CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,317 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-4769 EXP | Directory traversal vulnerability in the Jimtawl (com_jimtawl) component 1.0.2 Joomla! allows remote attackers to read arbitrary files and possibly ha… | Patch early | 7.5 high | 7.6% | 2011-03-23 |
| CVE-1999-0239 EXP | Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET. | Patch early | 7.5 high | 7.6% | 1998-01-01 |
| CVE-2006-2236 EXP | Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote atta… | Patch early | 7.6 high | 7.6% | 2006-05-08 |
| CVE-2006-1688 EXP | Multiple PHP remote file inclusion vulnerabilities in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allow remote att… | Patch early | 7.5 high | 7.6% | 2006-04-11 |
| CVE-2010-1214 EXP | Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitra… | Patch early | 9.3 high | 7.6% | 2010-07-30 |
| CVE-2004-1903 EXP | Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an object tag. | Patch early | 10.0 high | 7.6% | 2004-12-31 |
| CVE-2004-2114 EXP | Stack-based and heap-based buffer overflows in ProxyNow! 2.75 and earlier allow remote attackers to execute arbitrary code via a GET request with a lo… | Patch early | 10.0 high | 7.6% | 2004-12-31 |
| CVE-2005-0339 EXP | Buffer overflow in Foxmail 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long MAIL FROM command. | Patch early | 10.0 high | 7.6% | 2005-05-02 |
| CVE-2017-15920 EXP | In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability tha… | Patch early | 7.5 high | 7.6% | 2017-10-30 |
| CVE-2017-15921 EXP | In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability tha… | Patch early | 7.5 high | 7.6% | 2017-10-30 |
| CVE-2008-0100 EXP | Stack-based buffer overflow in the Scene::errorf function in Scene.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbit… | Patch early | 7.5 high | 7.6% | 2008-01-08 |
| CVE-2006-4559 EXP | Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attackers to execute arbitrary PHP co… | Patch early | 7.5 high | 7.6% | 2006-09-06 |
| CVE-2000-1033 EXP | Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attem… | Patch early | 7.5 high | 7.6% | 2000-12-11 |
| CVE-2008-1498 EXP | Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitrary code vi… | Patch early | 9.0 high | 7.6% | 2008-03-25 |
| CVE-2017-6549 EXP | Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U… | Patch early | 8.8 high | 7.6% | 2017-03-09 |
| CVE-2023-34634 EXP | Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .greenshot file is opened. | Patch early | 7.8 high | 7.6% | 2023-08-01 |
| CVE-2020-11803 EXP | An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lea… | Patch early | 8.8 high | 7.6% | 2020-09-17 |
| CVE-2005-0614 EXP | sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie. | Patch early | 7.5 high | 7.6% | 2005-05-02 |
| CVE-2021-28976 EXP | Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess. | Patch early | 7.2 high | 7.5% | 2021-06-23 |
| CVE-2013-3212 EXP | vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execut… | Patch early | 8.1 high | 7.5% | 2020-01-28 |
| CVE-2017-6412 EXP | In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310. | Patch early | 8.1 high | 7.5% | 2017-03-30 |
| CVE-2019-8558 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1,… | Patch early | 8.8 high | 7.5% | 2019-12-18 |
| CVE-2010-1239 EXP | Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Action /S /Launch" sequence, and… | Patch early | 9.3 high | 7.5% | 2010-04-05 |
| CVE-2008-1613 EXP | SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and 7.0, allows remote attackers t… | Patch early | 7.5 high | 7.5% | 2008-04-22 |
| CVE-2009-1807 EXP | Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the Se… | Patch early | 9.3 high | 7.5% | 2009-05-28 |
| CVE-2008-5753 EXP | Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary code via a bookmark file entry… | Patch early | 9.3 high | 7.5% | 2008-12-30 |
| CVE-2019-6279 EXP | ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnerability via the cgi-bin/webproc… | Patch early | 8.8 high | 7.5% | 2019-03-21 |
| CVE-2006-7157 EXP | Buffer overflow in Google Earth v4.0.2091 (beta) allows remote user-assisted attackers to cause a denial of service (crash) via a KML or KMZ file with… | Patch early | 7.1 high | 7.5% | 2007-03-07 |
| CVE-2006-7128 EXP | PHP remote file inclusion vulnerability in forum/forum.php JAF CMS 4.0 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the webs… | Patch early | 7.5 high | 7.5% | 2007-03-06 |
| CVE-2017-7037 EXP | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… | Patch early | 8.8 high | 7.5% | 2017-07-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt