CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,584 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
318,532 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-1978 EXP | COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code… | Patch early | 7.5 high | 53.4% | 2005-10-12 |
| CVE-2005-2847 EXP | img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary commands via shell metacharacters in… | Patch early | 7.5 high | 53.4% | 2005-09-08 |
| CVE-2006-6761 EXP | Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code… | Patch early | 6.5 medium | 53.4% | 2006-12-27 |
| CVE-2014-9118 EXP | The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters… | Patch early | 8.8 high | 53.4% | 2017-10-17 |
| CVE-2014-0644 EXP | EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external e… | Patch early | 7.8 high | 53.3% | 2014-04-17 |
| CVE-1999-0502 EXP | A Unix account has a default, null, blank, or missing password. | Patch early | 7.5 high | 53.3% | 1998-03-01 |
| CVE-2015-7007 EXP | Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement for AppleScript execution via u… | Patch early | 7.5 high | 53.3% | 2015-10-23 |
| CVE-2018-4233 EXP | An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affe… | Patch early | 8.8 high | 53.3% | 2018-06-08 |
| CVE-2006-2502 EXP | Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute… | Patch early | 5.1 medium | 53.3% | 2006-05-22 |
| CVE-2022-33098 EXP | Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows att… | Patch early | 6.1 medium | 53.3% | 2022-07-07 |
| CVE-2006-5702 EXP | Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-list… | Patch early | 5.0 medium | 53.3% | 2006-11-04 |
| CVE-1999-0191 EXP | IIS newdsn.exe CGI script allows remote users to overwrite files. | Patch early | 6.4 medium | 53.3% | 1997-09-01 |
| CVE-2009-0043 EXP | The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, which a… | Patch early | 10.0 high | 53.3% | 2009-01-08 |
| CVE-2008-3922 EXP | awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which… | Patch early | 9.3 high | 53.2% | 2008-09-04 |
| CVE-2010-0248 EXP | Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by… | Patch early | 8.1 high | 53.1% | 2010-01-22 |
| CVE-2018-0840 EXP | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Exp… | Patch early | 7.5 high | 53.1% | 2018-02-15 |
| CVE-2009-1955 EXP | The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in th… | Patch early | 7.5 high | 53% | 2009-06-08 |
| CVE-2007-5099 EXP | PHP remote file inclusion vulnerability in show.php in David Watters Helplink 0.1.0 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 53% | 2007-09-26 |
| CVE-2023-24078 EXP | Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/. | Patch early | 8.8 high | 53% | 2023-02-17 |
| CVE-2016-7434 EXP | The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query. | Patch early | 7.5 high | 52.9% | 2017-01-13 |
| CVE-2021-41381 EXP | Payara Micro Community 5.2021.6 and below allows Directory Traversal. | Patch early | 7.5 high | 52.9% | 2021-09-23 |
| CVE-2007-5348 EXP | Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Offic… | Patch early | 9.3 high | 52.9% | 2008-09-11 |
| CVE-2005-3589 EXP | Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal crash) via a long USER ftp comma… | Patch early | 7.8 high | 52.9% | 2005-11-16 |
| CVE-2001-0538 EXP | Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTM… | Patch early | 10.0 high | 52.9% | 2001-08-14 |
| CVE-2009-3591 EXP | Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with an invalid location. | Patch early | 5.0 medium | 52.8% | 2009-10-08 |
| CVE-2014-1903 EXP | admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not… | Patch early | 7.5 high | 52.8% | 2014-02-18 |
| CVE-2007-4921 EXP | PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attackers to execute arbitrary PHP cod… | Patch early | 7.5 high | 52.8% | 2007-09-17 |
| CVE-2000-0457 EXP | ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) a… | Patch early | 7.5 high | 52.8% | 2000-05-11 |
| CVE-2018-7286 EXP | An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjs… | Patch early | 6.5 medium | 52.7% | 2018-02-22 |
| CVE-2022-31470 EXP | An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 a… | Patch early | 6.1 medium | 52.7% | 2022-06-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt