CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,152 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
206,203 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-1320 EXP | Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote… | Patch early | 4.0 medium | 11.9% | 2010-04-22 |
| CVE-2002-1954 EXP | Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the q… | Patch early | 4.3 medium | 11.9% | 2002-12-31 |
| CVE-2008-1489 EXP | Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly… | Patch early | 6.8 medium | 11.8% | 2008-03-25 |
| CVE-2021-42325 EXP | Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name. | Patch early | 9.8 critical | 11.8% | 2021-10-12 |
| CVE-2008-1881 EXP | Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a… | Patch early | 6.8 medium | 11.8% | 2008-04-17 |
| CVE-2009-2168 EXP | cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit when the supplied credentials are… | Patch early | 9.8 critical | 11.8% | 2009-06-22 |
| CVE-2011-4153 EXP | PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL p… | Patch early | 5.0 medium | 11.8% | 2012-01-18 |
| CVE-2018-8468 EXP | An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." This affec… | Patch early | 4.7 medium | 11.8% | 2018-09-13 |
| CVE-2014-7279 EXP | The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equipment management authority"… | Patch early | 9.8 critical | 11.7% | 2017-03-23 |
| CVE-2019-17132 EXP | vBulletin through 5.5.4 mishandles custom avatars. | Patch early | 9.8 critical | 11.7% | 2019-10-04 |
| CVE-2010-1029 EXP | Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS… | Patch early | 5.0 medium | 11.7% | 2010-03-19 |
| CVE-2017-6506 EXP | In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. T… | Patch early | 9.8 critical | 11.7% | 2017-03-10 |
| CVE-2013-4295 EXP | The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an external… | Patch early | 5.0 medium | 11.7% | 2013-10-24 |
| CVE-2017-3897 EXP | A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security… | Patch early | 9.8 critical | 11.7% | 2017-09-01 |
| CVE-2006-1206 EXP | Matt Johnston Dropbear SSH server 0.47 and earlier, as used in embedded Linux devices and on general-purpose operating systems, allows remote attacker… | Patch early | 5.0 medium | 11.7% | 2006-03-14 |
| CVE-2005-2792 EXP | Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in… | Patch early | 5.0 medium | 11.7% | 2005-09-02 |
| CVE-2010-2122 EXP | Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows remote attackers to include and… | Patch early | 6.8 medium | 11.7% | 2010-06-01 |
| CVE-1999-1520 EXP | A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, whi… | Patch early | 5.0 medium | 11.7% | 1999-05-11 |
| CVE-2008-0333 EXP | Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read a… | Patch early | 5.0 medium | 11.7% | 2008-01-17 |
| CVE-2014-3976 EXP | Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a… | Patch early | 5.0 medium | 11.6% | 2014-06-05 |
| CVE-2001-0311 EXP | Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client. | Patch early | 4.6 medium | 11.6% | 2001-06-02 |
| CVE-2002-0591 EXP | Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute co… | Patch early | 5.0 medium | 11.6% | 2002-06-18 |
| CVE-2009-1574 EXP | racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a… | Patch early | 5.0 medium | 11.6% | 2009-05-06 |
| CVE-2016-6566 EXP | The valueAsString parameter inside the JSON payload contained by the ucLogin_txtLoginId_ClientStat POST parameter of the Sungard eTRAKiT3 software ver… | Patch early | 9.8 critical | 11.6% | 2018-07-13 |
| CVE-2003-0129 EXP | Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that i… | Patch early | 5.0 medium | 11.6% | 2003-03-24 |
| CVE-2019-8925 EXP | An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerability in the Administration zon… | Patch early | 4.3 medium | 11.6% | 2019-05-17 |
| CVE-2007-2209 EXP | Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.20 and possibly other products… | Patch early | 6.8 medium | 11.6% | 2007-04-24 |
| CVE-2014-9014 EXP | Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allo… | Patch early | 4.3 medium | 11.6% | 2019-11-06 |
| CVE-2018-18957 EXP | An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_publisher.c. | Patch early | 9.8 critical | 11.6% | 2018-11-05 |
| CVE-2012-1125 EXP | Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 for WordPress allows remote atta… | Patch early | 6.8 medium | 11.6% | 2012-10-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt