CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,359 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
12,661 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-5381 EXP | Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to exe… | Patch early | 9.3 high | 14.7% | 2007-10-12 |
| CVE-2003-1387 EXP | Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username. | Patch early | 7.5 high | 14.7% | 2003-12-31 |
| CVE-2006-2022 EXP | Buffer overflow in the parse_url function in the RTSP module (rtsp/parse_url.c) in Fenice 1.10 and earlier allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 14.7% | 2006-04-25 |
| CVE-2022-24715 EXP | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration,… | Patch early | 8.5 high | 14.7% | 2022-03-08 |
| CVE-2020-10963 EXP | FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/fi… | Patch early | 7.2 high | 14.7% | 2020-03-25 |
| CVE-2001-0836 EXP | Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request. | Patch early | 7.5 high | 14.7% | 2001-12-06 |
| CVE-2010-4228 EXP | Stack-based buffer overflow in NWFTPD.NLM before 5.10.02 in the FTP server in Novell NetWare allows remote authenticated users to execute arbitrary co… | Patch early | 9.0 high | 14.7% | 2011-03-22 |
| CVE-2022-3142 EXP | The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injecti… | Patch early | 8.8 high | 14.7% | 2022-09-19 |
| CVE-2004-1120 EXP | Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and earlier al… | Patch early | 10.0 high | 14.6% | 2005-01-10 |
| CVE-2009-2692 EXP | The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops stru… | Patch early | 7.8 high | 14.6% | 2009-08-14 |
| CVE-2009-3663 EXP | Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of service (cra… | Patch early | 10.0 high | 14.6% | 2009-10-11 |
| CVE-2004-1127 EXP | Buffer overflow in Open Dc Hub 0.7.14 allows remote attackers, with administrator privileges, to execute arbitrary code via a long RedirectAll command… | Patch early | 10.0 high | 14.6% | 2005-01-10 |
| CVE-2006-6125 EXP | Heap-based buffer overflow in the wireless driver (WG311ND5.SYS) 2.3.1.10 for NetGear WG311v1 wireless adapter allows remote attackers to execute arbi… | Patch early | 7.5 high | 14.6% | 2006-11-27 |
| CVE-2001-0050 EXP | Buffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary commands via an IP address th… | Patch early | 10.0 high | 14.6% | 2001-02-16 |
| CVE-2008-0296 EXP | Heap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC Media Player 0.8.6d and earlier on Windows might allow remote RTSP servers… | Patch early | 10.0 high | 14.6% | 2008-01-16 |
| CVE-2013-2567 EXP | An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.co… | Patch early | 7.5 high | 14.6% | 2020-01-29 |
| CVE-2006-3890 EXP | Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, al… | Patch early | 9.3 high | 14.6% | 2006-11-21 |
| CVE-2017-11152 EXP | Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write… | Patch early | 7.5 high | 14.6% | 2017-08-08 |
| CVE-2005-2878 EXP | Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via form… | Patch early | 7.5 high | 14.6% | 2005-09-13 |
| CVE-2010-2743 EXP | The kernel-mode drivers in Microsoft Windows XP SP3 do not properly perform indexing of a function-pointer table during the loading of keyboard layout… | Patch early | 7.2 high | 14.6% | 2011-01-20 |
| CVE-2024-46987 EXP | Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. A path traversal vulnerability accessible via MediaController… | Patch early | 7.7 high | 14.6% | 2024-09-18 |
| CVE-2001-0233 EXP | Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a… | Patch early | 10.0 high | 14.6% | 2001-03-26 |
| CVE-2018-20219 EXP | An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an authentication c… | Patch early | 8.1 high | 14.6% | 2019-03-21 |
| CVE-2004-1627 EXP | Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long APPE com… | Patch early | 7.5 high | 14.5% | 2004-10-22 |
| CVE-2006-5567 EXP | Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via a crafted (… | Patch early | 9.3 high | 14.5% | 2006-10-27 |
| CVE-2008-0339 EXP | Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack v… | Patch early | 10.0 high | 14.5% | 2008-01-17 |
| CVE-2006-2667 EXP | Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriag… | Patch early | 7.5 high | 14.5% | 2006-05-30 |
| CVE-2005-1306 EXP | The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containi… | Patch early | 7.5 high | 14.5% | 2005-06-15 |
| CVE-2017-16352 EXP | GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the Describ… | Patch early | 8.8 high | 14.5% | 2017-11-01 |
| CVE-2018-19585 EXP | GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when usi… | Patch early | 7.5 high | 14.5% | 2019-05-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt