CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,032 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-1904 EXP | Buffer overflow in the Log function in util.c in GazTek ghttpd 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a long HTTP GET… | Patch early | 7.5 high | 5.6% | 2002-12-31 |
| CVE-2005-1784 EXP | Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in… | Patch early | 7.5 high | 5.6% | 2005-05-27 |
| CVE-2005-3304 EXP | Multiple SQL injection vulnerabilities in PHP-Nuke 7.8 allow remote attackers to modify SQL queries and execute arbitrary PHP code via (1) the usernam… | Patch early | 7.5 high | 5.6% | 2005-10-26 |
| CVE-2018-4193 EXP | An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Windows Server" component. It allows atta… | Patch early | 7.8 high | 5.6% | 2018-06-08 |
| CVE-2008-2573 EXP | Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a long directory name in an SSH_… | Patch early | 8.5 high | 5.6% | 2008-06-06 |
| CVE-2003-0803 EXP | Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED acces… | Patch early | 7.5 high | 5.6% | 2003-10-06 |
| CVE-2003-0586 EXP | Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php. | Patch early | 7.5 high | 5.6% | 2003-08-18 |
| CVE-2006-2411 EXP | Buffer overflow in raydium_network_read function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to execute arbitrary cod… | Patch early | 7.5 high | 5.6% | 2006-05-16 |
| CVE-2017-15035 EXP | EmTec PyroBatchFTP before 3.18 allows remote servers to cause a denial of service (application crash). | Patch early | 7.5 high | 5.6% | 2017-10-05 |
| CVE-2009-4216 EXP | Directory traversal vulnerability in funzioni/lib/menulast.php in klinza professional cms 5.0.1 and earlier allows remote attackers to include and exe… | Patch early | 9.3 high | 5.6% | 2009-12-07 |
| CVE-2016-1827 EXP | The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a… | Patch early | 7.8 high | 5.6% | 2016-05-20 |
| CVE-2006-2645 EXP | PHP remote file inclusion vulnerability in manager/frontinc/prepend.php for Plume 1.0.3 allows remote attackers to execute arbitrary code via a URL in… | Patch early | 7.5 high | 5.6% | 2006-05-30 |
| CVE-2000-0343 EXP | Buffer overflow in Sniffit 0.3.x with the -L logging option enabled allows remote attackers to execute arbitrary commands via a long MAIL FROM mail he… | Patch early | 10.0 high | 5.6% | 2000-05-02 |
| CVE-2007-0766 EXP | Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of service (application crash) a… | Patch early | 9.3 high | 5.6% | 2007-02-06 |
| CVE-2013-4091 EXP | The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocomplete attribute for the passwo… | Patch early | 7.5 high | 5.6% | 2013-06-28 |
| CVE-2002-0895 EXP | Buffer overflow in MatuFtpServer 1.1.3.0 (1.1.3) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long P… | Patch early | 7.5 high | 5.6% | 2002-10-04 |
| CVE-2007-5824 EXP | webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon cr… | Patch early | 7.1 high | 5.6% | 2007-11-05 |
| CVE-2009-4836 EXP | Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbitrary PHP code via the anticod… | Patch early | 7.5 high | 5.6% | 2010-05-06 |
| CVE-2008-6363 EXP | Stack-based buffer overflow in DesignWorks Professional 4.3.1 and 5.0.7 allows remote attackers to execute arbitrary code via a crafted .cct file. NO… | Patch early | 9.3 high | 5.6% | 2009-03-02 |
| CVE-2009-0298 EXP | Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allows remote attackers to execute… | Patch early | 9.3 high | 5.6% | 2009-01-27 |
| CVE-2009-0443 EXP | Stack-based buffer overflow in Elecard AVC HD PLAYER 5.5.90116 allows remote attackers to execute arbitrary code via an M3U file containing a long str… | Patch early | 9.3 high | 5.6% | 2009-02-10 |
| CVE-2009-2617 EXP | Stack-based buffer overflow in medialib.dll in BaoFeng Storm 3.9.62 allows remote attackers to execute arbitrary code via a long pathname in the sourc… | Patch early | 9.3 high | 5.6% | 2009-07-27 |
| CVE-2009-2896 EXP | Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code… | Patch early | 9.3 high | 5.6% | 2009-08-20 |
| CVE-2009-3058 EXP | Stack-based buffer overflow in akPlayer 1.9.0 allows remote attackers to execute arbitrary code via a long string in a .plt playlist file. | Patch early | 9.3 high | 5.6% | 2009-09-03 |
| CVE-2009-4668 EXP | Stack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute arbitrary code via a long ID3… | Patch early | 9.3 high | 5.6% | 2010-03-05 |
| CVE-2010-2331 EXP | Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to execute arbitrary code via a long HEAD request. | Patch early | 9.3 high | 5.6% | 2010-06-18 |
| CVE-2010-2440 EXP | Stack-based buffer overflow in st-wizard.exe in Subtitle Translation Wizard 3.0 allows user-assisted remote attackers to execute arbitrary code via a… | Patch early | 9.3 high | 5.6% | 2010-06-24 |
| CVE-2014-3444 EXP | The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to execute arbitrary code or cause a… | Patch early | 9.3 high | 5.6% | 2014-05-20 |
| CVE-2004-2359 EXP | Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray applet, which… | Patch early | 10.0 high | 5.6% | 2004-12-31 |
| CVE-2005-2420 EXP | flsearch.pl in FtpLocate 2.02 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP GET request. | Patch early | 10.0 high | 5.6% | 2005-08-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt