CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,488 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-5850 EXP | Stack-based buffer overflow in Essentia Web Server 2.15 for Windows allows remote attackers to execute arbitrary code via a long URI, as demonstrated… | Patch early | 7.5 high | 7.2% | 2006-11-10 |
| CVE-2003-1518 EXP | Adiscon WinSyslog 4.21 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a long syslog message. | Patch early | 7.8 high | 7.2% | 2003-12-31 |
| CVE-2018-10253 EXP | Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls. | Patch early | 7.5 high | 7.2% | 2018-04-21 |
| CVE-2007-2563 EXP | Buffer overflow in the AddFile function in VersalSoft HTTP File Upload ActiveX control (UFileUploaderD.dll) allows remote attackers to execute arbitra… | Patch early | 9.3 high | 7.2% | 2007-05-09 |
| CVE-2004-1400 EXP | The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unauthorized access via a direct re… | Patch early | 7.5 high | 7.2% | 2004-12-31 |
| CVE-2017-15879 EXP | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before… | Patch early | 8.8 high | 7.2% | 2017-10-24 |
| CVE-2009-1634 EXP | The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, whic… | Patch early | 7.5 high | 7.2% | 2009-05-26 |
| CVE-1999-1018 EXP | IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker t… | Patch early | 7.5 high | 7.2% | 1999-07-27 |
| CVE-2007-1649 EXP | PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a serialized data input string beginnin… | Patch early | 7.8 high | 7.2% | 2007-03-24 |
| CVE-2017-7046 EXP | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… | Patch early | 8.8 high | 7.2% | 2017-07-20 |
| CVE-2010-1177 EXP | Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… | Patch early | 9.3 high | 7.2% | 2010-03-29 |
| CVE-2000-0640 EXP | Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, which provides different error… | Patch early | 7.5 high | 7.2% | 2000-07-08 |
| CVE-2009-1227 EXP | NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI Web Service allows remote atta… | Patch early | 10.0 high | 7.2% | 2009-04-02 |
| CVE-2007-5110 EXP | Absolute path traversal vulnerability in the EbCrypt.eb_c_PRNGenerator.1 ActiveX control in EBCRYPT.DLL 2.0.0.2087 and earlier in EB Design ebCrypt al… | Patch early | 7.5 high | 7.2% | 2007-09-26 |
| CVE-2022-40319 EXP | The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa… | Patch early | 7.5 high | 7.2% | 2023-01-17 |
| CVE-2007-2192 EXP | Buffer overflow in Photofiltre Studio 8.1.1 allows user-assisted remote attackers to execute arbitrary code via a crafted .tif file. | Patch early | 9.3 high | 7.2% | 2007-04-24 |
| CVE-2009-1611 EXP | Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 257 reply to a CWD comman… | Patch early | 10.0 high | 7.2% | 2009-05-11 |
| CVE-2002-0319 EXP | Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other… | Patch early | 7.5 high | 7.2% | 2002-06-25 |
| CVE-2002-1481 EXP | savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbi… | Patch early | 7.5 high | 7.2% | 2003-04-22 |
| CVE-2010-0388 EXP | Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a den… | Patch early | 7.5 high | 7.2% | 2010-01-25 |
| CVE-2017-6087 EXP | EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the selected_events[] pa… | Patch early | 8.8 high | 7.2% | 2017-03-24 |
| CVE-2009-2257 EXP | The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to… | Patch early | 7.8 high | 7.2% | 2009-06-30 |
| CVE-2000-0696 EXP | The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts,… | Patch early | 7.5 high | 7.2% | 2000-10-20 |
| CVE-2001-0987 EXP | Cross-site scripting vulnerability in CGIWrap before 3.7 allows remote attackers to execute arbitrary Javascript on other web clients by causing the J… | Patch early | 7.5 high | 7.2% | 2001-07-22 |
| CVE-2002-0451 EXP | filemanager_forms.php in PHProjekt 3.1 and 3.1a allows remote attackers to execute arbitrary PHP code by specifying the URL to the code in the lib_pat… | Patch early | 7.5 high | 7.2% | 2002-08-12 |
| CVE-2002-0959 EXP | Cross-site scripting vulnerability in Splatt Forum 3.0 allows remote attackers to execute arbitrary script as other users via an [img] tag with a clos… | Patch early | 7.5 high | 7.2% | 2002-10-04 |
| CVE-2002-1036 EXP | Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to execute web scrip… | Patch early | 7.5 high | 7.2% | 2002-10-04 |
| CVE-2012-0242 EXP | Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers… | Patch early | 10.0 high | 7.2% | 2012-02-21 |
| CVE-2007-2856 EXP | Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used, allows u… | Patch early | 9.3 high | 7.2% | 2007-05-24 |
| CVE-2014-3418 EXP | config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the skipj… | Patch early | 10.0 high | 7.2% | 2014-07-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt