CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,405 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
12,661 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2003-0865 EXP | Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a long request. | Patch early | 7.5 high | 14.5% | 2003-11-17 |
| CVE-2023-33440 EXP | Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user. | Patch early | 7.2 high | 14.5% | 2023-05-26 |
| CVE-2008-4762 EXP | Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service crash) and potentially execute a… | Patch early | 9.0 high | 14.5% | 2008-10-28 |
| CVE-2006-2362 EXP | Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-depen… | Patch early | 7.3 high | 14.5% | 2006-05-15 |
| CVE-2007-1561 EXP | The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE mess… | Patch early | 7.8 high | 14.5% | 2007-03-21 |
| CVE-2005-0245 EXP | Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcurso… | Patch early | 7.5 high | 14.5% | 2005-02-01 |
| CVE-2004-1284 EXP | Buffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafted MP3 play… | Patch early | 10.0 high | 14.5% | 2005-01-10 |
| CVE-2001-0815 EXP | Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitrary code via an HTTP request fo… | Patch early | 7.5 high | 14.4% | 2001-12-06 |
| CVE-2007-2434 EXP | Buffer overflow in asnsp.dll in Aventail Connect 4.1.2.13 allows remote attackers to cause a denial of service (application crash) or execute arbitrar… | Patch early | 10.0 high | 14.4% | 2007-05-02 |
| CVE-2006-2656 EXP | Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long fil… | Patch early | 7.5 high | 14.4% | 2006-05-30 |
| CVE-2013-0984 EXP | Directory Service in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a… | Patch early | 9.3 high | 14.4% | 2013-06-05 |
| CVE-2005-1544 EXP | Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample t… | Patch early | 7.5 high | 14.4% | 2005-05-14 |
| CVE-2001-0023 EXP | everythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter. | Patch early | 10.0 high | 14.4% | 2001-02-12 |
| CVE-2007-2586 EXP | The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and… | Patch early | 9.3 high | 14.4% | 2007-05-10 |
| CVE-2011-3496 EXP | service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) BF, (2… | Patch early | 10.0 high | 14.4% | 2011-09-16 |
| CVE-2014-8722 EXP | GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/<… | Patch early | 7.5 high | 14.4% | 2017-03-17 |
| CVE-2014-8877 EXP | The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress… | Patch early | 10.0 high | 14.4% | 2014-12-05 |
| CVE-2010-5323 EXP | Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3… | Patch early | 10.0 high | 14.4% | 2015-06-07 |
| CVE-2015-2825 EXP | Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPress allows remote attackers to e… | Patch early | 7.5 high | 14.4% | 2015-04-21 |
| CVE-2017-2547 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" co… | Patch early | 8.8 high | 14.3% | 2017-05-22 |
| CVE-2007-4567 EXP | The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, wh… | Patch early | 7.8 high | 14.3% | 2007-12-21 |
| CVE-2003-0896 EXP | The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote… | Patch early | 7.5 high | 14.3% | 2003-11-17 |
| CVE-2019-15637 EXP | Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This… | Patch early | 8.1 high | 14.3% | 2019-08-26 |
| CVE-2010-2682 EXP | Directory traversal vulnerability in the Realtyna Translator (com_realtyna) component 1.0.15 for Joomla! allows remote attackers to read arbitrary fil… | Patch early | 7.5 high | 14.3% | 2010-07-12 |
| CVE-2004-2167 EXP | Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary code via (1) the expandmacro f… | Patch early | 7.5 high | 14.3% | 2004-12-31 |
| CVE-2011-0917 EXP | Buffer overflow in nLDAP.exe in IBM Lotus Domino allows remote attackers to execute arbitrary code via a long string in an LDAP Bind operation, aka SP… | Patch early | 10.0 high | 14.3% | 2011-02-08 |
| CVE-2014-4158 EXP | Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a GET request. | Patch early | 7.5 high | 14.3% | 2014-06-13 |
| CVE-2012-1502 EXP | Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (applicatio… | Patch early | 7.5 high | 14.3% | 2012-06-16 |
| CVE-2000-1029 EXP | Buffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR query. | Patch early | 10.0 high | 14.3% | 2000-12-11 |
| CVE-2008-5220 EXP | Unrestricted file upload vulnerability in admin/upload_form.php in wPortfolio 0.3 and earlier allows remote attackers to execute arbitrary code by upl… | Patch early | 10.0 high | 14.3% | 2008-11-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt