CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,987 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
149,015 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-5619 EXP | html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, M… | Patch early | 10.0 high | 58.6% | 2008-12-17 |
| CVE-2013-2068 EXP | Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to create and o… | Patch early | 9.4 high | 58.6% | 2013-09-28 |
| CVE-2016-6515 EXP | The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows re… | Patch early | 7.5 high | 58.6% | 2016-08-07 |
| CVE-2007-4834 EXP | Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP code via a URL in the MGR paramet… | Patch early | 7.5 high | 58.5% | 2007-09-12 |
| CVE-2008-2158 EXP | Multiple stack-based buffer overflows in the Command Line Interface process in the Server Agent in EMC AlphaStor 3.1 SP1 for Windows allow remote atta… | Patch early | 10.0 high | 58.4% | 2008-05-29 |
| CVE-2007-0217 EXP | The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server res… | Patch early | 10.0 high | 58.4% | 2007-02-13 |
| CVE-2005-0555 EXP | Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted… | Patch early | 7.5 high | 58.4% | 2005-04-12 |
| CVE-2003-0831 EXP | ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to… | Patch early | 9.0 high | 58.4% | 2003-11-17 |
| CVE-2011-4166 EXP | Directory traversal vulnerability in the MPAUploader.Uploader.1.UploadFiles method in HP Managed Printing Administration before 2.6.4 allows remote at… | Patch early | 7.5 high | 58.3% | 2011-12-27 |
| CVE-2015-7601 EXP | Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..// (dot dot double slash) in a R… | Patch early | 7.8 high | 58.3% | 2015-09-29 |
| CVE-2013-3184 EXP | Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 58.3% | 2013-08-14 |
| CVE-2015-7243 EXP | Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a… | Patch early | 7.5 high | 58.3% | 2015-09-18 |
| CVE-2006-1186 EXP | Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll… | Patch early | 10.0 high | 58.3% | 2006-04-11 |
| CVE-2015-1172 EXP | Unrestricted file upload vulnerability in admin/upload-file.php in the Holding Pattern theme (aka holding_pattern) 0.6 and earlier for WordPress allow… | Patch early | 7.5 high | 58.3% | 2015-02-11 |
| CVE-2011-4722 EXP | Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files via a .. (dot d… | Patch early | 7.8 high | 58.2% | 2014-12-28 |
| CVE-2006-6425 EXP | Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code… | Patch early | 9.0 high | 58.2% | 2006-12-27 |
| CVE-2008-0926 EXP | The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which a… | Patch early | 7.5 high | 58.2% | 2008-03-28 |
| CVE-2009-2485 EXP | Stack-based buffer overflow in HT-MP3Player 1.0 allows remote attackers to execute arbitrary code via a long string in a .ht3 file. | Patch early | 9.3 high | 58.1% | 2009-07-16 |
| CVE-2008-0437 EXP | Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation proces… | Patch early | 10.0 high | 58.1% | 2008-01-23 |
| CVE-2017-8618 EXP | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold,… | Patch early | 7.5 high | 58.1% | 2017-07-11 |
| CVE-2010-1318 EXP | Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11… | Patch early | 10.0 high | 58.1% | 2010-04-20 |
| CVE-2012-4177 EXP | The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -orbit_exe_path command line ar… | Patch early | 10.0 high | 58% | 2012-08-07 |
| CVE-2007-4712 EXP | PHP remote file inclusion vulnerability in index.php in eNetman 1 allows remote attackers to execute arbitrary PHP code via a URL in the page paramete… | Patch early | 7.5 high | 57.9% | 2007-09-05 |
| CVE-2005-0554 EXP | Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and… | Patch early | 7.5 high | 57.9% | 2005-05-02 |
| CVE-2016-7194 EXP | The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via… | Patch early | 7.5 high | 57.9% | 2016-10-14 |
| CVE-2014-2850 EXP | The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary command… | Patch early | 8.5 high | 57.7% | 2014-04-11 |
| CVE-2015-1503 EXP | Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot)… | Patch early | 7.5 high | 57.6% | 2018-05-08 |
| CVE-2006-1188 EXP | Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads… | Patch early | 7.5 high | 57.6% | 2006-04-11 |
| CVE-2008-4654 EXP | Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows re… | Patch early | 9.3 high | 57.5% | 2008-10-22 |
| CVE-2006-5854 EXP | Multiple buffer overflows in the Spooler service (nwspool.dll) in Novell Netware Client 4.91 through 4.91 SP2 allow remote attackers to execute arbitr… | Patch early | 7.5 high | 57.5% | 2006-12-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt