CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,105 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
169,219 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-1150 EXP | Stack-based buffer overflow in the in_cdda.dll plugin for Winamp 5.0 through 5.08c allows attackers to execute arbitrary code via a cda:// URL with a… | Patch early | 5.1 medium | 8.7% | 2004-12-31 |
| CVE-2004-2280 EXP | Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial of service (crash) via unknown… | Patch early | 5.0 medium | 8.7% | 2004-12-31 |
| CVE-2009-1219 EXP | Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allows remote attackers t… | Patch early | 5.0 medium | 8.7% | 2009-04-01 |
| CVE-2012-5913 EXP | Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject… | Patch early | 4.3 medium | 8.7% | 2012-11-17 |
| CVE-2010-1313 EXP | Directory traversal vulnerability in the Seber Cart (com_sebercart) component 1.0.0.12 and 1.0.0.13 for Joomla!, when magic_quotes_gpc is disabled, al… | Patch early | 4.3 medium | 8.7% | 2010-04-08 |
| CVE-2007-6333 EXP | The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBC… | Patch early | 5.8 medium | 8.7% | 2007-12-13 |
| CVE-2004-1897 EXP | Administration interface in Monit 1.4 through 4.2 allows remote attackers to cause a denial of service (segmentation fault) by sending a Basic Authent… | Patch early | 5.0 medium | 8.7% | 2004-12-31 |
| CVE-2004-2116 EXP | Directory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a .. (dot dot) in the URL. | Patch early | 5.0 medium | 8.7% | 2004-12-31 |
| CVE-2009-4413 EXP | The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remote attackers to cause a denial… | Patch early | 5.0 medium | 8.7% | 2009-12-24 |
| CVE-2009-1684 EXP | Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2… | Patch early | 4.3 medium | 8.7% | 2009-06-10 |
| CVE-2001-0852 EXP | TUX HTTP server 2.1.0-2 in Red Hat Linux allows remote attackers to cause a denial of service via a long Host: header. | Patch early | 5.0 medium | 8.7% | 2001-12-06 |
| CVE-2006-2024 EXP | Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors… | Patch early | 4.0 medium | 8.7% | 2006-04-25 |
| CVE-2009-0177 EXP | vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6.5.1 build 126130, 6.5.1 and earlier; VMware Player… | Patch early | 5.0 medium | 8.6% | 2009-01-20 |
| CVE-2005-1112 EXP | IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code… | Patch early | 5.0 medium | 8.6% | 2005-05-02 |
| CVE-2018-10751 EXP | A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml p… | Patch early | 5.3 medium | 8.6% | 2018-05-29 |
| CVE-2008-0418 EXP | Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addon… | Patch early | 4.3 medium | 8.6% | 2008-02-08 |
| CVE-2012-6708 EXP | jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a… | Patch early | 6.1 medium | 8.6% | 2018-01-18 |
| CVE-2009-2620 EXP | src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote at… | Patch early | 5.0 medium | 8.6% | 2009-07-29 |
| CVE-1999-0060 EXP | Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Conf… | Patch early | 5.0 medium | 8.6% | 1998-03-16 |
| CVE-2008-3432 EXP | Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and 6.3 allows user-assisted attackers to execute arbitrary co… | Patch early | 6.8 medium | 8.6% | 2008-10-10 |
| CVE-2023-33145 EXP | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Patch early | 6.5 medium | 8.6% | 2023-06-14 |
| CVE-2011-4715 EXP | Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlier allows r… | Patch early | 5.0 medium | 8.6% | 2011-12-08 |
| CVE-2010-3039 EXP | /usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated… | Patch early | 6.8 medium | 8.6% | 2010-11-09 |
| CVE-2010-2307 EXP | Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHP… | Patch early | 5.0 medium | 8.6% | 2010-06-16 |
| CVE-2000-0977 EXP | mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" paramet… | Patch early | 5.0 medium | 8.6% | 2000-12-19 |
| CVE-2007-0817 EXP | Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Ag… | Patch early | 4.3 medium | 8.6% | 2007-02-07 |
| CVE-2005-4559 EXP | mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly ini… | Patch early | 5.0 medium | 8.6% | 2005-12-28 |
| CVE-2007-2482 EXP | Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allo… | Patch early | 6.8 medium | 8.6% | 2007-05-03 |
| CVE-2008-4323 EXP | Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application crash) via a crafted .ZIP file. | Patch early | 4.3 medium | 8.6% | 2008-09-29 |
| CVE-2016-3963 EXP | Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 443. | Patch early | 5.3 medium | 8.6% | 2016-04-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt