CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,987 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
169,210 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-6493 EXP | Buffer overflow in the krbv4_ldap_auth function in servers/slapd/kerberos.c in OpenLDAP 2.4.3 and earlier, when OpenLDAP is compiled with the --enable… | Patch early | 5.1 medium | 9.3% | 2006-12-13 |
| CVE-2011-5233 EXP | Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pi… | Patch early | 4.3 medium | 9.3% | 2012-10-25 |
| CVE-2018-9038 EXP | Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request. | Patch early | 6.5 medium | 9.3% | 2018-04-10 |
| CVE-2008-4682 EXP | wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application abort) via a malformed Tamos CommView captu… | Patch early | 5.0 medium | 9.3% | 2008-10-22 |
| CVE-2010-4301 EXP | epan/dissectors/packet-zbee-zcl.c in the ZigBee ZCL dissector in Wireshark 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (i… | Patch early | 5.0 medium | 9.3% | 2010-11-26 |
| CVE-2020-11457 EXP | pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user. | Patch early | 5.4 medium | 9.3% | 2020-04-01 |
| CVE-2012-4242 EXP | Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 9.3% | 2012-10-01 |
| CVE-2008-4610 EXP | MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2)… | Patch early | 5.0 medium | 9.3% | 2008-10-20 |
| CVE-2000-1132 EXP | DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed "forum" variable. | Patch early | 6.4 medium | 9.3% | 2001-01-09 |
| CVE-2024-45440 EXP | core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of… | Patch early | 5.3 medium | 9.3% | 2024-08-29 |
| CVE-2007-6528 EXP | Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) a… | Patch early | 5.0 medium | 9.3% | 2007-12-27 |
| CVE-2008-0073 EXP | Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code v… | Patch early | 6.8 medium | 9.3% | 2008-03-24 |
| CVE-2024-12342 EXP | A vulnerability was found in TP-Link VN020 F3v(T) TT_V6.2.1021. It has been rated as critical. This issue affects some unknown processing of the file… | Patch early | 6.5 medium | 9.3% | 2024-12-08 |
| CVE-2004-2526 EXP | Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .… | Patch early | 5.0 medium | 9.3% | 2004-12-31 |
| CVE-2023-38501 EXP | copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and… | Patch early | 6.3 medium | 9.2% | 2023-07-25 |
| CVE-2002-0772 EXP | Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories via a .. (d… | Patch early | 6.4 medium | 9.2% | 2002-08-12 |
| CVE-2013-2287 EXP | Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject ar… | Patch early | 4.3 medium | 9.2% | 2014-04-04 |
| CVE-2007-1701 EXP | PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deseria… | Patch early | 6.8 medium | 9.2% | 2007-03-27 |
| CVE-2005-2006 EXP | JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a "%." (percent dot), which rev… | Patch early | 5.0 medium | 9.2% | 2005-06-17 |
| CVE-2002-1559 EXP | Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (drive letter) or (2) .. (dot-do… | Patch early | 5.0 medium | 9.2% | 2003-03-31 |
| CVE-2014-9225 EXP | The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server… | Patch early | 4.0 medium | 9.2% | 2015-01-21 |
| CVE-2009-1045 EXP | requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of service (stack consumption and crash) via a long input argument in an i… | Patch early | 5.0 medium | 9.2% | 2009-03-23 |
| CVE-2006-2901 EXP | The web server for D-Link Wireless Access-Point (DWL-2100ap) firmware 2.10na and earlier allows remote attackers to obtain sensitive system informatio… | Patch early | 5.0 medium | 9.2% | 2006-06-07 |
| CVE-2001-0748 EXP | Acme.Serve 1.7, as used in Cisco Secure ACS Unix and possibly other products, allows remote attackers to read arbitrary files by prepending several /… | Patch early | 5.0 medium | 9.2% | 2001-10-18 |
| CVE-2011-0678 EXP | Unrestricted file upload vulnerability in the EasyEdit module in Lomtec ActiveWeb Professional 3.0 allows remote attackers to execute arbitrary code b… | Patch early | 6.8 medium | 9.2% | 2011-01-28 |
| CVE-2011-4898 EXP | wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbnam… | Patch early | 5.0 medium | 9.2% | 2012-01-30 |
| CVE-2006-3372 EXP | Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) via a DHTML setAttributeNode function call with zero… | Patch early | 5.0 medium | 9.2% | 2006-07-06 |
| CVE-2006-4006 EXP | The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_p… | Patch early | 5.0 medium | 9.2% | 2006-08-07 |
| CVE-2007-1542 EXP | Unspecified vulnerability in the Cisco IP Phone 7940 and 7960 running firmware before POS8-6-0 allows remote attackers to cause a denial of service vi… | Patch early | 5.0 medium | 9.2% | 2007-03-20 |
| CVE-2000-0613 EXP | Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to force the firewall to close legi… | Patch early | 5.0 medium | 9.2% | 2000-03-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt