CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,152 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
169,595 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-4493 EXP | Orion Application Server 2.0.7 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a w… | Patch early | 5.0 medium | 7% | 2010-01-13 |
| CVE-2007-0643 EXP | Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of service (application crash) and po… | Patch early | 4.3 medium | 7% | 2007-01-31 |
| CVE-2013-0143 EXP | cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authent… | Patch early | 6.5 medium | 7% | 2013-06-07 |
| CVE-1999-0931 EXP | Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands. | Patch early | 5.0 medium | 7% | 1999-09-30 |
| CVE-2004-2719 EXP | Buffer overflow in the UrlToLocal function in PunyLib.dll of Foxmail 5.0.300 allows remote attackers to execute arbitrary code via a mail message with… | Patch early | 6.8 medium | 7% | 2004-12-31 |
| CVE-2006-1929 EXP | PHP remote file inclusion vulnerability in include/common.php in I-Rater Platinum allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 5.0 medium | 7% | 2006-04-20 |
| CVE-2017-2363 EXP | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. wa… | Patch early | 6.5 medium | 7% | 2017-02-20 |
| CVE-2003-1548 EXP | MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other parameter, which reveals the i… | Patch early | 5.0 medium | 7% | 2003-12-31 |
| CVE-2002-1501 EXP | The MPS functionality in Enterasys SSR8000 (Smart Switch Router) before firmware 8.3.0.10 allows remote attackers to cause a denial of service (crash)… | Patch early | 5.0 medium | 7% | 2003-04-02 |
| CVE-2015-7896 EXP | LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via… | Patch early | 6.5 medium | 7% | 2017-08-24 |
| CVE-2007-6113 EXP | Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) 0.10.12 to 0.99.6 allows remote attackers to cause a denial of service… | Patch early | 4.3 medium | 7% | 2007-11-23 |
| CVE-2007-2249 EXP | include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_ids POST par… | Patch early | 6.5 medium | 7% | 2007-04-25 |
| CVE-2016-1838 EXP | The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and… | Patch early | 5.5 medium | 6.9% | 2016-05-20 |
| CVE-2014-1637 EXP | Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which allows remote attackers to down… | Patch early | 5.0 medium | 6.9% | 2014-01-22 |
| CVE-2013-2171 EXP | The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEASE-p4 does not properly determi… | Patch early | 6.9 medium | 6.9% | 2013-07-02 |
| CVE-2005-2813 EXP | Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00"… | Patch early | 5.0 medium | 6.9% | 2005-09-07 |
| CVE-2000-0571 EXP | LocalWEB HTTP server 1.2.0 allows remote attackers to cause a denial of service via a long GET request. | Patch early | 6.4 medium | 6.9% | 2000-07-05 |
| CVE-2008-4194 EXP | The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of service (daemon crash) via a long… | Patch early | 5.0 medium | 6.9% | 2008-09-24 |
| CVE-2008-6793 EXP | The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute arbitrary commands via shell met… | Patch early | 6.8 medium | 6.9% | 2009-05-07 |
| CVE-2011-3713 EXP | cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error… | Patch early | 5.0 medium | 6.9% | 2011-09-23 |
| CVE-2005-4799 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow remote attackers to inject arbitr… | Patch early | 5.1 medium | 6.9% | 2005-12-31 |
| CVE-2004-0242 EXP | X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command. | Patch early | 5.0 medium | 6.9% | 2004-11-23 |
| CVE-2002-1828 EXP | Savant Webserver 3.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request with a negative Content-Length value. | Patch early | 5.0 medium | 6.9% | 2002-12-31 |
| CVE-2005-0788 EXP | LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request. | Patch early | 5.0 medium | 6.9% | 2005-03-14 |
| CVE-2006-0319 EXP | Directory traversal vulnerability in the FTP server (port 22003/tcp) in Farmers WIFE 4.4 SP1 allows remote attackers to create arbitrary files via "..… | Patch early | 5.0 medium | 6.9% | 2006-01-19 |
| CVE-2006-3556 EXP | PHP remote file inclusion vulnerability in extcalendar.php in Mohamed Moujami ExtCalendar 2.0 allows remote attackers to execute arbitrary PHP code vi… | Patch early | 6.8 medium | 6.9% | 2006-07-13 |
| CVE-2018-5715 EXP | phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable). | Patch early | 6.1 medium | 6.9% | 2018-01-16 |
| CVE-2018-4240 EXP | An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchO… | Patch early | 6.5 medium | 6.9% | 2018-06-08 |
| CVE-2000-0780 EXP | The web server in IPSWITCH IMail 6.04 and earlier allows remote attackers to read and delete arbitrary files via a .. (dot dot) attack. | Patch early | 6.4 medium | 6.9% | 2000-10-20 |
| CVE-2016-1594 EXP | Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as dem… | Patch early | 6.5 medium | 6.9% | 2016-04-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt