CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,049 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
206,146 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-27746 EXP | SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email ad… | Patch early | 9.8 critical | 12.9% | 2024-03-01 |
| CVE-2002-1209 EXP | Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (d… | Patch early | 5.0 medium | 12.9% | 2002-11-04 |
| CVE-2006-7079 EXP | Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables a… | Patch early | 9.8 critical | 12.9% | 2007-03-02 |
| CVE-2021-43062 EXP | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 an… | Patch early | 6.1 medium | 12.9% | 2022-02-02 |
| CVE-2007-6244 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote attackers to inject a… | Patch early | 4.3 medium | 12.9% | 2007-12-20 |
| CVE-2019-1245 EXP | An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosu… | Patch early | 6.5 medium | 12.9% | 2019-09-11 |
| CVE-2020-29395 EXP | The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field. | Patch early | 6.1 medium | 12.9% | 2020-11-30 |
| CVE-2011-2505 EXP | libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns valu… | Patch early | 6.4 medium | 12.9% | 2011-07-14 |
| CVE-2008-5587 EXP | Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers… | Patch early | 4.3 medium | 12.9% | 2008-12-16 |
| CVE-2003-1505 EXP | Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a textarea in… | Patch early | 4.3 medium | 12.9% | 2003-12-31 |
| CVE-2002-2073 EXP | Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arb… | Patch early | 4.3 medium | 12.9% | 2002-12-31 |
| CVE-2021-24926 EXP | The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a… | Patch early | 6.1 medium | 12.9% | 2022-02-01 |
| CVE-2022-2840 EXP | The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via vario… | Patch early | 9.8 critical | 12.9% | 2022-09-19 |
| CVE-2012-2371 EXP | Cross-site scripting (XSS) vulnerability in index.php in the WP-FaceThumb plugin 0.1 for WordPress allows remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 12.8% | 2012-08-13 |
| CVE-2005-0710 EXP | MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restricti… | Patch early | 4.6 medium | 12.8% | 2005-05-02 |
| CVE-2000-0156 EXP | Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source R… | Patch early | 5.1 medium | 12.8% | 2000-02-16 |
| CVE-1999-0281 EXP | Denial of service in IIS using long URLs. | Patch early | 5.0 medium | 12.8% | 1997-06-01 |
| CVE-2005-2629 EXP | Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitr… | Patch early | 5.1 medium | 12.8% | 2005-11-18 |
| CVE-2018-9022 EXP | An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands… | Patch early | 9.8 critical | 12.8% | 2018-06-18 |
| CVE-2018-6911 EXP | The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argumen… | Patch early | 9.8 critical | 12.8% | 2018-02-13 |
| CVE-2020-6627 EXP | The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_lau… | Patch early | 9.8 critical | 12.8% | 2022-12-06 |
| CVE-2014-6043 EXP | ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote a… | Patch early | 6.5 medium | 12.8% | 2014-09-11 |
| CVE-2010-4156 EXP | The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive inform… | Patch early | 5.0 medium | 12.8% | 2010-11-10 |
| CVE-2015-2826 EXP | WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information. | Patch early | 5.3 medium | 12.8% | 2017-09-20 |
| CVE-2018-10285 EXP | The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attack… | Patch early | 9.8 critical | 12.8% | 2018-04-22 |
| CVE-2014-8498 EXP | SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (… | Patch early | 6.5 medium | 12.7% | 2014-11-17 |
| CVE-2005-1163 EXP | Multiple buffer overflows in Yager 5.24 and earlier allow remote attackers to execute arbitrary code via (1) a crafted nickname or (2) a packet with a… | Patch early | 6.4 medium | 12.7% | 2005-05-02 |
| CVE-2013-1601 EXP | An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LIN… | Patch early | 5.3 medium | 12.7% | 2020-01-28 |
| CVE-2007-6613 EXP | Stack-based buffer overflow in the print_iso9660_recurse function in iso-info (src/iso-info.c) in GNU Compact Disc Input and Control Library (libcdio)… | Patch early | 5.0 medium | 12.7% | 2008-01-03 |
| CVE-2011-1467 EXP | Unspecified vulnerability in the NumberFormatter::setSymbol (aka numfmt_set_symbol) function in the Intl extension in PHP before 5.3.6 allows context-… | Patch early | 5.0 medium | 12.7% | 2011-03-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt