CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,084 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-47875 EXP | A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code. | Patch early | 8.8 high | 10.2% | 2023-05-02 |
| CVE-2000-0474 EXP | Real Networks RealServer 7.x allows remote attackers to cause a denial of service via a malformed request for a page in the viewsource directory. | Patch early | 7.8 high | 10.2% | 2000-06-01 |
| CVE-2011-0920 EXP | The Remote Console in IBM Lotus Domino, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to byp… | Patch early | 9.3 high | 10.2% | 2011-02-08 |
| CVE-2009-1314 EXP | body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the savefile action with a file par… | Patch early | 10.0 high | 10.1% | 2009-04-17 |
| CVE-1999-0562 EXP | The registry in Windows NT can be accessed remotely by users who are not administrators. | Patch early | 7.5 high | 10.1% | 1997-01-01 |
| CVE-2016-4340 EXP | The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4… | Patch early | 8.8 high | 10.1% | 2017-01-23 |
| CVE-2009-0450 EXP | Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code via a long string in a playlis… | Patch early | 9.3 high | 10.1% | 2009-02-10 |
| CVE-2007-2458 EXP | Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 7.5 high | 10.1% | 2007-05-02 |
| CVE-2017-14084 EXP | A potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to execute arbitrary code on vulne… | Patch early | 8.1 high | 10.1% | 2017-10-06 |
| CVE-2016-9091 EXP | Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command injec… | Patch early | 7.2 high | 10.1% | 2017-04-05 |
| CVE-2006-3668 EXP | Heap-based buffer overflow in the it_read_envelope function in Dynamic Universal Music Bibliotheque (DUMB) 0.9.3 and earlier and current CVS as of 200… | Patch early | 7.6 high | 10.1% | 2006-07-18 |
| CVE-2010-3179 EXP | Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and… | Patch early | 9.3 high | 10.1% | 2010-10-21 |
| CVE-2002-0128 EXP | cgitest.exe in Sambar Server 5.1 before Beta 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long a… | Patch early | 7.5 high | 10.1% | 2002-03-25 |
| CVE-2008-4652 EXP | Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execute arbitr… | Patch early | 9.3 high | 10.1% | 2008-10-22 |
| CVE-2007-2156 EXP | Multiple PHP remote file inclusion vulnerabilities in Rezervi Generic 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the root p… | Patch early | 7.5 high | 10.1% | 2007-04-19 |
| CVE-2007-2597 EXP | Multiple PHP remote file inclusion vulnerabilities in telltarget CMS 1.3.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) o… | Patch early | 7.5 high | 10.1% | 2007-05-11 |
| CVE-2007-3217 EXP | Multiple PHP remote file inclusion vulnerabilities in Prototype of an PHP application 0.1 allow remote attackers to execute arbitrary PHP code via a U… | Patch early | 7.5 high | 10.1% | 2007-06-14 |
| CVE-2007-0561 EXP | Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root… | Patch early | 7.5 high | 10.1% | 2007-01-30 |
| CVE-2008-2693 EXP | Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to… | Patch early | 9.3 high | 10.1% | 2008-06-13 |
| CVE-2009-2364 EXP | Stack-based buffer overflow in Mp3-Nator 2.0 allows remote attackers to execute arbitrary code via (1) a long string in a .plf file and (2) a long str… | Patch early | 9.3 high | 10.1% | 2009-07-08 |
| CVE-2006-5058 EXP | Buffer overflow in (1) Call of Duty 1.5b and earlier, (2) Call of Duty United Offensive 1.51b and earlier, and (3) Call of Duty 2 1.3 and earlier allo… | Patch early | 7.5 high | 10.1% | 2006-09-28 |
| CVE-2017-12929 EXP | Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files lead… | Patch early | 8.8 high | 10.1% | 2017-09-21 |
| CVE-2017-12969 EXP | Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a den… | Patch early | 8.8 high | 10.1% | 2017-11-10 |
| CVE-2016-4806 EXP | Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server… | Patch early | 7.5 high | 10.1% | 2017-01-11 |
| CVE-2005-2199 EXP | PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via… | Patch early | 7.5 high | 10.1% | 2005-07-11 |
| CVE-2005-3488 EXP | Scorched 3D 39.1 (bf) and earlier allows remote attackers to cause a denial of service (long loop and server hang) via a negative numplayers value tha… | Patch early | 7.8 high | 10.1% | 2005-11-03 |
| CVE-2011-0885 EXP | A certain Comcast Business Gateway configuration of the SMC SMCD3G-CCR with firmware before 1.4.0.49.2 has a default password of D0nt4g3tme for the ms… | Patch early | 10.0 high | 10.1% | 2011-02-08 |
| CVE-2004-1695 EXP | EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administration feature via a URL that cont… | Patch early | 10.0 high | 10.1% | 2004-09-20 |
| CVE-2007-2816 EXP | Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP code via a URL in the root pa… | Patch early | 7.5 high | 10.1% | 2007-05-22 |
| CVE-2012-0278 EXP | Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file… | Patch early | 9.3 high | 10.1% | 2012-04-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt