CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,584 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
205,911 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-6554 EXP | functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute arbitrary PHP code via the me… | Patch early | 6.5 medium | 16.7% | 2013-05-23 |
| CVE-2010-1494 EXP | Directory traversal vulnerability in the AWDwall (com_awdwall) component 1.5.4 for Joomla! allows remote attackers to read arbitrary files via a .. (d… | Patch early | 5.0 medium | 16.7% | 2010-04-23 |
| CVE-2003-1275 EXP | Pocket Internet Explorer (PIE) 3.0 allows remote attackers to cause a denial of service (crash) via a Javascript function that uses the object.innerHT… | Patch early | 5.0 medium | 16.7% | 2003-12-31 |
| CVE-2005-1476 EXP | Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a pre… | Patch early | 5.1 medium | 16.7% | 2005-05-09 |
| CVE-2017-6182 EXP | In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command… | Patch early | 9.8 critical | 16.7% | 2017-03-30 |
| CVE-2018-15140 EXP | Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal t… | Patch early | 6.5 medium | 16.7% | 2018-08-13 |
| CVE-2012-3748 EXP | Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary code or cause a denial of serv… | Patch early | 5.1 medium | 16.7% | 2012-11-03 |
| CVE-2018-1042 EXP | Moodle 3.x has Server Side Request Forgery in the filepicker. | Patch early | 6.5 medium | 16.7% | 2018-01-22 |
| CVE-2020-15492 EXP | An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP p… | Patch early | 9.8 critical | 16.6% | 2020-07-23 |
| CVE-2017-6315 EXP | Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx. | Patch early | 9.8 critical | 16.6% | 2017-09-19 |
| CVE-2003-0128 EXP | The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of servi… | Patch early | 5.0 medium | 16.5% | 2003-03-24 |
| CVE-2008-4764 EXP | Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary f… | Patch early | 5.0 medium | 16.5% | 2008-10-28 |
| CVE-2010-3886 EXP | The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for th… | Patch early | 4.3 medium | 16.5% | 2010-10-08 |
| CVE-2017-8051 EXP | Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of t… | Patch early | 9.8 critical | 16.5% | 2017-04-21 |
| CVE-2003-0009 EXP | Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in th… | Patch early | 6.8 medium | 16.5% | 2003-03-07 |
| CVE-2006-2661 EXP | ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference. | Patch early | 5.0 medium | 16.5% | 2006-05-30 |
| CVE-2018-13784 EXP | PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php. | Patch early | 9.1 critical | 16.5% | 2018-07-09 |
| CVE-2018-18761 EXP | SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection. | Patch early | 9.8 critical | 16.5% | 2018-11-16 |
| CVE-2006-4889 EXP | Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled, allow remote… | Patch early | 5.1 medium | 16.4% | 2006-09-19 |
| CVE-2021-25161 EXP | A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x:… | Patch early | 6.1 medium | 16.4% | 2021-03-30 |
| CVE-2007-4890 EXP | Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1.0.0.0 in Microsoft Visual Stu… | Patch early | 5.8 medium | 16.4% | 2007-09-14 |
| CVE-2025-20125 EXP | A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information,… | Patch early | 9.1 critical | 16.4% | 2025-02-05 |
| CVE-2010-1532 EXP | Directory traversal vulnerability in the givesight PowerMail Pro (com_powermail) component 1.5.3 for Joomla! allows remote attackers to read arbitrary… | Patch early | 5.0 medium | 16.3% | 2010-04-26 |
| CVE-2009-1217 EXP | Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers to cause a denial of service (… | Patch early | 4.3 medium | 16.3% | 2009-04-01 |
| CVE-2005-4717 EXP | Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote at… | Patch early | 5.0 medium | 16.3% | 2005-12-31 |
| CVE-2015-5065 EXP | Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic For WooCommerce plugin before… | Patch early | 5.0 medium | 16.3% | 2015-06-24 |
| CVE-2000-0580 EXP | Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros to various TCP and UDP ports,… | Patch early | 5.0 medium | 16.3% | 2000-06-30 |
| CVE-2008-2005 EXP | The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to caus… | Patch early | 5.0 medium | 16.3% | 2008-05-06 |
| CVE-2013-3166 EXP | Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 16.3% | 2013-07-10 |
| CVE-2007-2718 EXP | Cross-site scripting (XSS) vulnerability in the WebMail system in Stalker CommuniGate Pro 5.1.8 and earlier, when using Microsoft Internet Explorer, a… | Patch early | 4.3 medium | 16.3% | 2007-05-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt