CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,935 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
169,186 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-3969 EXP | The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitializ… | Patch early | 6.5 medium | 10.1% | 2013-10-01 |
| CVE-2009-0756 EXP | The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that… | Patch early | 5.0 medium | 10.1% | 2009-03-03 |
| CVE-2011-4618 EXP | Cross-site scripting (XSS) vulnerability in advancedtext.php in Advanced Text Widget plugin before 2.0.2 for WordPress allows remote attackers to inje… | Patch early | 4.3 medium | 10.1% | 2013-01-24 |
| CVE-2007-4722 EXP | Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie07051001.dll 1.0.0.1 in Move Media Pl… | Patch early | 6.8 medium | 10.1% | 2007-09-05 |
| CVE-2009-3305 EXP | Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that… | Patch early | 5.0 medium | 10.1% | 2009-12-24 |
| CVE-2011-2522 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attacke… | Patch early | 6.8 medium | 10% | 2011-07-29 |
| CVE-2010-0682 EXP | WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter. | Patch early | 4.0 medium | 10% | 2010-02-23 |
| CVE-2005-0989 EXP | The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attacker… | Patch early | 5.0 medium | 10% | 2005-05-02 |
| CVE-2018-20523 EXP | Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a t… | Patch early | 5.3 medium | 10% | 2019-06-07 |
| CVE-2006-2460 EXP | Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESS… | Patch early | 6.4 medium | 10% | 2006-05-19 |
| CVE-2018-19042 EXP | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters o… | Patch early | 5.3 medium | 10% | 2019-01-31 |
| CVE-2018-19043 EXP | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename) via a ../ directory traversal… | Patch early | 5.3 medium | 10% | 2019-01-31 |
| CVE-2000-0213 EXP | The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacha… | Patch early | 5.0 medium | 10% | 2000-02-23 |
| CVE-2021-34370 EXP | Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags an… | Patch early | 6.1 medium | 10% | 2021-06-09 |
| CVE-2007-2807 EXP | Stack-based buffer overflow in mod/server.mod/servrmsg.c in Eggdrop 1.6.18, and possibly earlier, allows user-assisted, remote IRC servers to execute… | Patch early | 6.8 medium | 10% | 2007-05-22 |
| CVE-2006-4019 EXP | Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variabl… | Patch early | 6.4 medium | 10% | 2006-08-11 |
| CVE-2010-2939 EXP | Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and possibly ot… | Patch early | 4.3 medium | 10% | 2010-08-17 |
| CVE-2021-33904 EXP | In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are conf… | Patch early | 6.1 medium | 10% | 2021-06-07 |
| CVE-2012-4552 EXP | Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute arbitrary code via a crafted 3… | Patch early | 6.8 medium | 10% | 2012-11-18 |
| CVE-2011-5265 EXP | Cross-site scripting (XSS) vulnerability in cached_image.php in the Featurific For WordPress plugin 1.6.2 for WordPress allows remote attackers to inj… | Patch early | 4.3 medium | 10% | 2013-02-12 |
| CVE-2013-0238 EXP | The try_parse_v4_netmask function in hostmask.c in IRCD-Hybrid before 8.0.6 does not properly validate masks, which allows remote attackers to cause a… | Patch early | 5.0 medium | 10% | 2013-02-13 |
| CVE-2012-1617 EXP | Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbitrary files via a .. (dot dot)… | Patch early | 6.4 medium | 9.9% | 2012-09-26 |
| CVE-2010-1476 EXP | Directory traversal vulnerability in the AlphaUserPoints (com_alphauserpoints) component 1.5.5 for Joomla! allows remote attackers to read arbitrary f… | Patch early | 6.8 medium | 9.9% | 2010-04-19 |
| CVE-2016-0862 EXP | General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive… | Patch early | 6.5 medium | 9.9% | 2016-02-05 |
| CVE-2010-4717 EXP | Multiple stack-based buffer overflows in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote a… | Patch early | 6.5 medium | 9.9% | 2011-01-31 |
| CVE-2009-5135 EXP | The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an external en… | Patch early | 5.0 medium | 9.9% | 2013-05-02 |
| CVE-2003-1029 EXP | The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loop and memory consumption) via… | Patch early | 5.0 medium | 9.9% | 2004-02-17 |
| CVE-2019-12461 EXP | Web Port 1.19.1 allows XSS via the /log type parameter. | Patch early | 6.1 medium | 9.9% | 2019-05-30 |
| CVE-2021-41878 EXP | A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enables a remote attacker to execute… | Patch early | 6.1 medium | 9.9% | 2021-10-04 |
| CVE-2006-4191 EXP | Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitra… | Patch early | 5.1 medium | 9.9% | 2006-08-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt