CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,957 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2000-0493 EXP | Buffer overflow in Simple Network Time Sync (SMTS) daemon allows remote attackers to cause a denial of service and possibly execute arbitrary commands… | Patch early | 10.0 high | 6% | 2000-06-01 |
| CVE-2000-1026 EXP | Multiple buffer overflows in LBNL tcpdump allow remote attackers to execute arbitrary commands. | Patch early | 10.0 high | 6% | 2000-12-11 |
| CVE-2009-3664 EXP | Multiple directory traversal vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to include or execute arbitrary files via a .. (… | Patch early | 7.5 high | 6% | 2009-10-11 |
| CVE-2007-3365 EXP | MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions, which allows remote attackers to obtain sensitive inf… | Patch early | 7.5 high | 6% | 2007-06-22 |
| CVE-2017-6074 EXP | The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the L… | Patch early | 7.8 high | 6% | 2017-02-18 |
| CVE-2007-2272 EXP | PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0 allows remote attackers to ex… | Patch early | 7.5 high | 6% | 2007-04-25 |
| CVE-2001-1080 EXP | diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileg… | Patch early | 10.0 high | 6% | 2001-06-19 |
| CVE-2017-7183 EXP | The TFTP server in ExtraPuTTY 0.30 and earlier allows remote attackers to cause a denial of service (crash) via a large (1) read or (2) write TFTP pro… | Patch early | 7.5 high | 5.9% | 2017-03-27 |
| CVE-2009-1058 EXP | Stack-based buffer overflow in ZipGenius might allow remote attackers to execute arbitrary code via a crafted .zip file that triggers an SEH overwrite… | Patch early | 10.0 high | 5.9% | 2009-03-24 |
| CVE-2007-2169 EXP | Static code injection vulnerability in add.php in Mozzers SubSystem 1.0 allows remote attackers to inject PHP code into subs.php via the (1) Sub-name… | Patch early | 7.5 high | 5.9% | 2007-04-22 |
| CVE-2008-6519 EXP | Format string vulnerability in Xitami Web Server 2.2a through 2.5c2, and possibly other versions, allows remote attackers to cause a denial of service… | Patch early | 10.0 high | 5.9% | 2009-03-25 |
| CVE-2009-2396 EXP | PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress plugin, allows remote attackers… | Patch early | 9.3 high | 5.9% | 2009-07-09 |
| CVE-2008-6745 EXP | index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a register2 action. | Patch early | 7.5 high | 5.9% | 2009-04-23 |
| CVE-2008-4583 EXP | Insecure method vulnerability in the Chilkat FTP 2.0 ActiveX component (ChilkatCert.dll) allows remote attackers to overwrite arbitrary files via a fu… | Patch early | 7.5 high | 5.9% | 2008-10-15 |
| CVE-2009-1370 EXP | Stack-based buffer overflow in ape_plugin.plg in Xilisoft Video Converter 3.1.53.0704n and 5.1.23.0402 allows remote attackers to cause a denial of se… | Patch early | 9.3 high | 5.9% | 2009-04-22 |
| CVE-2008-5991 EXP | Directory traversal vulnerability in docs.php in MailWatch for MailScanner 1.0.4 and earlier allows remote attackers to include and execute arbitrary… | Patch early | 7.5 high | 5.9% | 2009-01-28 |
| CVE-2013-2817 EXP | An ActiveX control in IcoLaunch.dll in Mitsubishi Electric Automation MC-WorX Suite 8.02 allows user-assisted remote attackers to execute arbitrary pr… | Patch early | 9.3 high | 5.9% | 2014-02-24 |
| CVE-2008-3024 EXP | Stack-based buffer overflow in phgrafx in QNX Momentics (aka RTOS) 6.3.2 and earlier allows local users to gain privileges via a long .pal filename in… | Patch early | 9.3 high | 5.9% | 2008-07-07 |
| CVE-2003-0647 EXP | Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via an extremely long (2GB) HTTP G… | Patch early | 7.5 high | 5.9% | 2003-08-27 |
| CVE-2009-2333 EXP | Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execute arbitrary local files via a… | Patch early | 7.5 high | 5.9% | 2009-07-05 |
| CVE-2014-8386 EXP | Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted (1) display… | Patch early | 7.5 high | 5.9% | 2015-01-20 |
| CVE-2014-0358 EXP | Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read arbitrary files via a .. (dot do… | Patch early | 7.8 high | 5.9% | 2014-04-15 |
| CVE-2017-2521 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. wa… | Patch early | 8.8 high | 5.9% | 2017-05-22 |
| CVE-2009-3709 EXP | Stack-based buffer overflow in the Meta Content Optimizer in Konae Technologies Alleycode HTML Editor 2.21 allows user-assisted remote attackers to ex… | Patch early | 9.3 high | 5.9% | 2009-10-16 |
| CVE-2000-0384 EXP | NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure's MAC add… | Patch early | 10.0 high | 5.9% | 2000-05-08 |
| CVE-2000-0300 EXP | The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt PcAnywhere or NT domain accou… | Patch early | 10.0 high | 5.9% | 2000-04-06 |
| CVE-2007-6555 EXP | PHP remote file inclusion vulnerability in modules/mod_pxt_latest.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote at… | Patch early | 9.3 high | 5.9% | 2007-12-28 |
| CVE-2018-6388 EXP | iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell metacharacters in t… | Patch early | 8.8 high | 5.9% | 2018-01-29 |
| CVE-2010-2127 EXP | PHP remote file inclusion vulnerability in gallery.php in JV2 Folder Gallery 3.1 allows remote attackers to execute arbitrary PHP code via a URL in th… | Patch early | 7.5 high | 5.9% | 2010-06-01 |
| CVE-2010-2137 EXP | PHP remote file inclusion vulnerability in _center.php in ProMan 0.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 5.9% | 2010-06-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt