CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,098 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-6998 EXP | Stack-based buffer overflow in chrome/common/gfx/url_elider.cc in Google Chrome 0.2.149.27 and other versions before 0.2.149.29 might allow user-assis… | Patch early | 9.3 high | 9.7% | 2009-08-19 |
| CVE-2006-5307 EXP | Multiple PHP remote file inclusion vulnerabilities in AFGB GUESTBOOK 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the Htmls p… | Patch early | 7.5 high | 9.7% | 2006-10-17 |
| CVE-2002-2272 EXP | Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronize… | Patch early | 7.8 high | 9.7% | 2002-12-31 |
| CVE-2008-6497 EXP | The Neostrada Livebox ADSL Router allows remote attackers to cause a denial of service (network outage) via multiple HTTP requests for the /- URI. | Patch early | 7.8 high | 9.7% | 2009-03-20 |
| CVE-2016-10277 EXP | An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute arbitrary code within the con… | Patch early | 7.8 high | 9.7% | 2017-05-12 |
| CVE-2007-2609 EXP | Multiple PHP remote file inclusion vulnerabilities in gnuedu 1.3b2 allow remote attackers to execute arbitrary PHP code via a URL in the (a) ETCDIR pa… | Patch early | 7.5 high | 9.7% | 2007-05-11 |
| CVE-2005-2967 EXP | Format string vulnerability in input_cdda.c in xine-lib 1-beta through 1-beta 3, 1-rc, 1.0 through 1.0.2, and 1.1.1 allows remote servers to execute a… | Patch early | 7.5 high | 9.7% | 2005-10-14 |
| CVE-2018-15576 EXP | An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in… | Patch early | 8.1 high | 9.7% | 2018-08-24 |
| CVE-1999-0913 EXP | dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters. | Patch early | 10.0 high | 9.7% | 1999-08-05 |
| CVE-2005-4553 EXP | Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long APPE command. NOTE: the provenance of this inf… | Patch early | 7.5 high | 9.7% | 2005-12-28 |
| CVE-2004-0486 EXP | HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue tha… | Patch early | 7.6 high | 9.7% | 2004-07-07 |
| CVE-2009-0410 EXP | Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x, 7.0, 7.01, 7.02, 7.03, 7.03HP1a, and 8.0 allows remot… | Patch early | 10.0 high | 9.7% | 2009-02-03 |
| CVE-2007-0165 EXP | Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (crash) via malformed RPC requests tha… | Patch early | 7.8 high | 9.7% | 2007-01-10 |
| CVE-2007-2142 EXP | Multiple PHP remote file inclusion vulnerabilities in AjPortal2Php allow remote attackers to execute arbitrary PHP code via a URL in the PagePrefix pa… | Patch early | 7.5 high | 9.7% | 2007-04-19 |
| CVE-2007-2762 EXP | Multiple PHP remote file inclusion vulnerabilities in Build it Fast (bif3) 0.4.1 allow remote attackers to execute arbitrary PHP code via a URL in (1)… | Patch early | 7.5 high | 9.7% | 2007-05-18 |
| CVE-2005-1173 EXP | Buffer overflow in PMSoftware Simple Web Server 1.0 allows remote attackers to execute arbitrary code via a long GET request. | Patch early | 7.5 high | 9.7% | 2005-05-02 |
| CVE-2018-4328 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTun… | Patch early | 8.8 high | 9.7% | 2019-04-03 |
| CVE-2020-11699 EXP | An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execute… | Patch early | 8.8 high | 9.6% | 2020-09-17 |
| CVE-2009-1672 EXP | The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (… | Patch early | 9.3 high | 9.6% | 2009-05-18 |
| CVE-2011-2506 EXP | setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment clos… | Patch early | 7.5 high | 9.6% | 2011-07-14 |
| CVE-2003-0100 EXP | Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of… | Patch early | 7.5 high | 9.6% | 2003-03-03 |
| CVE-2009-1586 EXP | Stack-based buffer overflow in the NZB importer feature in GrabIt 1.7.2 Beta 3 and earlier allows remote attackers to execute arbitrary code via a cra… | Patch early | 9.3 high | 9.6% | 2009-05-07 |
| CVE-2007-4155 EXP | Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll in EMC VMware 6.0.0 allows remote attackers to execute arbitrary loca… | Patch early | 9.3 high | 9.6% | 2007-08-03 |
| CVE-2022-26521 EXP | Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Med… | Patch early | 7.2 high | 9.6% | 2022-03-10 |
| CVE-2006-1371 EXP | Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea FileManager plugin to upload and… | Patch early | 9.0 high | 9.6% | 2006-03-23 |
| CVE-2019-14749 EXP | An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionalit… | Patch early | 8.8 high | 9.6% | 2019-08-07 |
| CVE-2005-1950 EXP | hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument. | Patch early | 7.5 high | 9.6% | 2005-06-09 |
| CVE-2018-4323 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTun… | Patch early | 8.8 high | 9.6% | 2019-04-03 |
| CVE-2012-1189 EXP | Stack-based buffer overflow in modules/graphic/ssgraph/grsound.cpp in The Open Racing Car Simulator (TORCS) before 1.3.3 and Speed Dreams allows user-… | Patch early | 9.3 high | 9.6% | 2012-10-08 |
| CVE-2010-4281 EXP | Incomplete blacklist vulnerability in the safe_url_extraclean function in ajax.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbi… | Patch early | 7.5 high | 9.6% | 2010-12-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt