CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,759 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
205,615 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-0395 EXP | The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an unsafe type, which allows user… | Patch early | 5.1 medium | 55.4% | 2006-08-05 |
| CVE-2021-43857 EXP | Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched… | Patch early | 9.8 critical | 55.3% | 2021-12-27 |
| CVE-2005-4734 EXP | Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remote attacke… | Patch early | 6.4 medium | 55.3% | 2005-12-31 |
| CVE-2004-0942 EXP | Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header… | Patch early | 5.0 medium | 55.1% | 2005-02-09 |
| CVE-2016-6602 EXP | ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartex… | Patch early | 9.8 critical | 55.1% | 2017-01-23 |
| CVE-2015-1833 EXP | XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2… | Patch early | 6.4 medium | 55% | 2015-05-29 |
| CVE-2013-5877 EXP | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 1… | Patch early | 5.0 medium | 55% | 2014-01-15 |
| CVE-2004-0594 EXP | The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allo… | Patch early | 5.1 medium | 54.9% | 2004-07-27 |
| CVE-2008-2168 EXP | Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded… | Patch early | 4.3 medium | 54.9% | 2008-05-13 |
| CVE-2014-5446 EXP | Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allows remote a… | Patch early | 5.0 medium | 54.7% | 2014-12-04 |
| CVE-2022-36267 EXP | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can… | Patch early | 9.8 critical | 54.5% | 2022-08-08 |
| CVE-2010-3863 EXP | Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows r… | Patch early | 5.0 medium | 54.5% | 2010-11-05 |
| CVE-2022-24562 EXP | In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the enti… | Patch early | 9.8 critical | 54.5% | 2022-06-16 |
| CVE-2024-11972 EXP | The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install an… | Patch early | 9.8 critical | 54.5% | 2024-12-31 |
| CVE-2025-49132 EXP | Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespac… | Patch early | 10.0 critical | 54.5% | 2025-06-20 |
| CVE-2021-36356 EXP | KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary e… | Patch early | 9.8 critical | 54.4% | 2021-08-31 |
| CVE-2023-41425 EXP | Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded… | Patch early | 6.1 medium | 54.3% | 2023-11-07 |
| CVE-2018-5347 EXP | Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because… | Patch early | 9.8 critical | 54.2% | 2018-01-12 |
| CVE-2006-1993 EXP | Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via cert… | Patch early | 5.1 medium | 54% | 2006-04-25 |
| CVE-2005-0455 EXP | Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlie… | Patch early | 5.1 medium | 54% | 2005-05-02 |
| CVE-2025-27007 EXP | Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a… | Patch early | 9.8 critical | 53.9% | 2025-05-01 |
| CVE-2018-8734 EXP | SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL comm… | Patch early | 9.8 critical | 53.8% | 2018-04-18 |
| CVE-2013-3502 EXP | monarch_scan.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands, and… | Patch early | 6.5 medium | 53.7% | 2013-05-08 |
| CVE-2016-5312 EXP | Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbi… | Patch early | 6.5 medium | 53.7% | 2017-04-14 |
| CVE-2016-3209 EXP | Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Se… | Patch early | 5.5 medium | 53.7% | 2016-10-14 |
| CVE-2019-6441 EXP | An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The passw… | Patch early | 9.8 critical | 53.6% | 2019-03-21 |
| CVE-2017-17932 EXP | A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute ar… | Patch early | 9.8 critical | 53.6% | 2017-12-28 |
| CVE-2023-27823 EXP | An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials. | Patch early | 9.8 critical | 53.6% | 2023-05-12 |
| CVE-2002-1143 EXP | Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document i… | Patch early | 5.0 medium | 53.6% | 2003-04-11 |
| CVE-2019-19844 EXP | Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing… | Patch early | 9.8 critical | 53.6% | 2019-12-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt