3199 EXP | Opera 9 allows remote attackers to cause a denial of service (crash) via an A tag with an href attribute with a URL containing a long hostname, which… | Patch early | 5.0 medium | 14.6% | 2006-06-23 |
| CVE-2010-1081 EXP | Directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for Core Joomla! allows remote at… | Patch early | 5.0 medium | 14.6% | 2010-03-23 |
| CVE-2018-6409 EXP | An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the… | Patch early | 5.3 medium | 14.6% | 2018-05-26 |
| CVE-2006-5220 EXP | Multiple PHP remote file inclusion vulnerabilities in WebYep 1.1.9, when register_globals is enabled, allow remote attackers to execute arbitrary PHP… | Patch early | 5.1 medium | 14.6% | 2006-10-10 |
| CVE-2020-24223 EXP | Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters. | Patch early | 6.1 medium | 14.6% | 2020-08-30 |
| CVE-2023-5702 EXP | A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic. Affected by this issue is some unknown functionality… | Patch early | 4.3 medium | 14.5% | 2023-10-23 |
| CVE-2019-9649 EXP | An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory trav… | Patch early | 5.3 medium | 14.5% | 2019-03-22 |
| CVE-2016-0772 EXP | The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, whic… | Patch early | 6.5 medium | 14.5% | 2016-09-02 |
| CVE-2008-0411 EXP | Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code v… | Patch early | 6.8 medium | 14.5% | 2008-02-28 |
| CVE-2011-1081 EXP | modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Nam… | Patch early | 5.0 medium | 14.5% | 2011-03-20 |
| CVE-2018-15141 EXP | Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal t… | Patch early | 6.5 medium | 14.5% | 2018-08-13 |
| CVE-2011-0420 EXP | The grapheme_extract function in the Internationalization extension (Intl) for ICU for PHP 5.3.5 allows context-dependent attackers to cause a denial… | Patch early | 5.0 medium | 14.4% | 2011-02-19 |
| CVE-2009-2350 EXP | Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attack… | Patch early | 4.3 medium | 14.4% | 2009-07-07 |
| CVE-2000-0929 EXP | Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not cl… | Patch early | 5.0 medium | 14.4% | 2000-12-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt