CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,049 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
169,548 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-2850 EXP | SlimFTPd 3.17 allows remote attackers to cause a denial of service (crash) via certain (1) USER and (2) PASS commands, possibly due to a buffer overfl… | Patch early | 5.0 medium | 7.2% | 2005-09-08 |
| CVE-2015-1578 EXP | Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing atta… | Patch early | 5.8 medium | 7.2% | 2015-02-11 |
| CVE-2018-5333 EXP | In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an invalid address is… | Patch early | 5.5 medium | 7.2% | 2018-01-11 |
| CVE-2007-6314 EXP | BarracudaDrive Web Server before 3.8 allows remote attackers to read the source code for web scripts by appending a (1) + (plus), (2) . (dot), or (3)… | Patch early | 5.0 medium | 7.2% | 2007-12-12 |
| CVE-2006-2481 EXP | VMware ESX Server 2.0.x before 2.0.2 and 2.x before 2.5.2 patch 4 stores authentication credentials in base 64 encoded format in the vmware.mui.kid an… | Patch early | 5.0 medium | 7.2% | 2006-07-31 |
| CVE-2008-0071 EXP | The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause a denial o… | Patch early | 4.3 medium | 7.2% | 2008-06-16 |
| CVE-2006-3074 EXP | klif.sys in Kaspersky Internet Security 6.0 and 7.0, Kaspersky Anti-Virus (KAV) 6.0 and 7.0, KAV 6.0 for Windows Workstations, and KAV 6.0 for Windows… | Patch early | 5.0 medium | 7.2% | 2006-06-19 |
| CVE-2009-1357 EXP | CRLF injection vulnerability in da/DA/Login in Sun Java System Delegated Administrator 6.2 through 6.4 allows remote attackers to inject arbitrary HTT… | Patch early | 6.8 medium | 7.2% | 2009-04-23 |
| CVE-2009-1496 EXP | Directory traversal vulnerability in the Cmi Marketplace (com_cmimarketplace) component 0.1 for Joomla! allows remote attackers to list arbitrary dire… | Patch early | 5.0 medium | 7.2% | 2009-05-01 |
| CVE-2006-6797 EXP | The Client Server Run-Time Subsystem (CSRSS) in Microsoft Windows allows local users to cause a denial of service (crash) or read arbitrary memory fro… | Patch early | 6.6 medium | 7.2% | 2006-12-28 |
| CVE-2015-6402 EXP | Cross-site scripting (XSS) vulnerability in the management interface on Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allows remote attack… | Patch early | 4.3 medium | 7.2% | 2015-12-14 |
| CVE-2005-2577 EXP | Wyse Winterm 1125SE running firmware 4.2.09f or 4.4.061f allows remote attackers to cause a denial of service (device crash) via a packet with a zero… | Patch early | 5.0 medium | 7.2% | 2005-08-16 |
| CVE-2006-1103 EXP | engine/server.cpp in Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (segmentation fault… | Patch early | 5.0 medium | 7.2% | 2006-03-09 |
| CVE-2004-1678 EXP | Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary… | Patch early | 5.0 medium | 7.2% | 2004-09-13 |
| CVE-2004-1742 EXP | Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a .. (dot dot) in the viewcat parameter. | Patch early | 5.0 medium | 7.2% | 2004-08-24 |
| CVE-2003-1239 EXP | Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in the album par… | Patch early | 5.0 medium | 7.2% | 2003-12-31 |
| CVE-2003-1176 EXP | post_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or write to private forums by modif… | Patch early | 6.4 medium | 7.2% | 2003-12-31 |
| CVE-2010-4055 EXP | Stack consumption vulnerability in solid.exe in IBM solidDB 6.5.0.3 and earlier allows remote attackers to cause a denial of service (memory consumpti… | Patch early | 5.0 medium | 7.2% | 2010-10-23 |
| CVE-2010-4057 EXP | solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing ma… | Patch early | 5.0 medium | 7.2% | 2010-10-23 |
| CVE-2014-9350 EXP | TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attackers to cause a denial of servi… | Patch early | 5.0 medium | 7.2% | 2014-12-08 |
| CVE-2012-4939 EXP | Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance… | Patch early | 4.3 medium | 7.2% | 2012-10-31 |
| CVE-2002-0876 EXP | Web server for Shambala 4.5 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request. | Patch early | 5.0 medium | 7.2% | 2002-10-04 |
| CVE-2002-1322 EXP | Rational ClearCase 4.1, 2002.05, and possibly other versions allows remote attackers to cause a denial of service (crash) via certain packets to port… | Patch early | 5.0 medium | 7.2% | 2002-12-11 |
| CVE-1999-1109 EXP | Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, w… | Patch early | 5.0 medium | 7.2% | 1999-12-22 |
| CVE-2007-1897 EXP | SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQ… | Patch early | 6.5 medium | 7.2% | 2007-04-09 |
| CVE-2008-1769 EXP | VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via a crafted Cinepak file that triggers an out-of-bounds array access a… | Patch early | 6.8 medium | 7.2% | 2008-04-25 |
| CVE-2019-5392 EXP | A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | Patch early | 5.3 medium | 7.2% | 2019-06-05 |
| CVE-2012-5344 EXP | Directory traversal vulnerability in the WebServer (Thttpd.bat) in IpTools (aka Tiny TCP/IP server) 0.1.4 allows remote attackers to read arbitrary fi… | Patch early | 5.0 medium | 7.2% | 2012-10-09 |
| CVE-1999-1030 EXP | counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via an HTTP request that ends in %0A (newline), which causes a malformed… | Patch early | 5.0 medium | 7.1% | 1999-05-19 |
| CVE-1999-1519 EXP | Gene6 G6 FTP Server 2.0 allows a remote attacker to cause a denial of service (resource exhaustion) via a long (1) user name or (2) password. | Patch early | 5.0 medium | 7.1% | 1999-11-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt