CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,157 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
169,597 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-13980 EXP | The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser… | Patch early | 5.5 medium | 6.9% | 2018-07-16 |
| CVE-2006-0658 EXP | Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload an… | Patch early | 5.0 medium | 6.9% | 2006-02-13 |
| CVE-1999-0174 EXP | The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 6.4 medium | 6.9% | 1997-02-01 |
| CVE-2011-2201 EXP | The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of d… | Patch early | 4.3 medium | 6.9% | 2011-09-14 |
| CVE-2016-8017 EXP | Special element injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers… | Patch early | 4.1 medium | 6.9% | 2017-03-14 |
| CVE-2014-3975 EXP | Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via a full pathname in the viewdir… | Patch early | 5.0 medium | 6.9% | 2014-06-05 |
| CVE-2014-9436 EXP | Absolute path traversal vulnerability in SysAid On-Premise before 14.4.2 allows remote attackers to read arbitrary files via a \\\\ (four backslashes)… | Patch early | 5.0 medium | 6.9% | 2015-01-02 |
| CVE-2008-6280 EXP | Cross-site scripting (XSS) vulnerability in apply.cgi on the Linksys WRT160N allows remote attackers to inject arbitrary web script or HTML via the ac… | Patch early | 4.3 medium | 6.9% | 2009-02-25 |
| CVE-2012-0550 EXP | Unspecified vulnerability in the GlassFish Enterprise Server component in Oracle Sun Products Suite GlassFish Enterprise Server 3.1.1 allows remote at… | Patch early | 6.8 medium | 6.9% | 2012-05-03 |
| CVE-2008-4048 EXP | Heap-based buffer overflow in a certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remot… | Patch early | 6.8 medium | 6.9% | 2008-09-11 |
| CVE-2008-4729 EXP | Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Control 13.0 and earlier allows re… | Patch early | 6.8 medium | 6.9% | 2008-10-24 |
| CVE-2010-0315 EXP | WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a sp… | Patch early | 5.0 medium | 6.9% | 2010-01-14 |
| CVE-2006-4858 EXP | PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier component for Mambo allows remo… | Patch early | 6.8 medium | 6.9% | 2006-09-19 |
| CVE-2010-0166 EXP | The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when t… | Patch early | 5.1 medium | 6.9% | 2010-03-25 |
| CVE-2013-4093 EXP | The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to obtain sensitive information vi… | Patch early | 5.0 medium | 6.9% | 2013-06-28 |
| CVE-2005-0731 EXP | PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to Fi… | Patch early | 5.0 medium | 6.9% | 2005-03-10 |
| CVE-2004-1381 EXP | Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported… | Patch early | 5.0 medium | 6.9% | 2004-10-20 |
| CVE-2014-8604 EXP | The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which a… | Patch early | 5.0 medium | 6.9% | 2015-06-10 |
| CVE-2014-8605 EXP | The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient… | Patch early | 5.0 medium | 6.9% | 2015-06-10 |
| CVE-2016-0075 EXP | The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain p… | Patch early | 5.5 medium | 6.9% | 2016-10-14 |
| CVE-2016-5309 EXP | The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud;… | Patch early | 5.5 medium | 6.9% | 2017-04-14 |
| CVE-2006-6808 EXP | Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 6.8 medium | 6.9% | 2006-12-28 |
| CVE-2000-0396 EXP | The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to… | Patch early | 5.0 medium | 6.9% | 2000-05-24 |
| CVE-2008-3667 EXP | Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTTP header. | Patch early | 6.8 medium | 6.9% | 2008-08-13 |
| CVE-2010-4437 EXP | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.4, 10.0.2, 10.3.2, and 10.3.3 allows remot… | Patch early | 5.8 medium | 6.9% | 2011-01-19 |
| CVE-2017-6192 EXP | Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arbitrary code via a crafted imag… | Patch early | 5.5 medium | 6.9% | 2018-02-20 |
| CVE-1999-0414 EXP | In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the conne… | Patch early | 5.0 medium | 6.9% | 1999-03-01 |
| CVE-2000-0208 EXP | The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters… | Patch early | 5.0 medium | 6.9% | 2000-02-29 |
| CVE-2008-2390 EXP | Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows remote attackers to execute ar… | Patch early | 6.8 medium | 6.9% | 2008-05-21 |
| CVE-2012-0901 EXP | Cross-site scripting (XSS) vulnerability in yousaytoo.php in YouSayToo auto-publishing plugin 1.0 for WordPress allows remote attackers to inject arbi… | Patch early | 4.3 medium | 6.9% | 2012-01-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt