CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,957 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-2375 EXP | Buffer overflow in the POP3 server in 1st Class Mail Server 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbi… | Patch early | 7.5 high | 5.9% | 2004-12-31 |
| CVE-2008-5755 EXP | Stack-based buffer overflow in IntelliTamper 2.07 and 2.08 allows remote attackers to execute arbitrary code via a MAP file containing a long URL, pos… | Patch early | 9.3 high | 5.9% | 2008-12-30 |
| CVE-2002-2379 EXP | Cisco AS5350 IOS 12.2(11)T with access control lists (ACLs) applied and possibly with ssh running allows remote attackers to cause a denial of service… | Patch early | 7.8 high | 5.9% | 2002-12-31 |
| CVE-2006-6055 EXP | Stack-based buffer overflow in A5AGU.SYS 1.0.1.41 for the D-Link DWL-G132 wireless adapter allows remote attackers to execute arbitrary code via a 802… | Patch early | 10.0 high | 5.9% | 2006-11-22 |
| CVE-2009-0349 EXP | Stack-based buffer overflow in FTPShell Server 4.3 allows user-assisted remote attackers to cause a denial of service (persistent daemon crash) and po… | Patch early | 9.3 high | 5.9% | 2009-01-29 |
| CVE-2009-0491 EXP | Stack-based buffer overflow in Elecard MPEG Player 5.5 build 15884.081218 allows remote attackers to execute arbitrary code via a M3U file containing… | Patch early | 9.3 high | 5.9% | 2009-02-10 |
| CVE-2009-1449 EXP | Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.1 allows remote attackers to execute arbitrary code vi… | Patch early | 9.3 high | 5.9% | 2009-04-27 |
| CVE-2009-2384 EXP | Buffer overflow in amp.exe in Brothersoft PEamp 1.02b allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3u play… | Patch early | 9.3 high | 5.9% | 2009-07-08 |
| CVE-2009-3536 EXP | Multiple stack-based buffer overflows in EpicDJSoftware EpicVJ 1.2.8.0 and 1.3.1.2 allow remote attackers to cause a denial of service (application cr… | Patch early | 9.3 high | 5.9% | 2009-10-02 |
| CVE-2000-0437 EXP | Buffer overflow in the CyberPatrol daemon "cyberdaemon" used in gauntlet and WebShield allows remote attackers to cause a denial of service or execute… | Patch early | 10.0 high | 5.9% | 2000-05-18 |
| CVE-2000-0584 EXP | Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name… | Patch early | 10.0 high | 5.9% | 2000-07-02 |
| CVE-2000-0706 EXP | Buffer overflows in ntop running in web mode allows remote attackers to execute arbitrary commands. | Patch early | 10.0 high | 5.9% | 2000-10-20 |
| CVE-2003-0509 EXP | SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via t… | Patch early | 10.0 high | 5.9% | 2003-08-07 |
| CVE-2006-1232 EXP | Multiple SQL injection vulnerabilities in DSDownload 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via… | Patch early | 7.5 high | 5.9% | 2006-03-14 |
| CVE-2009-1329 EXP | Stack-based buffer overflow in Mini-stream Shadow Stream Recorder 3.0.1.7 allows remote attackers to execute arbitrary code via a long URI in a playli… | Patch early | 9.3 high | 5.8% | 2009-04-17 |
| CVE-2009-1815 EXP | Stack-based buffer overflow in Sonic Spot Audioactive Player 1.93b allows remote attackers to execute arbitrary code via a long string in a playlist f… | Patch early | 9.3 high | 5.8% | 2009-05-29 |
| CVE-2010-2146 EXP | PHP remote file inclusion vulnerability in banned.php in Visitor Logger allows remote attackers to execute arbitrary PHP code via a URL in the VL_incl… | Patch early | 7.5 high | 5.8% | 2010-06-03 |
| CVE-1999-0455 EXP | The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does n… | Patch early | 7.5 high | 5.8% | 1999-12-25 |
| CVE-2007-3071 EXP | Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSellerate SDK allows user-assisted… | Patch early | 9.3 high | 5.8% | 2007-06-06 |
| CVE-2011-4334 EXP | edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload arbitrary PHP file… | Patch early | 8.8 high | 5.8% | 2017-10-23 |
| CVE-2019-17525 EXP | The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks. | Patch early | 8.8 high | 5.8% | 2020-04-21 |
| CVE-2007-1412 EXP | The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensitive information (script source… | Patch early | 7.8 high | 5.8% | 2007-03-12 |
| CVE-2017-6088 EXP | Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to execute arbitrary SQL commands v… | Patch early | 7.2 high | 5.8% | 2017-04-11 |
| CVE-2018-6323 EXP | The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, has an unsigne… | Patch early | 7.8 high | 5.8% | 2018-01-26 |
| CVE-2010-4884 EXP | PHP remote file inclusion vulnerability in guestbook/gbook.php in Gaestebuch 1.2 allows remote attackers to execute arbitrary PHP code via a URL in th… | Patch early | 7.5 high | 5.8% | 2011-10-07 |
| CVE-2002-1951 EXP | Buffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request with a large number of subdirec… | Patch early | 7.5 high | 5.8% | 2002-12-31 |
| CVE-2010-4170 EXP | The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gain privileg… | Patch early | 7.2 high | 5.8% | 2010-12-07 |
| CVE-2017-2362 EXP | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. Th… | Patch early | 8.8 high | 5.8% | 2017-02-20 |
| CVE-2018-4382 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1… | Patch early | 8.8 high | 5.8% | 2019-04-03 |
| CVE-2018-4438 EXP | A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue affected versions prior to iOS 12.… | Patch early | 8.8 high | 5.8% | 2019-04-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt