CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,265 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
169,629 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-6503 EXP | The CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platforms do not properly interact with Visual C++ compiler options, which al… | Patch early | 5.9 medium | 6.4% | 2016-08-06 |
| CVE-2009-1621 EXP | Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the route param… | Patch early | 5.0 medium | 6.4% | 2009-05-12 |
| CVE-2012-2997 EXP | XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 through 10.2.4 and 11.0.0 through 11.2.1 allows re… | Patch early | 4.0 medium | 6.4% | 2014-01-21 |
| CVE-2000-0482 EXP | Check Point Firewall-1 allows remote attackers to cause a denial of service by sending a large number of malformed fragmented IP packets. | Patch early | 5.0 medium | 6.4% | 2000-06-06 |
| CVE-2006-6558 EXP | Crob FTP Server 3.6.1 b.263 allows remote attackers to cause a denial of service via a long series of "?A" sequences in the (1) LIST and possibly (2)… | Patch early | 5.0 medium | 6.4% | 2006-12-14 |
| CVE-2009-3272 EXP | Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2, allows remote attackers to ca… | Patch early | 5.0 medium | 6.4% | 2009-09-21 |
| CVE-2012-4515 EXP | Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers… | Patch early | 6.8 medium | 6.4% | 2012-11-11 |
| CVE-2006-0138 EXP | aMSN (aka Alvaro's Messenger) allows remote attackers to cause a denial of service (client hang and termination of client's instant-messaging session)… | Patch early | 5.0 medium | 6.4% | 2006-01-09 |
| CVE-2008-4918 EXP | Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote… | Patch early | 4.3 medium | 6.4% | 2008-11-04 |
| CVE-2008-6996 EXP | Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for remote attackers or malware to ca… | Patch early | 5.0 medium | 6.4% | 2009-08-19 |
| CVE-2001-0566 EXP | Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when SNMP is disa… | Patch early | 5.0 medium | 6.4% | 2001-08-14 |
| CVE-2006-6295 EXP | PHP remote file inclusion vulnerability in includes/mx_common.php in the mx_tinies 1.3.0 Module for MxBB Portal 1.06 allows remote attackers to execut… | Patch early | 6.8 medium | 6.4% | 2006-12-05 |
| CVE-2008-5965 EXP | Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to check for t… | Patch early | 5.0 medium | 6.4% | 2009-01-26 |
| CVE-2013-1464 EXP | Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to injec… | Patch early | 4.3 medium | 6.4% | 2013-02-07 |
| CVE-2018-15536 EXP | /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extrac… | Patch early | 5.5 medium | 6.4% | 2018-08-24 |
| CVE-2015-1494 EXP | The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site sc… | Patch early | 4.3 medium | 6.4% | 2015-02-17 |
| CVE-2005-0872 EXP | Cross-site scripting (XSS) vulnerability in calendar_scheduler.php in the Topic Calendar 1.0.1 module for phpBB allows remote attackers to inject arbi… | Patch early | 4.3 medium | 6.4% | 2005-05-02 |
| CVE-2009-2966 EXP | avp.exe in Kaspersky Internet Security 9.0.0.459 and Anti-Virus 9.0.0.463 allows remote attackers to cause a denial of service (CPU consumption and ne… | Patch early | 4.3 medium | 6.4% | 2009-08-25 |
| CVE-2021-27520 EXP | A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter. | Patch early | 6.1 medium | 6.4% | 2021-03-19 |
| CVE-2009-4170 EXP | WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to w… | Patch early | 5.0 medium | 6.4% | 2009-12-02 |
| CVE-2008-5667 EXP | The scanning engine in VirusBlokAda VBA32 Personal Antivirus 3.12.8.x allows remote attackers to cause a denial of service (memory corruption and appl… | Patch early | 5.0 medium | 6.4% | 2008-12-19 |
| CVE-1999-0848 EXP | Denial of service in BIND named via consuming more than "fdmax" file descriptors. | Patch early | 5.0 medium | 6.4% | 1999-11-10 |
| CVE-2015-0555 EXP | Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote attackers to execute arbitrar… | Patch early | 6.8 medium | 6.4% | 2015-02-24 |
| CVE-2009-0961 EXP | The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the call approval dialog when another… | Patch early | 5.0 medium | 6.4% | 2009-06-19 |
| CVE-2010-1217 EXP | Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attack… | Patch early | 4.3 medium | 6.4% | 2010-03-30 |
| CVE-2015-3300 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plug… | Patch early | 4.3 medium | 6.4% | 2015-05-14 |
| CVE-2002-0375 EXP | Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript via a URL with the script in t… | Patch early | 5.0 medium | 6.4% | 2002-05-29 |
| CVE-2012-0025 EXP | Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for Irfan… | Patch early | 6.8 medium | 6.4% | 2012-11-02 |
| CVE-2020-15718 EXP | RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could… | Patch early | 6.1 medium | 6.4% | 2020-07-15 |
| CVE-2009-4091 EXP | comments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers to edit or delete comments via… | Patch early | 5.0 medium | 6.4% | 2009-11-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt