CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,759 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
169,115 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-28999 EXP | The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console. | Patch early | 6.4 medium | 13.9% | 2024-06-04 |
| CVE-2006-1985 EXP | Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to exe… | Patch early | 5.1 medium | 13.9% | 2006-04-21 |
| CVE-2019-3810 EXP | A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did n… | Patch early | 6.1 medium | 13.9% | 2019-03-25 |
| CVE-2005-3077 EXP | Microsoft Internet Explorer 5.2.3 for Mac OS allows remote attackers to cause a denial of service (crash) via a web page with malformed attributes in… | Patch early | 5.0 medium | 13.9% | 2005-09-27 |
| CVE-2006-5536 EXP | Directory traversal vulnerability in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to read arbitrary fil… | Patch early | 5.0 medium | 13.9% | 2006-10-26 |
| CVE-2013-6127 EXP | The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict Rep… | Patch early | 5.8 medium | 13.9% | 2013-10-25 |
| CVE-2007-1562 EXP | The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to ot… | Patch early | 6.8 medium | 13.8% | 2007-03-21 |
| CVE-2006-1510 EXP | Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 a… | Patch early | 4.0 medium | 13.8% | 2006-03-30 |
| CVE-2022-23409 EXP | The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php. | Patch early | 4.9 medium | 13.8% | 2022-01-31 |
| CVE-2012-5321 EXP | tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks… | Patch early | 5.8 medium | 13.8% | 2012-10-08 |
| CVE-2009-1902 EXP | The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request… | Patch early | 5.0 medium | 13.7% | 2009-06-03 |
| CVE-2006-3109 EXP | Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), al… | Patch early | 4.3 medium | 13.7% | 2006-06-21 |
| CVE-2013-3631 EXP | NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.php, aka the "Advanced | Execut… | Patch early | 6.0 medium | 13.7% | 2013-11-02 |
| CVE-2013-3724 EXP | The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash and service… | Patch early | 5.0 medium | 13.7% | 2013-08-01 |
| CVE-2013-2765 EXP | The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process… | Patch early | 5.0 medium | 13.7% | 2013-07-15 |
| CVE-2003-0078 EXP | ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding… | Patch early | 5.0 medium | 13.7% | 2003-03-03 |
| CVE-2019-6442 EXP | An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, rel… | Patch early | 6.5 medium | 13.7% | 2019-01-16 |
| CVE-2003-0447 EXP | The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via an argument t… | Patch early | 5.1 medium | 13.7% | 2003-07-24 |
| CVE-2017-16353 EXP | GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file… | Patch early | 6.5 medium | 13.7% | 2017-11-01 |
| CVE-2002-1603 EXP | GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /),… | Patch early | 5.0 medium | 13.7% | 2002-02-13 |
| CVE-2007-0562 EXP | Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (applicat… | Patch early | 4.3 medium | 13.7% | 2007-01-30 |
| CVE-2007-2052 EXP | Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the… | Patch early | 5.0 medium | 13.6% | 2007-04-16 |
| CVE-2002-1487 EXP | The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by sending the raw messages (1) 2… | Patch early | 5.0 medium | 13.6% | 2003-04-02 |
| CVE-2002-1522 EXP | Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute ar… | Patch early | 5.0 medium | 13.6% | 2003-04-02 |
| CVE-2006-2686 EXP | PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[AA_INC_PAT… | Patch early | 6.4 medium | 13.6% | 2006-05-31 |
| CVE-2020-11027 EXP | In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to… | Patch early | 6.1 medium | 13.6% | 2020-04-30 |
| CVE-2010-1340 EXP | Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote attackers to read arbitrary f… | Patch early | 5.0 medium | 13.6% | 2010-04-09 |
| CVE-2010-1534 EXP | Directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (d… | Patch early | 5.0 medium | 13.6% | 2010-04-26 |
| CVE-2010-1858 EXP | Directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote attackers to read arbitrary files… | Patch early | 5.0 medium | 13.6% | 2010-05-07 |
| CVE-2010-1312 EXP | Directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote attackers to read arbitrary f… | Patch early | 5.0 medium | 13.6% | 2010-04-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt