CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,295 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-2763 EXP | Buffer overflow in the UnlockSupport function in the LockModules subsystem in a certain ActiveX control in ltmm15.dll in Sienzo Digital Music Mentor (… | Patch early | 10.0 high | 7.8% | 2007-05-18 |
| CVE-2016-5764 EXP | Micro Focus Rumba FTP 4.X client buffer overflow makes it possible to corrupt the stack and allow arbitrary code execution. Fixed in: Rumba FTP 4.5 (H… | Patch early | 8.8 high | 7.8% | 2016-10-27 |
| CVE-2006-3323 EXP | PHP remote file inclusion vulnerability in admin/admin.php in MF Piadas 1.0 allows remote attackers to execute arbitrary PHP code via the page paramet… | Patch early | 7.5 high | 7.8% | 2006-06-30 |
| CVE-2011-5012 EXP | Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflection 2008, Re… | Patch early | 10.0 high | 7.8% | 2011-12-25 |
| CVE-2009-4541 EXP | Multiple PHP remote file inclusion vulnerabilities in IsolSoft Support Center 2.5 allow remote attackers to execute arbitrary PHP code via a URL in th… | Patch early | 7.5 high | 7.7% | 2010-01-04 |
| CVE-2000-0937 EXP | Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allo… | Patch early | 7.5 high | 7.7% | 2000-12-19 |
| CVE-2012-2271 EXP | Buffer overflow in the InitLicenKeys function in a certain ActiveX control in SkinCrafter3_vs2005.dll in SkinCrafter 3.0 allows remote attackers to ex… | Patch early | 10.0 high | 7.7% | 2012-05-21 |
| CVE-2004-2107 EXP | Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use… | Patch early | 7.5 high | 7.7% | 2004-12-31 |
| CVE-2012-3585 EXP | Heap-based buffer overflow in jpeg_ls.dll in the Jpeg_LS (aka JLS) plugin in the formats plugins in IrfanView PlugIns before 4.34 allows remote attack… | Patch early | 9.3 high | 7.7% | 2012-07-05 |
| CVE-2014-5084 EXP | A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let a remote malicious user execut… | Patch early | 8.8 high | 7.7% | 2020-02-10 |
| CVE-2005-3487 EXP | Multiple buffer overflows in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole::addLine, (2… | Patch early | 7.5 high | 7.7% | 2005-11-03 |
| CVE-2004-1471 EXP | Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access t… | Patch early | 7.1 high | 7.7% | 2004-12-31 |
| CVE-2019-8611 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safa… | Patch early | 8.8 high | 7.7% | 2019-12-18 |
| CVE-2019-8671 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safa… | Patch early | 8.8 high | 7.7% | 2019-12-18 |
| CVE-1999-0996 EXP | Buffer overflow in Infoseek Ultraseek search engine allows remote attackers to execute commands via a long GET request. | Patch early | 7.5 high | 7.7% | 1999-12-15 |
| CVE-2006-5558 EXP | Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via format… | Patch early | 10.0 high | 7.7% | 2006-10-27 |
| CVE-2008-0702 EXP | Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of service (daemon crash or hang)… | Patch early | 9.3 high | 7.7% | 2008-02-12 |
| CVE-2008-3155 EXP | Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to cause a denial of serv… | Patch early | 9.3 high | 7.7% | 2008-07-11 |
| CVE-2007-3446 EXP | BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers to obtain login access. | Patch early | 7.5 high | 7.7% | 2007-06-27 |
| CVE-2001-1471 EXP | prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the… | Patch early | 8.8 high | 7.7% | 2001-07-31 |
| CVE-2008-0222 EXP | Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and exe… | Patch early | 7.5 high | 7.7% | 2008-01-10 |
| CVE-2010-0387 EXP | Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to cau… | Patch early | 7.5 high | 7.7% | 2010-01-25 |
| CVE-2007-2988 EXP | A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administrative credentials are missing,… | Patch early | 7.5 high | 7.7% | 2007-06-01 |
| CVE-2020-12351 EXP | Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. | Patch early | 8.8 high | 7.7% | 2020-11-23 |
| CVE-2023-25289 EXP | Directory Traversal vulnerability in virtualreception Digital Receptie version win7sp1_rtm.101119-1850 6.1.7601.1.0.65792 in embedded web server, allo… | Patch early | 7.5 high | 7.7% | 2023-05-04 |
| CVE-2017-0569 EXP | An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the c… | Patch early | 7.0 high | 7.7% | 2017-04-07 |
| CVE-2014-1202 EXP | The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a… | Patch early | 9.3 high | 7.7% | 2014-01-25 |
| CVE-2017-7115 EXP | An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It… | Patch early | 8.1 high | 7.7% | 2017-10-23 |
| CVE-2005-0735 EXP | newsscript.pl for NewsScript allows remote attackers to gain privileges by setting the mode parameter to admin. | Patch early | 10.0 high | 7.7% | 2005-05-02 |
| CVE-2018-6126 EXP | A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML… | Patch early | 8.8 high | 7.7% | 2019-01-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt