CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,620 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-17874 EXP | Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can mak… | Patch early | 8.8 high | 6% | 2017-12-27 |
| CVE-2006-2225 EXP | Buffer overflow in XM Easy Personal FTP Server 4.3 and earlier allows remote attackers to execute arbitrary code, probably via a USER command with a l… | Patch early | 7.5 high | 6% | 2006-05-05 |
| CVE-2006-2408 EXP | Multiple buffer overflows in Raydium before SVN revision 310 allow remote attackers to execute arbitrary code via a large packet when logged via (1) t… | Patch early | 7.5 high | 6% | 2006-05-16 |
| CVE-2001-0173 EXP | Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execut… | Patch early | 10.0 high | 6% | 2001-05-03 |
| CVE-2011-5006 EXP | Stack-based buffer overflow in QQPlayer 3.2.845 allows remote attackers to execute arbitrary code via a crafted PnSize value in a MOV file. | Patch early | 9.3 high | 6% | 2011-12-25 |
| CVE-2004-0241 EXP | X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php. | Patch early | 10.0 high | 6% | 2004-11-23 |
| CVE-2008-3733 EXP | Stack-based buffer overflow in EO Video (eo-video) 1.36 allows remote attackers to cause a denial of service (application crash) or execute arbitrary… | Patch early | 9.3 high | 6% | 2008-08-20 |
| CVE-2009-1071 EXP | Stack-based buffer overflow in Icarus 2.0 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a cra… | Patch early | 9.3 high | 6% | 2009-03-26 |
| CVE-2009-1327 EXP | Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u)… | Patch early | 9.3 high | 6% | 2009-04-17 |
| CVE-2009-4754 EXP | Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (… | Patch early | 9.3 high | 6% | 2010-03-29 |
| CVE-2007-6649 EXP | PHP remote file inclusion vulnerability in includes/tumbnail.php in MatPo Bilder Galerie 1.1 allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 6% | 2008-01-04 |
| CVE-2007-6657 EXP | PHP remote file inclusion vulnerability in source/includes/load_forum.php in Mihalism Multi Forum Host 3.0.x and earlier allows remote attackers to ex… | Patch early | 7.5 high | 6% | 2008-01-04 |
| CVE-2004-0345 EXP | Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name. | Patch early | 10.0 high | 6% | 2004-11-23 |
| CVE-2008-7209 EXP | Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows remote attackers to execute arbi… | Patch early | 7.5 high | 6% | 2009-09-11 |
| CVE-2007-2667 EXP | Buffer overflow in the DB Software Laboratory VImpX ActiveX control in VImpX.ocx 4.7.3 allows remote attackers to execute arbitrary code via a long Lo… | Patch early | 9.3 high | 6% | 2007-05-14 |
| CVE-2008-2283 EXP | IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEnhWMF methods in (a) the IDAuto… | Patch early | 9.3 high | 6% | 2008-05-18 |
| CVE-2016-4312 EXP | XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote auth… | Patch early | 7.5 high | 6% | 2017-02-17 |
| CVE-2002-0747 EXP | Buffer overflow in lsmcode in AIX 4.3.3. | Patch early | 10.0 high | 6% | 2002-08-12 |
| CVE-2018-5708 EXP | An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticated to, the administrator's pan… | Patch early | 8.0 high | 6% | 2018-03-30 |
| CVE-2018-19550 EXP | Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can c… | Patch early | 8.8 high | 6% | 2018-11-26 |
| CVE-2007-6542 EXP | PHP remote file inclusion vulnerability in admin/frontpage_right.php in Arcadem LE 2.04 and earlier allows remote attackers to execute arbitrary PHP c… | Patch early | 7.5 high | 6% | 2007-12-27 |
| CVE-2007-4962 EXP | Directory traversal vulnerability in WinImage 8.10 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a .. (… | Patch early | 9.3 high | 6% | 2007-09-18 |
| CVE-2020-16602 EXP | Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file c… | Patch early | 8.1 high | 6% | 2020-09-02 |
| CVE-2007-5583 EXP | Cisco IP Phone 7940 with firmware P0S3-08-7-00 allows remote attackers to cause a denial of service ("486 Busy" responses or device reboot) via a sequ… | Patch early | 7.8 high | 6% | 2007-12-18 |
| CVE-2003-0317 EXP | iisPROTECT 2.1 and 2.2 allows remote attackers to bypass authentication via an HTTP request containing URL-encoded characters. | Patch early | 7.5 high | 6% | 2003-12-31 |
| CVE-2013-4980 EXP | Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remo… | Patch early | 9.0 high | 6% | 2014-03-03 |
| CVE-2013-4981 EXP | Buffer overflow in cgi-bin/user/Config.cgi in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remo… | Patch early | 9.0 high | 6% | 2014-03-03 |
| CVE-2010-4371 EXP | Buffer overflow in the in_mod plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to the comment box… | Patch early | 9.3 high | 6% | 2010-12-02 |
| CVE-2018-7705 EXP | Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read e-mail messages to arbitrary recipi… | Patch early | 8.1 high | 6% | 2018-03-15 |
| CVE-1999-1553 EXP | Buffer overflow in XCmail 0.99.6 with autoquote enabled allows remote attackers to execute arbitrary commands via a long subject line. | Patch early | 10.0 high | 6% | 1999-05-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt