CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,903 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
169,168 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-0396 EXP | Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-001, allows remote attackers to execute arbitrary… | Patch early | 5.1 medium | 11.1% | 2006-03-14 |
| CVE-2011-1761 EXP | Multiple stack-based buffer overflows in the (1) abc_new_macro and (2) abc_new_umacro functions in src/load_abc.cpp in libmodplug before 0.8.8.3 allow… | Patch early | 6.8 medium | 11.1% | 2012-06-07 |
| CVE-2006-2852 EXP | PHP remote file inclusion vulnerability in dotWidget CMS 1.0.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbit… | Patch early | 6.8 medium | 11.1% | 2006-06-06 |
| CVE-2006-0996 EXP | Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 11.1% | 2006-04-10 |
| CVE-2013-4625 EXP | Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to… | Patch early | 4.3 medium | 11.1% | 2013-08-09 |
| CVE-2006-2868 EXP | Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.6 allow remote attackers to execute arbitrary PHP code via a URL in the includePat… | Patch early | 5.1 medium | 11.1% | 2006-06-06 |
| CVE-2009-0039 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 a… | Patch early | 6.8 medium | 11.1% | 2009-04-17 |
| CVE-2004-0179 EXP | Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4)… | Patch early | 6.8 medium | 11.1% | 2004-06-01 |
| CVE-2017-18195 EXP | An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog p… | Patch early | 5.3 medium | 11.1% | 2018-02-26 |
| CVE-2008-3794 EXP | Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execut… | Patch early | 6.8 medium | 11% | 2008-08-26 |
| CVE-2005-0873 EXP | Multiple cross-site scripting (XSS) vulnerabilities in test.jsp in Oracle Reports Server 10g (9.0.4.3.3) allow remote attackers to inject arbitrary we… | Patch early | 4.3 medium | 11% | 2005-05-02 |
| CVE-2010-2310 EXP | SolarWinds TFTP Server 10.4.0.13 allows remote attackers to cause a denial of service (crash) via a long write request. | Patch early | 5.0 medium | 11% | 2010-06-16 |
| CVE-2006-0528 EXP | The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent… | Patch early | 5.0 medium | 11% | 2006-02-02 |
| CVE-2006-6097 EXP | GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTY… | Patch early | 4.0 medium | 11% | 2006-11-24 |
| CVE-2009-2764 EXP | Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of service (application crash) vi… | Patch early | 5.0 medium | 11% | 2009-08-14 |
| CVE-2005-3202 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers to inject arbitrary web script… | Patch early | 6.8 medium | 11% | 2005-10-14 |
| CVE-2006-3995 EXP | Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php, (4) install.uhp.php, (5) too… | Patch early | 6.8 medium | 11% | 2006-08-05 |
| CVE-2014-7221 EXP | TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (buffer overflow and application crash) by connecti… | Patch early | 6.5 medium | 11% | 2018-01-08 |
| CVE-2014-7222 EXP | Buffer overflow in TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (application crash) by connectin… | Patch early | 6.5 medium | 11% | 2018-01-08 |
| CVE-2006-4901 EXP | Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, and eTrust Audit 1.5 and r8, allows remote attackers to spoof alerts… | Patch early | 6.4 medium | 11% | 2006-09-22 |
| CVE-2001-0590 EXP | Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL… | Patch early | 5.0 medium | 11% | 2001-08-02 |
| CVE-2006-5205 EXP | Directory traversal vulnerability in Invision Gallery 2.0.7 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the dir par… | Patch early | 5.0 medium | 11% | 2006-10-10 |
| CVE-2009-0347 EXP | Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitrar… | Patch early | 5.8 medium | 10.9% | 2009-01-29 |
| CVE-2014-1907 EXP | Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers… | Patch early | 6.4 medium | 10.9% | 2014-03-06 |
| CVE-2019-1343 EXP | A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID… | Patch early | 6.5 medium | 10.9% | 2019-10-10 |
| CVE-2019-1346 EXP | A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID… | Patch early | 6.5 medium | 10.9% | 2019-10-10 |
| CVE-2012-2385 EXP | The terminal dispatcher in mosh before 1.2.1 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an esc… | Patch early | 4.0 medium | 10.9% | 2012-06-29 |
| CVE-2012-3792 EXP | Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a deni… | Patch early | 5.0 medium | 10.9% | 2012-06-25 |
| CVE-2012-3795 EXP | Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a deni… | Patch early | 5.0 medium | 10.9% | 2012-06-25 |
| CVE-2011-4926 EXP | Cross-site scripting (XSS) vulnerability in adminimize/adminimize_page.php in the Adminimize plugin before 1.7.22 for WordPress allows remote attacker… | Patch early | 4.3 medium | 10.9% | 2012-08-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt