CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,486 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
205,888 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-40032 EXP | SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execu… | Patch early | 9.8 critical | 20.7% | 2023-02-17 |
| CVE-2000-0073 EXP | Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word. | Patch early | 5.0 medium | 20.7% | 1999-11-17 |
| CVE-2006-2914 EXP | PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote attackers to execute arbitrary code via a URL in the templatefolder parameter t… | Patch early | 5.1 medium | 20.7% | 2006-06-23 |
| CVE-2018-6481 EXP | A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending… | Patch early | 9.8 critical | 20.7% | 2018-02-27 |
| CVE-2000-0105 EXP | Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that refe… | Patch early | 5.0 medium | 20.7% | 2000-02-01 |
| CVE-2019-0186 EXP | The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Unin… | Patch early | 6.1 medium | 20.6% | 2019-04-26 |
| CVE-2000-0983 EXP | Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null… | Patch early | 5.0 medium | 20.6% | 2000-12-19 |
| CVE-2014-9734 EXP | Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to read arbitrary files… | Patch early | 5.0 medium | 20.6% | 2015-06-30 |
| CVE-2015-6018 EXP | The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary comm… | Patch early | 9.8 critical | 20.6% | 2015-12-31 |
| CVE-2019-14312 EXP | Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer. This vulnerability allows a remote a… | Patch early | 6.5 medium | 20.6% | 2019-08-09 |
| CVE-2015-4664 EXP | An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands. | Patch early | 9.8 critical | 20.6% | 2018-06-18 |
| CVE-2011-1930 EXP | In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker t… | Patch early | 9.8 critical | 20.5% | 2019-11-14 |
| CVE-2002-2031 EXP | Internet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to determine the existence of arbitrary files via a scr… | Patch early | 5.0 medium | 20.5% | 2002-12-31 |
| CVE-2019-14348 EXP | The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-york… | Patch early | 9.8 critical | 20.5% | 2019-08-05 |
| CVE-2008-2949 EXP | Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change the location property of a frame via the String da… | Patch early | 6.8 medium | 20.5% | 2008-06-30 |
| CVE-2000-0676 EXP | Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a… | Patch early | 5.0 medium | 20.5% | 2000-10-20 |
| CVE-2008-0237 EXP | The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure Sav… | Patch early | 6.8 medium | 20.5% | 2008-01-11 |
| CVE-1999-0681 EXP | Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause… | Patch early | 5.0 medium | 20.5% | 2001-03-12 |
| CVE-2024-38200 EXP | Microsoft Office Spoofing Vulnerability | Patch early | 6.5 medium | 20.5% | 2024-08-12 |
| CVE-2016-4071 EXP | Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows r… | Patch early | 9.8 critical | 20.5% | 2016-05-20 |
| CVE-2016-3717 EXP | The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image. | Patch early | 5.5 medium | 20.4% | 2016-05-05 |
| CVE-2013-1451 EXP | Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, doe… | Patch early | 4.0 medium | 20.4% | 2013-01-29 |
| CVE-2010-0740 EXP | The ssl3_get_record function in ssl/s3_pkt.c in OpenSSL 0.9.8f through 0.9.8m allows remote attackers to cause a denial of service (crash) via a malfo… | Patch early | 5.0 medium | 20.4% | 2010-03-26 |
| CVE-2022-31125 EXP | Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauth… | Patch early | 10.0 critical | 20.3% | 2022-07-06 |
| CVE-2014-5258 EXP | Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitrary files… | Patch early | 4.0 medium | 20.3% | 2014-11-06 |
| CVE-2004-0791 EXP | Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a… | Patch early | 5.0 medium | 20.3% | 2005-04-12 |
| CVE-2021-27828 EXP | SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavi… | Patch early | 9.1 critical | 20.3% | 2021-06-01 |
| CVE-2008-6825 EXP | Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to include and execute arbitrary… | Patch early | 6.8 medium | 20.3% | 2009-06-05 |
| CVE-2005-1381 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) ca… | Patch early | 6.8 medium | 20.2% | 2005-05-03 |
| CVE-2018-13416 EXP | In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) att… | Patch early | 9.8 critical | 20.2% | 2018-08-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt