CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,987 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
169,210 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-6976 EXP | MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (NMS) settings via a crafted SNM… | Patch early | 6.4 medium | 9.2% | 2009-08-19 |
| CVE-2005-0828 EXP | highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote at… | Patch early | 5.0 medium | 9.2% | 2005-05-02 |
| CVE-2007-6318 EXP | SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the… | Patch early | 6.8 medium | 9.2% | 2007-12-12 |
| CVE-2011-5219 EXP | Directory traversal vulnerability in examples/show_code.php in mPDF 5.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot)… | Patch early | 5.0 medium | 9.2% | 2012-10-25 |
| CVE-2008-0623 EXP | Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows remote attackers to execute ar… | Patch early | 4.3 medium | 9.2% | 2008-02-06 |
| CVE-2014-3848 EXP | The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials via… | Patch early | 5.0 medium | 9.1% | 2014-05-23 |
| CVE-2006-1999 EXP | The multiplayer menu in OpenTTD 0.4.7 allows remote attackers to cause a denial of service via a UDP packet with an incorrect size, which causes the c… | Patch early | 5.0 medium | 9.1% | 2006-04-25 |
| CVE-2015-1561 EXP | The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed i… | Patch early | 6.5 medium | 9.1% | 2015-07-14 |
| CVE-2010-3804 EXP | The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, use… | Patch early | 5.0 medium | 9.1% | 2010-11-22 |
| CVE-2008-5660 EXP | Format string vulnerability in the vinagre_utils_show_error function (src/vinagre-utils.c) in Vinagre 0.5.x before 0.5.2 and 2.x before 2.24.2 might a… | Patch early | 6.8 medium | 9.1% | 2008-12-17 |
| CVE-1999-0669 EXP | The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as de… | Patch early | 4.0 medium | 9.1% | 1999-09-01 |
| CVE-2015-4062 EXP | SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to exec… | Patch early | 6.5 medium | 9.1% | 2015-05-27 |
| CVE-2018-5751 EXP | The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev2… | Patch early | 6.5 medium | 9.1% | 2018-06-16 |
| CVE-2006-2576 EXP | Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute ar… | Patch early | 5.1 medium | 9.1% | 2006-05-24 |
| CVE-2007-0051 EXP | Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary c… | Patch early | 6.8 medium | 9.1% | 2007-01-04 |
| CVE-2015-3301 EXP | Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress b… | Patch early | 4.0 medium | 9.1% | 2015-05-14 |
| CVE-2003-1396 EXP | Heap-based buffer overflow in Opera 6.05 through 7.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code… | Patch early | 6.8 medium | 9.1% | 2003-12-31 |
| CVE-2012-3414 EXP | Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1… | Patch early | 4.3 medium | 9.1% | 2013-07-19 |
| CVE-2007-1380 EXP | The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-dependent attackers to obtain… | Patch early | 5.0 medium | 9.1% | 2007-03-10 |
| CVE-2010-1982 EXP | Directory traversal vulnerability in the JA Voice (com_javoice) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a .. (do… | Patch early | 5.0 medium | 9.1% | 2010-05-19 |
| CVE-2021-40868 EXP | In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS. | Patch early | 6.1 medium | 9.1% | 2021-09-21 |
| CVE-2009-2419 EXP | Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause… | Patch early | 4.3 medium | 9.1% | 2009-07-09 |
| CVE-2023-30256 EXP | Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_cre… | Patch early | 6.1 medium | 9.1% | 2023-05-11 |
| CVE-2019-12962 EXP | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header. | Patch early | 6.1 medium | 9.1% | 2019-06-25 |
| CVE-2018-15768 EXP | Dell OpenManage Network Manager versions prior to 6.5.0 enabled read/write access to the file system for MySQL users due to insecure default configura… | Patch early | 6.5 medium | 9.1% | 2018-11-30 |
| CVE-2009-0037 EXP | The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which… | Patch early | 6.8 medium | 9.1% | 2009-03-05 |
| CVE-2003-0511 EXP | The web server for Cisco Aironet AP1x00 Series Wireless devices running certain versions of IOS 12.2 allow remote attackers to cause a denial of servi… | Patch early | 5.0 medium | 9% | 2003-08-27 |
| CVE-2014-9261 EXP | The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to rea… | Patch early | 5.0 medium | 9% | 2015-03-23 |
| CVE-2007-0676 EXP | SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | Patch early | 6.8 medium | 9% | 2007-02-03 |
| CVE-2009-0677 EXP | avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to exec… | Patch early | 6.5 medium | 9% | 2009-02-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt