CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,488 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-2651 EXP | Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5. | Patch early | 9.8 critical | 15.8% | 2022-08-04 |
| CVE-2005-0566 EXP | Buffer overflow in Golden FTP Server Pro (goldenftpd) 2.x allows remote attackers to execute arbitrary code via a long RNTO command. | Patch early | 7.5 high | 15.7% | 2005-01-22 |
| CVE-2010-1759 EXP | Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows r… | Patch early | 9.3 high | 15.7% | 2010-06-11 |
| CVE-2021-43136 EXP | An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platfor… | Patch early | 9.8 critical | 15.7% | 2021-11-10 |
| CVE-2011-1206 EXP | Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before… | Patch early | 10.0 high | 15.7% | 2011-04-21 |
| CVE-2010-1306 EXP | Directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote attackers to read arbitrary loca… | Patch early | 7.5 high | 15.7% | 2010-04-08 |
| CVE-2010-1875 EXP | Directory traversal vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to read arbitra… | Patch early | 7.5 high | 15.7% | 2010-05-12 |
| CVE-2018-1218 EXP | In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the 'nsrd' daemon causes a buffer o… | Patch early | 7.5 high | 15.7% | 2018-03-19 |
| CVE-2004-1325 EXP | The getItemInfoByAtom function in the ActiveX control for Microsoft Windows Media Player 9.0 returns a 0 if the file does not exist and the size of th… | Patch early | 5.0 medium | 15.7% | 2004-12-18 |
| CVE-2008-4327 EXP | gdiplus.dll in GDI+ in Microsoft Windows XP SP3 does not properly handle crafted .ico files, which allows remote attackers to cause a denial of servic… | Patch early | 4.3 medium | 15.7% | 2008-09-30 |
| CVE-2010-2351 EXP | Stack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remote attackers to execute arbitr… | Patch early | 10.0 high | 15.7% | 2010-06-21 |
| CVE-2000-0200 EXP | Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art l… | Patch early | 5.1 medium | 15.7% | 2000-03-06 |
| CVE-2006-4489 EXP | Multiple PHP remote file inclusion vulnerabilities in MiniBill 2006-07-14 (1.2.2) allow remote attackers to execute arbitrary PHP code via (1) a URL i… | Patch early | 7.5 high | 15.7% | 2006-08-31 |
| CVE-2019-8375 EXP | The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script… | Patch early | 9.8 critical | 15.7% | 2019-02-24 |
| CVE-2019-3924 EXP | MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The software will execute user defin… | Patch early | 7.5 high | 15.7% | 2019-02-20 |
| CVE-2010-1602 EXP | Directory traversal vulnerability in the ZiMB Comment (com_zimbcomment) component 0.8.1 for Joomla! allows remote attackers to read arbitrary files an… | Patch early | 7.5 high | 15.7% | 2010-04-29 |
| CVE-2019-14696 EXP | Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter. | Patch early | 6.1 medium | 15.7% | 2019-08-06 |
| CVE-2005-2856 EXP | Stack-based buffer overflow in the WinACE UNACEV2.DLL third-party compression utility before 2.6.0.0, as used in multiple products including (1) ALZip… | Patch early | 7.5 high | 15.7% | 2005-09-08 |
| CVE-2008-3443 EXP | The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows re… | Patch early | 5.0 medium | 15.7% | 2008-08-14 |
| CVE-2007-2356 EXP | Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attackers to e… | Patch early | 6.8 medium | 15.7% | 2007-04-30 |
| CVE-2017-12965 EXP | Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter. | Patch early | 9.8 critical | 15.7% | 2017-08-23 |
| CVE-2009-1335 EXP | Microsoft Internet Explorer 7 and 8 on Windows XP and Vista allows remote attackers to cause a denial of service (application hang) via a large docume… | Patch early | 4.3 medium | 15.7% | 2009-04-17 |
| CVE-2021-38759 EXP | Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator privileges. | Patch early | 9.8 critical | 15.7% | 2021-12-07 |
| CVE-2008-0220 EXP | Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunc… | Patch early | 7.5 high | 15.7% | 2008-01-10 |
| CVE-2004-0659 EXP | Buffer overflow in TranslateFilename for common.c in MPlayer 1.0pre4 allows remote attackers to execute arbitrary code via a long file name. | Patch early | 10.0 high | 15.7% | 2004-08-06 |
| CVE-2007-5219 EXP | Directory traversal vulnerability in the CLAVSetting.CLSetting.1 ActiveX control in CLAVSetting.DLL 1.00.1829 in the CLAVSetting module in CyberLink P… | Patch early | 6.4 medium | 15.7% | 2007-10-05 |
| CVE-2008-3242 EXP | Heap-based buffer overflow in the PPMedia Class ActiveX control in PPMPlayer.dll in PPMate 2.3.1.93 allows remote attackers to execute arbitrary code… | Patch early | 10.0 high | 15.7% | 2008-07-21 |
| CVE-2014-9119 EXP | Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary file… | Patch early | 5.0 medium | 15.7% | 2014-12-31 |
| CVE-2006-3172 EXP | Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary PHP code via a URL with a trai… | Patch early | 7.5 high | 15.6% | 2006-06-23 |
| CVE-2004-0354 EXP | Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code via forma… | Patch early | 10.0 high | 15.6% | 2004-11-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt