CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,759 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
205,598 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-100015 EXP | Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write to arbitrary files via a .. (do… | Patch early | 6.4 medium | 57.4% | 2015-01-13 |
| CVE-2005-1218 EXP | The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of servic… | Patch early | 5.0 medium | 57.3% | 2005-08-10 |
| CVE-2020-15922 EXP | There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) pr… | Patch early | 9.8 critical | 57.3% | 2020-07-24 |
| CVE-2015-5453 EXP | Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id para… | Patch early | 6.5 medium | 57.3% | 2015-07-08 |
| CVE-2006-4364 EXP | Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attackers to cause a denial of service… | Patch early | 5.0 medium | 57.3% | 2006-08-27 |
| CVE-2010-1899 EXP | Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attack… | Patch early | 4.3 medium | 57.2% | 2010-09-15 |
| CVE-2019-5029 EXP | An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands s… | Patch early | 9.8 critical | 57.2% | 2019-11-13 |
| CVE-2008-1358 EXP | Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary code via a F… | Patch early | 6.5 medium | 57.1% | 2008-03-17 |
| CVE-2019-5434 EXP | An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in t… | Patch early | 9.8 critical | 57% | 2019-05-06 |
| CVE-2015-2997 EXP | SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getAgentLogFil… | Patch early | 5.0 medium | 57% | 2015-06-08 |
| CVE-2021-45428 EXP | TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HT… | Patch early | 9.8 critical | 56.9% | 2022-01-03 |
| CVE-2017-6361 EXP | QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors. | Patch early | 9.8 critical | 56.8% | 2017-03-23 |
| CVE-2005-2287 EXP | SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large TCP packet with a leading space… | Patch early | 5.0 medium | 56.8% | 2005-07-18 |
| CVE-2001-0731 EXP | Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" quer… | Patch early | 5.0 medium | 56.8% | 2001-10-01 |
| CVE-2012-1006 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 56.6% | 2012-02-07 |
| CVE-2022-1104 EXP | The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as… | Patch early | 4.8 medium | 56.4% | 2022-05-09 |
| CVE-2018-12634 EXP | CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html… | Patch early | 9.8 critical | 56.4% | 2018-06-22 |
| CVE-2016-0784 EXP | Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated ad… | Patch early | 6.5 medium | 56.3% | 2016-04-11 |
| CVE-2018-17173 EXP | LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail. | Patch early | 9.8 critical | 56.2% | 2018-09-21 |
| CVE-2016-3078 EXP | Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buffe… | Patch early | 9.8 critical | 56.1% | 2016-08-07 |
| CVE-2013-1469 EXP | Directory traversal vulnerability in install.php in Piwigo before 2.4.7 allows remote attackers to read and delete arbitrary files via a .. (dot dot)… | Patch early | 4.0 medium | 56% | 2013-03-13 |
| CVE-2010-2115 EXP | SolarWinds TFTP Server 10.4.0.10 allows remote attackers to cause a denial of service (no new connections) via a crafted read request. | Patch early | 5.0 medium | 56% | 2010-05-28 |
| CVE-2007-0044 EXP | Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to ma… | Patch early | 4.3 medium | 55.9% | 2007-01-03 |
| CVE-2019-7255 EXP | Linear eMerge E3-Series devices allow XSS. | Patch early | 6.1 medium | 55.8% | 2019-07-02 |
| CVE-2011-4908 EXP | TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php. | Patch early | 9.8 critical | 55.8% | 2020-02-12 |
| CVE-2019-8387 EXP | MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component. | Patch early | 9.8 critical | 55.7% | 2019-05-08 |
| CVE-2018-1612 EXP | IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and obtain sensitive information.… | Patch early | 5.8 medium | 55.7% | 2018-07-17 |
| CVE-2014-7236 EXP | Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenablep… | Patch early | 9.1 critical | 55.6% | 2020-02-17 |
| CVE-2012-1196 EXP | Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote… | Patch early | 5.0 medium | 55.5% | 2012-02-18 |
| CVE-2006-0395 EXP | The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an unsafe type, which allows user… | Patch early | 5.1 medium | 55.4% | 2006-08-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt