CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,806 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
205,615 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-29689 EXP | PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vuln… | Patch early | 9.8 critical | 53.5% | 2023-08-04 |
| CVE-2006-6761 EXP | Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code… | Patch early | 6.5 medium | 53.4% | 2006-12-27 |
| CVE-2006-2502 EXP | Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute… | Patch early | 5.1 medium | 53.3% | 2006-05-22 |
| CVE-2022-33098 EXP | Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows att… | Patch early | 6.1 medium | 53.3% | 2022-07-07 |
| CVE-2006-5702 EXP | Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-list… | Patch early | 5.0 medium | 53.3% | 2006-11-04 |
| CVE-1999-0191 EXP | IIS newdsn.exe CGI script allows remote users to overwrite files. | Patch early | 6.4 medium | 53.3% | 1997-09-01 |
| CVE-2018-7739 EXP | antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and password parameters, as demons… | Patch early | 9.8 critical | 53.2% | 2018-03-07 |
| CVE-2019-9760 EXP | FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-controlled machine that sends craf… | Patch early | 9.8 critical | 53.1% | 2019-03-14 |
| CVE-2009-3591 EXP | Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with an invalid location. | Patch early | 5.0 medium | 52.8% | 2009-10-08 |
| CVE-2018-8021 EXP | Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. N… | Patch early | 9.8 critical | 52.8% | 2018-11-07 |
| CVE-2018-7286 EXP | An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjs… | Patch early | 6.5 medium | 52.7% | 2018-02-22 |
| CVE-2022-31470 EXP | An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 a… | Patch early | 6.1 medium | 52.7% | 2022-06-07 |
| CVE-2008-2370 EXP | Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization befo… | Patch early | 5.0 medium | 52.7% | 2008-08-04 |
| CVE-2022-31126 EXP | Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauth… | Patch early | 10.0 critical | 52.6% | 2022-07-06 |
| CVE-2008-2549 EXP | Adobe Acrobat Reader 8.1.2 and earlier, and before 7.1.1, allows remote attackers to cause a denial of service (application crash) and possibly execut… | Patch early | 4.3 medium | 52.6% | 2008-06-04 |
| CVE-2018-11686 EXP | The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php. | Patch early | 9.8 critical | 52.5% | 2019-07-03 |
| CVE-2012-5192 EXP | Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to read arbitrary files via "''%2F"… | Patch early | 5.0 medium | 52.5% | 2014-01-28 |
| CVE-2007-3898 EXP | The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, wh… | Patch early | 6.4 medium | 52.3% | 2007-11-14 |
| CVE-2017-5174 EXP | An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerability has bee… | Patch early | 9.8 critical | 52.3% | 2017-05-19 |
| CVE-2012-4031 EXP | Multiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote attackers to read arbitrary files via… | Patch early | 5.0 medium | 52.3% | 2012-07-17 |
| CVE-2019-8953 EXP | The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php… | Patch early | 6.1 medium | 52.2% | 2019-02-20 |
| CVE-2012-0897 EXP | Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (… | Patch early | 6.8 medium | 52.2% | 2012-01-20 |
| CVE-2018-8831 EXP | A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of t… | Patch early | 6.1 medium | 52% | 2018-04-18 |
| CVE-2010-1622 EXP | SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary c… | Patch early | 6.0 medium | 52% | 2010-06-21 |
| CVE-2015-1487 EXP | The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrary… | Patch early | 5.5 medium | 52% | 2015-08-01 |
| CVE-2019-13068 EXP | public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field). | Patch early | 5.4 medium | 51.9% | 2019-06-30 |
| CVE-2007-4232 EXP | PHP remote file inclusion vulnerability in admin/inc/change_action.php in Andreas Robertz PHPNews 0.93 allows remote attackers to execute arbitrary PH… | Patch early | 6.8 medium | 51.7% | 2007-08-08 |
| CVE-2011-0522 EXP | The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text decoder (modules/codec/subtitles/subsusf.c) in Vide… | Patch early | 6.8 medium | 51.5% | 2011-02-07 |
| CVE-2013-1847 EXP | The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of ser… | Patch early | 5.0 medium | 51.4% | 2013-05-02 |
| CVE-2010-4052 EXP | Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, all… | Patch early | 5.0 medium | 51.3% | 2011-01-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt