CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,003 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
169,214 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2000-0656 EXP | Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the FTP proto… | Patch early | 5.0 medium | 9% | 2000-07-25 |
| CVE-2009-1220 EXP | Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30… | Patch early | 4.3 medium | 9% | 2009-04-01 |
| CVE-2008-0132 EXP | Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message window and waiting for the adminis… | Patch early | 5.0 medium | 9% | 2008-01-08 |
| CVE-2004-1965 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 9% | 2004-04-25 |
| CVE-2006-4126 EXP | The dc_chat function in cmd.dc.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to cause a denial of service (application crash) by send… | Patch early | 5.0 medium | 9% | 2006-08-14 |
| CVE-2006-4192 EXP | Multiple buffer overflows in MODPlug Tracker (OpenMPT) 1.17.02.43 and earlier and libmodplug 0.8 and earlier, as used in GStreamer and possibly other… | Patch early | 5.1 medium | 9% | 2006-08-17 |
| CVE-2020-25495 EXP | A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote attackers to inject arbitrary we… | Patch early | 6.1 medium | 9% | 2020-12-18 |
| CVE-2007-4802 EXP | Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a long eighth argument to the SetI… | Patch early | 6.8 medium | 9% | 2007-09-11 |
| CVE-2011-2744 EXP | Directory traversal vulnerability in Chyrp 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded d… | Patch early | 6.8 medium | 9% | 2011-07-19 |
| CVE-2004-1269 EXP | lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subs… | Patch early | 5.0 medium | 9% | 2005-01-10 |
| CVE-2009-4495 EXP | Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or pos… | Patch early | 5.0 medium | 9% | 2010-01-13 |
| CVE-2012-0788 EXP | The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of… | Patch early | 5.0 medium | 9% | 2012-02-14 |
| CVE-2019-3474 EXP | A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authenticated as a low privilege user… | Patch early | 6.5 medium | 9% | 2019-02-20 |
| CVE-2009-2285 EXP | Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial of service (crash) via a crafte… | Patch early | 4.3 medium | 9% | 2009-07-01 |
| CVE-2008-3286 EXP | SWAT 4 1.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via a (1) VERIFYCONTENT or (2) GAMECONFIG command sent to t… | Patch early | 5.0 medium | 8.9% | 2008-07-24 |
| CVE-2012-1835 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the All-in-One Event Calendar plugin 1.4 and 1.5 for WordPress allow remote attackers to inject… | Patch early | 4.3 medium | 8.9% | 2012-08-14 |
| CVE-2001-0080 EXP | Cisco Catalyst 6000, 5000, or 4000 switches allow remote attackers to cause a denial of service by connecting to the SSH service with a non-SSH client… | Patch early | 5.0 medium | 8.9% | 2001-02-12 |
| CVE-2016-4004 EXP | Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated administrators to read arbitrary file… | Patch early | 4.9 medium | 8.9% | 2016-04-12 |
| CVE-2009-4494 EXP | AOLserver 4.5.1 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title,… | Patch early | 5.0 medium | 8.9% | 2010-01-13 |
| CVE-2008-1561 EXP | Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of service (appli… | Patch early | 5.0 medium | 8.9% | 2008-03-31 |
| CVE-2003-0211 EXP | Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections. | Patch early | 5.0 medium | 8.9% | 2003-05-05 |
| CVE-2008-5642 EXP | Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a… | Patch early | 5.0 medium | 8.9% | 2008-12-17 |
| CVE-2006-2458 EXP | Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code via (1) the asf_read_header f… | Patch early | 4.0 medium | 8.9% | 2006-05-18 |
| CVE-2002-0737 EXP | Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a denial of service (resource exhau… | Patch early | 6.4 medium | 8.9% | 2002-08-12 |
| CVE-2008-4324 EXP | The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dere… | Patch early | 5.0 medium | 8.9% | 2008-09-29 |
| CVE-2014-2575 EXP | Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and… | Patch early | 6.5 medium | 8.9% | 2014-06-06 |
| CVE-2010-0313 EXP | The core_get_proxyauth_dn function in ns-slapd in Sun Java System Directory Server Enterprise Edition 7.0 allows remote attackers to cause a denial of… | Patch early | 5.0 medium | 8.9% | 2010-01-14 |
| CVE-2012-4982 EXP | Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary w… | Patch early | 5.8 medium | 8.9% | 2012-12-05 |
| CVE-2019-11269 EXP | Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versi… | Patch early | 5.4 medium | 8.9% | 2019-06-12 |
| CVE-2006-2555 EXP | The parse_command function in Genecys 0.2 and earlier allows remote attackers to cause a denial of service (crash) via a command with a missing ":" (c… | Patch early | 5.0 medium | 8.9% | 2006-05-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt