CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,986 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
206,131 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-14335 EXP | An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of th… | Patch early | 6.5 medium | 13.2% | 2018-07-24 |
| CVE-2018-7921 EXP | Huawei B315s-22 products with software of 21.318.01.00.26 have an information leak vulnerability. Unauthenticated adjacent attackers may exploit this… | Patch early | 6.5 medium | 13.2% | 2018-09-12 |
| CVE-2002-1542 EXP | SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a… | Patch early | 5.0 medium | 13.2% | 2003-03-31 |
| CVE-2019-9792 EXP | The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value c… | Patch early | 9.8 critical | 13.2% | 2019-04-26 |
| CVE-2011-1471 EXP | Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (CPU… | Patch early | 4.3 medium | 13.2% | 2011-03-20 |
| CVE-2005-2710 EXP | Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) ti… | Patch early | 5.1 medium | 13.2% | 2005-09-27 |
| CVE-2012-5614 EXP | Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a… | Patch early | 4.0 medium | 13.2% | 2012-12-03 |
| CVE-2008-2952 EXP | liblber/io.c in OpenLDAP 2.2.4 to 2.4.10 allows remote attackers to cause a denial of service (program termination) via crafted ASN.1 BER datagrams th… | Patch early | 5.0 medium | 13.2% | 2008-07-01 |
| CVE-2016-8527 EXP | Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). The vulnerability is present in… | Patch early | 6.1 medium | 13.2% | 2018-08-06 |
| CVE-2006-4965 EXP | Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTi… | Patch early | 5.0 medium | 13.1% | 2006-09-25 |
| CVE-2008-0153 EXP | telnetd.exe in Pragma TelnetServer 7.0.4.589 allows remote attackers to cause a denial of service (process crash and resource exhaustion) via a crafte… | Patch early | 5.0 medium | 13.1% | 2008-01-09 |
| CVE-2013-4982 EXP | AVTECH AVN801 DVR has a security bypass via the administration login captcha | Patch early | 9.8 critical | 13.1% | 2019-12-27 |
| CVE-1999-0981 EXP | Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local fi… | Patch early | 5.1 medium | 13.1% | 1999-12-08 |
| CVE-2007-2926 EXP | ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY… | Patch early | 4.3 medium | 13.1% | 2007-07-24 |
| CVE-2013-2748 EXP | Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system. | Patch early | 9.8 critical | 13.1% | 2020-01-28 |
| CVE-2016-0049 EXP | Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows… | Patch early | 6.2 medium | 13.1% | 2016-02-10 |
| CVE-2021-20031 EXP | A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains… | Patch early | 6.1 medium | 13% | 2021-10-12 |
| CVE-2006-2860 EXP | PHP remote file inclusion vulnerability in Webspotblogging 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter… | Patch early | 6.4 medium | 13% | 2006-06-06 |
| CVE-2015-1365 EXP | Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to write to arbi… | Patch early | 5.0 medium | 13% | 2015-01-27 |
| CVE-2019-4013 EXP | IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code… | Patch early | 9.0 critical | 13% | 2019-04-10 |
| CVE-2006-3581 EXP | Multiple stack-based buffer overflows in Audacious AdPlug 2.0 and earlier allow remote user-assisted attackers to execute arbitrary code via large (1)… | Patch early | 5.1 medium | 13% | 2006-07-13 |
| CVE-2009-4488 EXP | Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or… | Patch early | 9.8 critical | 13% | 2010-01-13 |
| CVE-2017-8871 EXP | The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and C… | Patch early | 6.5 medium | 13% | 2017-06-12 |
| CVE-2002-0289 EXP | Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP request. | Patch early | 5.0 medium | 13% | 2002-05-31 |
| CVE-2011-2780 EXP | Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) i… | Patch early | 5.0 medium | 13% | 2011-07-19 |
| CVE-2017-7462 EXP | Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory. | Patch early | 9.8 critical | 13% | 2017-04-11 |
| CVE-2012-3571 EXP | ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) vi… | Patch early | 6.1 medium | 13% | 2012-07-25 |
| CVE-2013-4117 EXP | Cross-site scripting (XSS) vulnerability in includes/CatGridPost.php in the Category Grid View Gallery plugin 2.3.1 for WordPress allows remote attack… | Patch early | 4.3 medium | 13% | 2013-07-16 |
| CVE-2006-6863 EXP | PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote attackers to execute arbitrary PH… | Patch early | 9.8 critical | 13% | 2006-12-31 |
| CVE-2019-15039 EXP | An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1. | Patch early | 9.8 critical | 12.9% | 2019-10-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt