CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,116 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-3934 EXP | Buffer overflow in Symantec pcAnywhere 11.0.1, 11.5.1, and all other 32-bit versions allows remote attackers to cause a denial of service (application… | Patch early | 7.8 high | 9.5% | 2005-12-01 |
| CVE-2006-3192 EXP | PHP remote file inclusion vulnerability in Ad Manager Pro 2.6 allows remote attackers to execute arbitrary PHP code via a URL in the (1) ipath paramet… | Patch early | 7.5 high | 9.5% | 2006-06-23 |
| CVE-2007-2456 EXP | Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root pa… | Patch early | 7.5 high | 9.5% | 2007-05-02 |
| CVE-2015-7259 EXP | ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid username and password pairs, w… | Patch early | 8.8 high | 9.5% | 2017-08-24 |
| CVE-1999-0926 EXP | Apache allows remote attackers to conduct a denial of service via a large number of MIME headers. | Patch early | 10.0 high | 9.4% | 1999-09-03 |
| CVE-2002-0068 EXP | Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an ftp:// URL… | Patch early | 7.5 high | 9.4% | 2002-03-08 |
| CVE-2005-0838 EXP | Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possibly execute arbitrary code via… | Patch early | 7.5 high | 9.4% | 2005-05-02 |
| CVE-1999-0266 EXP | The info2www CGI script allows remote file access or remote command execution. | Patch early | 7.5 high | 9.4% | 1998-03-01 |
| CVE-2007-4586 EXP | Multiple buffer overflows in php_iisfunc.dll in the iisfunc extension for PHP 5.2.0 and earlier allow context-dependent attackers to execute arbitrary… | Patch early | 7.5 high | 9.4% | 2007-08-29 |
| CVE-2007-2428 EXP | Multiple PHP remote file inclusion vulnerabilities in page.php in Ahhp-Portal allow remote attackers to execute arbitrary PHP code via a URL in the (1… | Patch early | 7.5 high | 9.4% | 2007-05-02 |
| CVE-2000-0011 EXP | Buffer overflow in AnalogX SimpleServer:WWW HTTP server allows remote attackers to execute commands via a long GET request. | Patch early | 7.5 high | 9.4% | 1999-12-31 |
| CVE-2009-3850 EXP | Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad… | Patch early | 9.3 high | 9.4% | 2009-11-06 |
| CVE-2010-4233 EXP | The Linux installation on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 has a default passwo… | Patch early | 10.0 high | 9.4% | 2010-11-17 |
| CVE-2015-3203 EXP | Unrestricted file upload vulnerability in h5ai before 0.25.0 allows remote attackers to execute arbitrary code by uploading a file with an executable… | Patch early | 7.5 high | 9.4% | 2015-09-28 |
| CVE-2012-2208 EXP | Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a ..… | Patch early | 7.5 high | 9.4% | 2012-08-14 |
| CVE-2007-2070 EXP | Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary… | Patch early | 7.5 high | 9.4% | 2007-04-18 |
| CVE-2010-4283 EXP | PHP remote file inclusion vulnerability in extras/pandora_diag.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 9.4% | 2010-12-02 |
| CVE-2007-1164 EXP | Multiple PHP remote file inclusion vulnerabilities in DBImageGallery 1.2.2 allow remote attackers to execute arbitrary PHP code via a URL in the donsi… | Patch early | 7.5 high | 9.4% | 2007-03-02 |
| CVE-2008-3681 EXP | components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the… | Patch early | 7.5 high | 9.4% | 2008-08-14 |
| CVE-2007-3294 EXP | Multiple buffer overflows in libtidy, as used in the Tidy extension for PHP 5.2.3 and possibly other products, allow context-dependent attackers to ex… | Patch early | 7.5 high | 9.4% | 2007-06-20 |
| CVE-2007-4903 EXP | Multiple buffer overflows in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allow remote attackers to execute… | Patch early | 7.5 high | 9.4% | 2007-09-17 |
| CVE-2018-4197 EXP | A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… | Patch early | 8.8 high | 9.4% | 2019-04-03 |
| CVE-2018-4315 EXP | A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… | Patch early | 8.8 high | 9.4% | 2019-04-03 |
| CVE-2004-1095 EXP | Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (… | Patch early | 10.0 high | 9.4% | 2005-01-10 |
| CVE-2006-0565 EXP | PHP remote file include vulnerability in inc/backend_settings.php in Loudblog 0.4 and earlier allows remote attackers to execute arbitrary PHP code vi… | Patch early | 7.5 high | 9.4% | 2006-02-06 |
| CVE-2007-1943 EXP | Integer overflow in ACDSee Photo Manager 9.0 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via l… | Patch early | 9.3 high | 9.4% | 2007-04-11 |
| CVE-2010-2931 EXP | Stack-based buffer overflow in SigPlus Pro 3.74 ActiveX control allows remote attackers to execute arbitrary code via a long eighth argument (HexStrin… | Patch early | 9.3 high | 9.4% | 2010-08-05 |
| CVE-1999-0492 EXP | The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses. | Patch early | 10.0 high | 9.4% | 1999-04-23 |
| CVE-2007-2270 EXP | The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) character in the From header, and… | Patch early | 7.8 high | 9.4% | 2007-04-25 |
| CVE-2002-1486 EXP | Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly… | Patch early | 7.5 high | 9.4% | 2003-04-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt