CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,061 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-6494 EXP | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username… | Patch early | 10.0 high | 11.8% | 2007-12-20 |
| CVE-2023-27826 EXP | SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. which allows attackers… | Patch early | 8.8 high | 11.8% | 2023-04-12 |
| CVE-2007-2285 EXP | Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote attackers to read arbitrary f… | Patch early | 7.8 high | 11.8% | 2007-04-26 |
| CVE-2018-10517 EXP | In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploit… | Patch early | 7.2 high | 11.8% | 2018-04-27 |
| CVE-2004-1192 EXP | Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitrary code via format string… | Patch early | 10.0 high | 11.7% | 2005-01-10 |
| CVE-2012-6083 EXP | Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet. | Patch early | 7.5 high | 11.7% | 2020-01-23 |
| CVE-2008-1912 EXP | Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause a denial of service (applicat… | Patch early | 9.3 high | 11.7% | 2008-04-22 |
| CVE-2013-6021 EXP | Buffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code via a long sessionid value in… | Patch early | 9.3 high | 11.7% | 2013-10-19 |
| CVE-2005-4573 EXP | PHP remote file include vulnerability in plog-admin-functions.php in Plogger Beta 2 allows remote attackers to execute arbitrary code via a URL in the… | Patch early | 7.5 high | 11.7% | 2005-12-29 |
| CVE-2014-7884 EXP | Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated attack vectors. | Patch early | 9.0 high | 11.7% | 2015-03-14 |
| CVE-2000-0256 EXP | Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise av… | Patch early | 7.5 high | 11.7% | 2000-04-19 |
| CVE-2019-12744 EXP | SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-2018… | Patch early | 7.5 high | 11.7% | 2019-06-20 |
| CVE-2007-5722 EXP | Stack-based buffer overflow in a certain ActiveX control in GLChat.ocx 2.5.1.32 in GlobalLink 2.7.0.8, as used in Ourgame GLWorld and possibly other p… | Patch early | 7.5 high | 11.7% | 2007-10-30 |
| CVE-2019-9768 EXP | Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timestamp, which makes it easier for… | Patch early | 7.5 high | 11.7% | 2019-03-14 |
| CVE-2009-0174 EXP | Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in the HREF attribute of a REF elem… | Patch early | 9.3 high | 11.7% | 2009-01-20 |
| CVE-2010-3631 EXP | Array index error in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Mac OS X allows attackers to execute arbitrary code via unspecifi… | Patch early | 9.3 high | 11.7% | 2010-10-06 |
| CVE-2000-0245 EXP | Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts. | Patch early | 10.0 high | 11.7% | 2000-03-27 |
| CVE-2006-3228 EXP | Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary code via a crafted .mid (MIDI)… | Patch early | 9.3 high | 11.7% | 2006-06-26 |
| CVE-2007-5604 EXP | Buffer overflow in the ExtractCab function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0… | Patch early | 7.5 high | 11.7% | 2008-06-04 |
| CVE-2012-4512 EXP | The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memo… | Patch early | 8.8 high | 11.7% | 2020-02-08 |
| CVE-2010-0050 EXP | Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (ap… | Patch early | 8.8 high | 11.6% | 2010-03-15 |
| CVE-2003-1090 EXP | Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title. | Patch early | 10.0 high | 11.6% | 2003-02-06 |
| CVE-2009-3859 EXP | Buffer overflow in eEye Retina WiFi Scanner 1.0.8.68, as used in Retina Network Security Scanner 5.10.14, allows user-assisted remote attackers to cau… | Patch early | 9.3 high | 11.6% | 2009-11-04 |
| CVE-2008-4116 EXP | Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbit… | Patch early | 9.3 high | 11.6% | 2008-09-18 |
| CVE-2019-19731 EXP | Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE acti… | Patch early | 7.5 high | 11.6% | 2019-12-16 |
| CVE-2011-4189 EXP | The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corrup… | Patch early | 7.5 high | 11.6% | 2012-03-02 |
| CVE-1999-0710 EXP | The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attacker… | Patch early | 7.5 high | 11.6% | 1999-07-25 |
| CVE-2002-1456 EXP | Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value. | Patch early | 7.5 high | 11.6% | 2003-06-09 |
| CVE-2004-1147 EXP | phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands vi… | Patch early | 10.0 high | 11.6% | 2005-01-10 |
| CVE-2007-0233 EXP | wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matchi… | Patch early | 7.5 high | 11.6% | 2007-01-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt