CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,997 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-4013 EXP | IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code… | Patch early | 9.0 critical | 13% | 2019-04-10 |
| CVE-2006-3581 EXP | Multiple stack-based buffer overflows in Audacious AdPlug 2.0 and earlier allow remote user-assisted attackers to execute arbitrary code via large (1)… | Patch early | 5.1 medium | 13% | 2006-07-13 |
| CVE-2009-4488 EXP | Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or… | Patch early | 9.8 critical | 13% | 2010-01-13 |
| CVE-2017-8871 EXP | The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and C… | Patch early | 6.5 medium | 13% | 2017-06-12 |
| CVE-2002-0289 EXP | Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP request. | Patch early | 5.0 medium | 13% | 2002-05-31 |
| CVE-2010-1952 EXP | Directory traversal vulnerability in the BeeHeard (com_beeheard) and BeeHeard Lite (com_beeheardlite) component 1.0 for Joomla! allows remote attacker… | Patch early | 7.5 high | 13% | 2010-05-19 |
| CVE-2011-2780 EXP | Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) i… | Patch early | 5.0 medium | 13% | 2011-07-19 |
| CVE-2006-1776 EXP | PHP remote file inclusion vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 13% | 2006-04-13 |
| CVE-2008-2303 EXP | Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a d… | Patch early | 10.0 high | 13% | 2008-07-14 |
| CVE-2017-7462 EXP | Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory. | Patch early | 9.8 critical | 13% | 2017-04-11 |
| CVE-2000-0622 EXP | Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL… | Patch early | 10.0 high | 13% | 2000-07-19 |
| CVE-2013-2009 EXP | WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution | Patch early | 8.8 high | 13% | 2020-02-07 |
| CVE-2012-3571 EXP | ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) vi… | Patch early | 6.1 medium | 13% | 2012-07-25 |
| CVE-2012-0985 EXP | Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wireless Wizard… | Patch early | 9.3 high | 13% | 2012-06-07 |
| CVE-2008-1802 EXP | Buffer overflow in the process_redirect_pdu (rdp.c) function in rdesktop 1.5.0 allows remote attackers to execute arbitrary code via a Remote Desktop… | Patch early | 9.3 high | 13% | 2008-05-12 |
| CVE-2013-2227 EXP | GLPI 0.83.7 has Local File Inclusion in common.tabs.php. | Patch early | 7.5 high | 13% | 2019-11-01 |
| CVE-2013-4117 EXP | Cross-site scripting (XSS) vulnerability in includes/CatGridPost.php in the Category Grid View Gallery plugin 2.3.1 for WordPress allows remote attack… | Patch early | 4.3 medium | 13% | 2013-07-16 |
| CVE-2010-0157 EXP | Directory traversal vulnerability in the Bible Study (com_biblestudy) component 6.1 for Joomla! allows remote attackers to include and execute arbitra… | Patch early | 7.5 high | 13% | 2010-01-06 |
| CVE-2000-1035 EXP | Buffer overflows in TYPSoft FTP Server 0.78 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands v… | Patch early | 10.0 high | 13% | 2000-12-11 |
| CVE-2001-0280 EXP | Buffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command. | Patch early | 10.0 high | 13% | 2001-05-03 |
| CVE-2007-4034 EXP | Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPC… | Patch early | 9.3 high | 13% | 2007-07-27 |
| CVE-2009-2511 EXP | Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, a… | Patch early | 7.5 high | 13% | 2009-10-14 |
| CVE-2019-15039 EXP | An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1. | Patch early | 9.8 critical | 12.9% | 2019-10-01 |
| CVE-2010-2626 EXP | index.pl in Miyabi CGI Tools SEO Links 1.02 allows remote attackers to execute arbitrary commands via shell metacharacters in the fn command. NOTE: so… | Patch early | 7.5 high | 12.9% | 2010-07-02 |
| CVE-2024-27746 EXP | SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email ad… | Patch early | 9.8 critical | 12.9% | 2024-03-01 |
| CVE-2002-1209 EXP | Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (d… | Patch early | 5.0 medium | 12.9% | 2002-11-04 |
| CVE-2005-4466 EXP | Heap-based buffer overflow in the SIPParser function in i3sipmsg.dll in Interaction SIP Proxy before 3.0.011 allows remote attackers to cause a denial… | Patch early | 7.5 high | 12.9% | 2005-12-22 |
| CVE-2006-7079 EXP | Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables a… | Patch early | 9.8 critical | 12.9% | 2007-03-02 |
| CVE-2019-9491 EXP | Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the… | Patch early | 7.8 high | 12.9% | 2019-10-21 |
| CVE-2005-2277 EXP | Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file… | Patch early | 10.0 high | 12.9% | 2005-07-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt