CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,486 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
205,888 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-0502 EXP | Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the original message,… | Patch early | 5.0 medium | 20.2% | 2004-08-18 |
| CVE-2005-3559 EXP | Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) in… | Patch early | 5.0 medium | 20.2% | 2005-11-16 |
| CVE-2018-5973 EXP | SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, or the suppliers.php IndustryI… | Patch early | 9.8 critical | 20.1% | 2018-01-25 |
| CVE-2015-6908 EXP | The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable ass… | Patch early | 5.0 medium | 20% | 2015-09-11 |
| CVE-2004-2383 EXP | Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from othe… | Patch early | 5.1 medium | 20% | 2004-12-31 |
| CVE-2017-4901 EXP | The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory acce… | Patch early | 9.9 critical | 19.9% | 2017-06-08 |
| CVE-1999-0107 EXP | Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a lar… | Patch early | 5.0 medium | 19.9% | 1997-12-30 |
| CVE-2018-1322 EXP | An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x whi… | Patch early | 4.9 medium | 19.9% | 2018-03-20 |
| CVE-2019-9791 EXP | The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMo… | Patch early | 9.8 critical | 19.9% | 2019-04-26 |
| CVE-2019-19742 EXP | On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field. | Patch early | 4.8 medium | 19.8% | 2019-12-18 |
| CVE-2005-3207 EXP | The forms servlet (f90servlet) in Oracle Forms 4.5.10.22 allows remote attackers to cause a denial of service (TNS listener stop) via a userid paramet… | Patch early | 5.0 medium | 19.8% | 2005-10-14 |
| CVE-2007-1399 EXP | Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to e… | Patch early | 9.8 critical | 19.8% | 2007-03-10 |
| CVE-2015-4148 EXP | The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property i… | Patch early | 5.0 medium | 19.8% | 2015-06-09 |
| CVE-2021-43617 EXP | Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttr… | Patch early | 9.8 critical | 19.8% | 2021-11-14 |
| CVE-2014-8768 EXP | Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denia… | Patch early | 5.0 medium | 19.8% | 2014-11-20 |
| CVE-2018-5726 EXP | MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to obtain sensitive information via a crafted HTTP request, as demonstrated by the usernam… | Patch early | 9.8 critical | 19.8% | 2018-01-16 |
| CVE-2018-4934 EXP | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to informa… | Patch early | 6.5 medium | 19.8% | 2018-05-19 |
| CVE-2020-24215 EXP | An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP re… | Patch early | 9.8 critical | 19.8% | 2020-10-06 |
| CVE-2011-2202 EXP | The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, whi… | Patch early | 6.4 medium | 19.7% | 2011-06-16 |
| CVE-2007-0247 EXP | squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing respo… | Patch early | 5.0 medium | 19.7% | 2007-01-16 |
| CVE-2019-8049 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 19.7% | 2019-08-20 |
| CVE-2016-6175 EXP | Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header… | Patch early | 9.8 critical | 19.7% | 2017-02-07 |
| CVE-2013-2679 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitr… | Patch early | 6.1 medium | 19.6% | 2020-02-18 |
| CVE-2019-8385 EXP | An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and local file inclusion vulnerability… | Patch early | 9.8 critical | 19.6% | 2019-06-05 |
| CVE-2013-7240 EXP | Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary fi… | Patch early | 5.0 medium | 19.6% | 2014-01-03 |
| CVE-2016-0951 EXP | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a… | Patch early | 9.8 critical | 19.6% | 2016-02-10 |
| CVE-2016-0952 EXP | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a… | Patch early | 9.8 critical | 19.6% | 2016-02-10 |
| CVE-2016-0953 EXP | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a… | Patch early | 9.8 critical | 19.6% | 2016-02-10 |
| CVE-2004-1306 EXP | Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers t… | Patch early | 5.1 medium | 19.6% | 2004-12-31 |
| CVE-2000-0168 EXP | Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Dev… | Patch early | 5.0 medium | 19.6% | 2000-03-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt