CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,882 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
169,157 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-1834 EXP | Integer signedness error in Opera before 8.54 allows remote attackers to execute arbitrary code via long values in a stylesheet attribute, which pass… | Patch early | 5.1 medium | 12.1% | 2006-04-19 |
| CVE-2007-0017 EXP | Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and t… | Patch early | 6.8 medium | 12.1% | 2007-01-03 |
| CVE-2006-4208 EXP | Directory traversal vulnerability in wp-db-backup.php in Skippy WP-DB-Backup plugin for WordPress 1.7 and earlier allows remote authenticated users wi… | Patch early | 5.0 medium | 12.1% | 2006-08-17 |
| CVE-2001-0054 EXP | Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a str… | Patch early | 5.0 medium | 12% | 2001-02-16 |
| CVE-2009-4017 EXP | PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, whi… | Patch early | 5.0 medium | 12% | 2009-11-24 |
| CVE-2012-5533 EXP | The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via… | Patch early | 5.0 medium | 12% | 2012-11-24 |
| CVE-2016-9722 EXP | IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended… | Patch early | 4.2 medium | 12% | 2018-01-10 |
| CVE-2004-2104 EXP | Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, vi… | Patch early | 5.0 medium | 11.9% | 2004-12-31 |
| CVE-2011-5252 EXP | Open redirect vulnerability in Users/Account/LogOff in Orchard 1.0.x before 1.0.21, 1.1.x before 1.1.31, 1.2.x before 1.2.42, and 1.3.x before 1.3.10… | Patch early | 5.8 medium | 11.9% | 2013-01-12 |
| CVE-2009-1284 EXP | Buffer overflow in BibTeX 0.99 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a long .bib bibliogra… | Patch early | 5.0 medium | 11.9% | 2009-04-09 |
| CVE-2004-1488 EXP | wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web… | Patch early | 5.0 medium | 11.9% | 2005-04-27 |
| CVE-2012-3793 EXP | Integer overflow in Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attac… | Patch early | 5.0 medium | 11.9% | 2012-06-25 |
| CVE-2008-1270 EXP | mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrar… | Patch early | 5.0 medium | 11.9% | 2008-03-10 |
| CVE-2004-2043 EXP | Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allo… | Patch early | 5.0 medium | 11.9% | 2004-05-01 |
| CVE-2010-1981 EXP | Directory traversal vulnerability in the Fabrik (com_fabrik) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot d… | Patch early | 6.8 medium | 11.9% | 2010-05-19 |
| CVE-2006-5846 EXP | Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a .. (… | Patch early | 6.4 medium | 11.9% | 2006-11-10 |
| CVE-2010-1320 EXP | Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote… | Patch early | 4.0 medium | 11.9% | 2010-04-22 |
| CVE-2002-1954 EXP | Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the q… | Patch early | 4.3 medium | 11.9% | 2002-12-31 |
| CVE-2008-1489 EXP | Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly… | Patch early | 6.8 medium | 11.8% | 2008-03-25 |
| CVE-2008-1881 EXP | Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a… | Patch early | 6.8 medium | 11.8% | 2008-04-17 |
| CVE-2011-4153 EXP | PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL p… | Patch early | 5.0 medium | 11.8% | 2012-01-18 |
| CVE-2018-8468 EXP | An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." This affec… | Patch early | 4.7 medium | 11.8% | 2018-09-13 |
| CVE-2010-1029 EXP | Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS… | Patch early | 5.0 medium | 11.7% | 2010-03-19 |
| CVE-2013-4295 EXP | The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an external… | Patch early | 5.0 medium | 11.7% | 2013-10-24 |
| CVE-2006-1206 EXP | Matt Johnston Dropbear SSH server 0.47 and earlier, as used in embedded Linux devices and on general-purpose operating systems, allows remote attacker… | Patch early | 5.0 medium | 11.7% | 2006-03-14 |
| CVE-2005-2792 EXP | Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in… | Patch early | 5.0 medium | 11.7% | 2005-09-02 |
| CVE-2010-2122 EXP | Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows remote attackers to include and… | Patch early | 6.8 medium | 11.7% | 2010-06-01 |
| CVE-1999-1520 EXP | A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, whi… | Patch early | 5.0 medium | 11.7% | 1999-05-11 |
| CVE-2008-0333 EXP | Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read a… | Patch early | 5.0 medium | 11.7% | 2008-01-17 |
| CVE-2014-3976 EXP | Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a… | Patch early | 5.0 medium | 11.6% | 2014-06-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt