CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,178 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-1999-0953 EXP | WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers. | Patch early | 10.0 high | 8.6% | 1999-09-16 |
| CVE-2003-0143 EXP | The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authentic… | Patch early | 10.0 high | 8.6% | 2003-03-18 |
| CVE-2003-1148 EXP | Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and po… | Patch early | 7.5 high | 8.6% | 2003-10-25 |
| CVE-2007-0614 EXP | The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a… | Patch early | 7.8 high | 8.6% | 2007-01-31 |
| CVE-2008-6953 EXP | Buffer overflow in oovoo.exe in ooVoo 1.7.1.35, and possibly other versions before 1.7.1.59, allows remote attackers to cause a denial of service (cra… | Patch early | 9.3 high | 8.6% | 2009-08-12 |
| CVE-2002-0962 EXP | Cross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via (1) the url variable in the L… | Patch early | 7.5 high | 8.6% | 2002-10-04 |
| CVE-2003-0651 EXP | Buffer overflow in the mylo_log logging function for mod_mylo 0.2.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET… | Patch early | 7.5 high | 8.6% | 2003-08-27 |
| CVE-2018-4200 EXP | An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud before 7.5 on Windows is affe… | Patch early | 8.8 high | 8.6% | 2018-06-08 |
| CVE-2009-1830 EXP | Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long search query. | Patch early | 10.0 high | 8.6% | 2009-05-29 |
| CVE-2010-1176 EXP | Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… | Patch early | 9.3 high | 8.6% | 2010-03-29 |
| CVE-2019-3999 EXP | Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to exe… | Patch early | 7.8 high | 8.6% | 2020-02-25 |
| CVE-2008-0127 EXP | The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute ar… | Patch early | 8.8 high | 8.6% | 2008-01-10 |
| CVE-2014-6389 EXP | backup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the d parameter. | Patch early | 7.5 high | 8.6% | 2014-10-06 |
| CVE-2014-9144 EXP | Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metacharacters in the ping field (s… | Patch early | 7.5 high | 8.6% | 2014-12-05 |
| CVE-2010-1685 EXP | Stack-based buffer overflow in CursorArts ZipWrangler 1.20 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing a… | Patch early | 9.3 high | 8.6% | 2010-05-04 |
| CVE-2008-0379 EXP | Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to c… | Patch early | 9.3 high | 8.6% | 2008-01-22 |
| CVE-2008-6833 EXP | Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and execute arbitrary local files… | Patch early | 10.0 high | 8.6% | 2009-06-22 |
| CVE-2012-0406 EXP | The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a deni… | Patch early | 7.8 high | 8.6% | 2012-04-20 |
| CVE-2002-0955 EXP | Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execute arbitra… | Patch early | 7.5 high | 8.6% | 2002-10-04 |
| CVE-2010-1132 EXP | The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute… | Patch early | 9.3 high | 8.5% | 2010-03-27 |
| CVE-2007-2536 EXP | PicoZip allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous fil… | Patch early | 7.8 high | 8.5% | 2007-05-09 |
| CVE-2014-3437 EXP | The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requ… | Patch early | 7.5 high | 8.5% | 2014-11-07 |
| CVE-2006-3970 EXP | PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows remote attackers to execute arb… | Patch early | 7.5 high | 8.5% | 2006-08-01 |
| CVE-2000-0187 EXP | EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metachar… | Patch early | 7.5 high | 8.5% | 2000-02-27 |
| CVE-2008-0396 EXP | Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Ente… | Patch early | 7.8 high | 8.5% | 2008-01-23 |
| CVE-2008-1262 EXP | The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote… | Patch early | 10.0 high | 8.5% | 2008-03-10 |
| CVE-2007-2364 EXP | Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the ro… | Patch early | 7.5 high | 8.5% | 2007-04-30 |
| CVE-2014-0242 EXP | mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type h… | Patch early | 7.5 high | 8.5% | 2019-12-09 |
| CVE-2007-0684 EXP | PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 8.5% | 2007-02-03 |
| CVE-2014-0329 EXP | The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remote attacker… | Patch early | 9.3 high | 8.5% | 2014-02-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt