CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,212 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-6787 EXP | Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service or possibly have other impact v… | Patch early | 10.0 high | 8.1% | 2015-12-06 |
| CVE-1999-0950 EXP | Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories. | Patch early | 10.0 high | 8.1% | 1999-10-28 |
| CVE-2014-9304 EXP | Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrativ… | Patch early | 7.5 high | 8.1% | 2014-12-07 |
| CVE-2009-4202 EXP | Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include a… | Patch early | 7.5 high | 8.1% | 2009-12-04 |
| CVE-2002-1014 EXP | Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary code via an… | Patch early | 7.5 high | 8.1% | 2002-10-04 |
| CVE-2008-3318 EXP | admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrar… | Patch early | 7.5 high | 8.1% | 2008-07-25 |
| CVE-2001-0183 EXP | ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag in a TCP packet, which makes t… | Patch early | 7.5 high | 8.1% | 2001-03-26 |
| CVE-2001-0192 EXP | Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions. | Patch early | 10.0 high | 8.1% | 2001-05-03 |
| CVE-2004-0286 EXP | Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a… | Patch early | 10.0 high | 8.1% | 2004-11-23 |
| CVE-2002-0006 EXP | XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as other clien… | Patch early | 7.5 high | 8.1% | 2002-06-25 |
| CVE-2014-9633 EXP | The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device handle, which triggers a NULL po… | Patch early | 7.5 high | 8.1% | 2015-02-03 |
| CVE-2006-5395 EXP | Buffer overflow in Microsoft Class Package Export Tool (aka clspack.exe) allows context-dependent attackers to execute arbitrary code via a long strin… | Patch early | 7.5 high | 8.1% | 2006-10-18 |
| CVE-2007-6189 EXP | A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitr… | Patch early | 9.3 high | 8.1% | 2007-11-30 |
| CVE-2010-4323 EXP | Heap-based buffer overflow in novell-tftp.exe in Novell ZENworks Configuration Manager (ZCM) 10.3.1, 10.3.2, and 11.0, and earlier versions, allows re… | Patch early | 7.5 high | 8.1% | 2011-02-19 |
| CVE-2017-9742 EXP | The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and appl… | Patch early | 7.8 high | 8.1% | 2017-06-19 |
| CVE-2017-9750 EXP | opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers to cause a denial of service (b… | Patch early | 7.8 high | 8.1% | 2017-06-19 |
| CVE-2017-9756 EXP | The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overf… | Patch early | 7.8 high | 8.1% | 2017-06-19 |
| CVE-2005-3405 EXP | ATutor 1.4.1 through 1.5.1-pl1 allows remote attackers to execute arbitrary PHP functions via a direct request to forum.inc.php with a modified addsla… | Patch early | 7.5 high | 8.1% | 2005-11-01 |
| CVE-2008-0729 EXP | Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion and device crash) via certain Ja… | Patch early | 7.1 high | 8.1% | 2008-02-12 |
| CVE-2006-1749 EXP | PHP remote file inclusion vulnerability in config.php in phpListPro 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the retu… | Patch early | 7.5 high | 8.1% | 2006-04-12 |
| CVE-1999-1508 EXP | Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented UR… | Patch early | 10.0 high | 8.1% | 1999-11-16 |
| CVE-2003-0304 EXP | one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Ins… | Patch early | 10.0 high | 8.1% | 2003-06-09 |
| CVE-2015-1371 EXP | Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code by uploading a file with an exe… | Patch early | 7.5 high | 8.1% | 2015-01-27 |
| CVE-2000-1093 EXP | Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command. | Patch early | 7.5 high | 8.1% | 2001-01-09 |
| CVE-1999-1521 EXP | Computalynx CMail 2.4 and CMail 2.3 SP2 SMTP servers are vulnerable to a buffer overflow attack in the MAIL FROM command that may allow a remote attac… | Patch early | 10.0 high | 8.1% | 1999-09-12 |
| CVE-2008-0763 EXP | Stack-based buffer overflow in NPSpcSVR.exe in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier allows remote attackers to execute arb… | Patch early | 10.0 high | 8.1% | 2008-02-13 |
| CVE-2002-1656 EXP | X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via sniffing or th… | Patch early | 7.5 high | 8.1% | 2002-12-31 |
| CVE-2017-14523 EXP | WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that ex… | Patch early | 7.5 high | 8% | 2018-01-26 |
| CVE-2017-6823 EXP | Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action. | Patch early | 8.8 high | 8% | 2017-03-12 |
| CVE-2007-0873 EXP | nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) config_ed… | Patch early | 7.5 high | 8% | 2007-02-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt