CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,810 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
206,044 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-6176 EXP | Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism… | Patch early | 4.3 medium | 14% | 2015-12-09 |
| CVE-2010-1308 EXP | Directory traversal vulnerability in the SVMap (com_svmap) component 1.1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot d… | Patch early | 5.0 medium | 14% | 2010-04-08 |
| CVE-2006-2557 EXP | PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newsportal (TRanx rebuilded), allows… | Patch early | 6.4 medium | 14% | 2006-05-24 |
| CVE-2008-5551 EXP | The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by inj… | Patch early | 4.3 medium | 14% | 2008-12-12 |
| CVE-2010-1659 EXP | Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote attackers to read arbitrar… | Patch early | 5.0 medium | 14% | 2010-05-03 |
| CVE-2000-1112 EXP | Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that c… | Patch early | 4.6 medium | 14% | 2001-01-09 |
| CVE-2018-7702 EXP | SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e-mail messages to arbitrary re… | Patch early | 9.1 critical | 14% | 2018-03-15 |
| CVE-2007-4965 EXP | Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (applicati… | Patch early | 5.8 medium | 14% | 2007-09-18 |
| CVE-2021-24286 EXP | The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, l… | Patch early | 6.1 medium | 13.9% | 2021-05-14 |
| CVE-2013-3526 EXP | Cross-site scripting (XSS) vulnerability in js/ta_loaded.js.php in the Traffic Analyzer plugin, possibly 3.3.2 and earlier, for WordPress allows remot… | Patch early | 4.3 medium | 13.9% | 2013-05-10 |
| CVE-2008-1933 EXP | Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to overwrite arbitrary files via the… | Patch early | 4.3 medium | 13.9% | 2008-04-25 |
| CVE-2008-2666 EXP | Multiple directory traversal vulnerabilities in PHP 5.2.6 and earlier allow context-dependent attackers to bypass safe_mode restrictions by creating a… | Patch early | 5.0 medium | 13.9% | 2008-06-20 |
| CVE-2005-1275 EXP | Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of servic… | Patch early | 5.0 medium | 13.9% | 2005-04-25 |
| CVE-2013-4659 EXP | Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on route… | Patch early | 9.8 critical | 13.9% | 2017-03-14 |
| CVE-2024-28999 EXP | The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console. | Patch early | 6.4 medium | 13.9% | 2024-06-04 |
| CVE-2006-1985 EXP | Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to exe… | Patch early | 5.1 medium | 13.9% | 2006-04-21 |
| CVE-2019-3810 EXP | A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did n… | Patch early | 6.1 medium | 13.9% | 2019-03-25 |
| CVE-2015-7874 EXP | Buffer overflow in the chat server in KiTTY Portable 0.65.0.2p and earlier allows remote attackers to execute arbitrary code via a long nickname. | Patch early | 9.8 critical | 13.9% | 2020-01-15 |
| CVE-2005-3077 EXP | Microsoft Internet Explorer 5.2.3 for Mac OS allows remote attackers to cause a denial of service (crash) via a web page with malformed attributes in… | Patch early | 5.0 medium | 13.9% | 2005-09-27 |
| CVE-2006-5536 EXP | Directory traversal vulnerability in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to read arbitrary fil… | Patch early | 5.0 medium | 13.9% | 2006-10-26 |
| CVE-2013-6127 EXP | The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict Rep… | Patch early | 5.8 medium | 13.9% | 2013-10-25 |
| CVE-2018-12463 EXP | An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to… | Patch early | 9.8 critical | 13.8% | 2018-07-12 |
| CVE-2007-1562 EXP | The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to ot… | Patch early | 6.8 medium | 13.8% | 2007-03-21 |
| CVE-2017-18001 EXP | Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys dat… | Patch early | 9.8 critical | 13.8% | 2017-12-31 |
| CVE-2019-8660 EXP | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3.… | Patch early | 9.8 critical | 13.8% | 2019-12-18 |
| CVE-2006-1510 EXP | Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 a… | Patch early | 4.0 medium | 13.8% | 2006-03-30 |
| CVE-2021-33216 EXP | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer… | Patch early | 9.8 critical | 13.8% | 2021-07-07 |
| CVE-2022-23409 EXP | The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php. | Patch early | 4.9 medium | 13.8% | 2022-01-31 |
| CVE-2012-5321 EXP | tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks… | Patch early | 5.8 medium | 13.8% | 2012-10-08 |
| CVE-2009-1902 EXP | The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request… | Patch early | 5.0 medium | 13.7% | 2009-06-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt