CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,105 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
169,219 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-0760 EXP | Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI. | Patch early | 6.4 medium | 8.8% | 2004-08-18 |
| CVE-2007-3157 EXP | IPSecDrv.sys 10.4.0.12 in SafeNET High Assurance Remote 1.4.0 Build 12, and SoftRemote, allows remote attackers to cause a denial of service (infinite… | Patch early | 5.0 medium | 8.8% | 2007-06-11 |
| CVE-2009-2534 EXP | RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allow remote attackers to cause a denial of service (daemon crash) via an RTSP SETUP r… | Patch early | 5.0 medium | 8.8% | 2009-07-20 |
| CVE-2004-2059 EXP | Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SearchFor par… | Patch early | 5.0 medium | 8.8% | 2004-12-31 |
| CVE-2002-0288 EXP | Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP req… | Patch early | 5.0 medium | 8.8% | 2002-05-31 |
| CVE-2007-1044 EXP | Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name a… | Patch early | 5.0 medium | 8.8% | 2007-02-21 |
| CVE-2006-2739 EXP | PHP remote file inclusion vulnerability in footers.php in Epicdesigns tinyBB 0.3, when register_globals is enabled, allows remote attackers to execute… | Patch early | 5.1 medium | 8.8% | 2006-06-01 |
| CVE-2010-0718 EXP | Buffer overflow in Microsoft Windows Media Player 9 and 11.0.5721.5145 allows remote attackers to cause a denial of service (divide-by-zero error and… | Patch early | 4.3 medium | 8.8% | 2010-02-26 |
| CVE-2014-1222 EXP | Directory traversal vulnerability in kcfinder/browse.php in Vtiger CRM before 6.0.0 Security patch 1 allows remote authenticated users to read arbitra… | Patch early | 4.0 medium | 8.8% | 2014-08-12 |
| CVE-2004-1102 EXP | MailPost 5.1.1sv, and possibly earlier versions, displays a different error message depending on whether the requested file exists or not, which allow… | Patch early | 5.0 medium | 8.8% | 2005-01-10 |
| CVE-2019-20354 EXP | The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user) to download arbitrary files f… | Patch early | 4.3 medium | 8.8% | 2020-01-06 |
| CVE-2005-3927 EXP | Multiple directory traversal vulnerabilities in GuppY 4.5.9 and earlier allow remote attackers to read and include arbitrary files via (1) the meskin… | Patch early | 6.4 medium | 8.8% | 2005-11-30 |
| CVE-2009-1828 EXP | Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN ele… | Patch early | 5.0 medium | 8.8% | 2009-05-29 |
| CVE-2011-5107 EXP | Cross-site scripting (XSS) vulnerability in post_alert.php in Alert Before Your Post plugin, possibly 0.1.1 and earlier, for WordPress allows remote a… | Patch early | 4.3 medium | 8.8% | 2012-08-23 |
| CVE-2011-5179 EXP | Cross-site scripting (XSS) vulnerability in skysa-official/skysa.php in Skysa App Bar Integration plugin, possibly before 1.04, for WordPress allows r… | Patch early | 4.3 medium | 8.8% | 2012-09-20 |
| CVE-2005-2848 EXP | Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary fi… | Patch early | 5.0 medium | 8.8% | 2005-09-08 |
| CVE-2013-2416 EXP | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier allows remote attackers to affect… | Patch early | 4.3 medium | 8.8% | 2013-04-17 |
| CVE-2010-2482 EXP | LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to cause a denial of service (NUL… | Patch early | 4.3 medium | 8.8% | 2010-07-06 |
| CVE-2007-3487 EXP | Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote attackers to… | Patch early | 6.4 medium | 8.8% | 2007-06-29 |
| CVE-2014-0372 EXP | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 1… | Patch early | 5.5 medium | 8.8% | 2014-01-15 |
| CVE-2012-4878 EXP | Absolute path traversal vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 allows remote administrators to read arbitrary files via a full… | Patch early | 5.0 medium | 8.8% | 2012-09-06 |
| CVE-2013-3539 EXP | Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC… | Patch early | 6.8 medium | 8.8% | 2013-10-01 |
| CVE-2014-4643 EXP | Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a denial of service (application cr… | Patch early | 5.0 medium | 8.8% | 2014-06-25 |
| CVE-2013-3239 EXP | phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary… | Patch early | 4.6 medium | 8.8% | 2013-04-26 |
| CVE-2014-10079 EXP | In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML sou… | Patch early | 5.3 medium | 8.7% | 2019-02-23 |
| CVE-2011-3489 EXP | RnaUtility.dll in RsvcHost.exe 2.30.0.23 in Rockwell RSLogix 19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted… | Patch early | 5.0 medium | 8.7% | 2011-09-16 |
| CVE-2017-15271 EXP | A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729. This issue could be triggered prior to authentica… | Patch early | 5.9 medium | 8.7% | 2017-11-15 |
| CVE-1999-0750 EXP | Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account. | Patch early | 5.1 medium | 8.7% | 1999-09-13 |
| CVE-2014-8826 EXP | LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypass the Gatekeeper protection me… | Patch early | 5.0 medium | 8.7% | 2015-01-30 |
| CVE-2012-1614 EXP | Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/i… | Patch early | 5.0 medium | 8.7% | 2012-09-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt