CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,553 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-3532 EXP | SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 5.4% | 2013-05-10 |
| CVE-2008-2111 EXP | The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in t… | Patch early | 9.3 high | 5.4% | 2008-05-07 |
| CVE-2007-2487 EXP | Stack-based buffer overflow in AtomixMP3 allows remote attackers to execute arbitrary code via a long filename in an MP3 file, a different vector than… | Patch early | 7.5 high | 5.4% | 2007-05-03 |
| CVE-2007-0117 EXP | DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows att… | Patch early | 10.0 high | 5.4% | 2007-01-09 |
| CVE-2007-4060 EXP | Multiple buffer overflows in the HttpSprockMake function in http.c in Frank Yaul corehttp 0.5.3alpha allow remote attackers to execute arbitrary code… | Patch early | 9.0 high | 5.4% | 2007-07-30 |
| CVE-2017-3622 EXP | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (CDE)). The supported version th… | Patch early | 7.8 high | 5.4% | 2017-04-24 |
| CVE-2008-6935 EXP | Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cau… | Patch early | 10.0 high | 5.4% | 2009-08-11 |
| CVE-2004-1717 EXP | Multiple buffer overflows in the psscan function in ps.c for gv (ghostview) allow remote attackers to execute arbitrary code via a Postscript file wit… | Patch early | 7.5 high | 5.4% | 2004-08-16 |
| CVE-2023-34723 EXP | An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information via /config/system.conf. | Patch early | 7.5 high | 5.4% | 2023-08-25 |
| CVE-2003-1210 EXP | Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands v… | Patch early | 7.5 high | 5.4% | 2003-12-31 |
| CVE-2008-0337 EXP | Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to execute arbitrary c… | Patch early | 7.5 high | 5.4% | 2008-01-17 |
| CVE-2003-1160 EXP | FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.h… | Patch early | 10.0 high | 5.4% | 2003-10-30 |
| CVE-2005-0633 EXP | Buffer overflow in Trillian 3.0 and Pro 3.0 allows remote attackers to execute arbitrary code via a crafted PNG image file. | Patch early | 7.5 high | 5.3% | 2005-03-02 |
| CVE-2009-0241 EXP | Stack-based buffer overflow in the process_path function in gmetad/server.c in Ganglia 3.1.1 allows remote attackers to cause a denial of service (cra… | Patch early | 7.5 high | 5.3% | 2009-01-21 |
| CVE-2023-30350 EXP | FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin password. | Patch early | 8.8 high | 5.3% | 2023-05-29 |
| CVE-2001-0442 EXP | Buffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly execute arbi… | Patch early | 7.5 high | 5.3% | 2001-06-27 |
| CVE-2002-0332 EXP | Buffer overflows in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to execute arbitrary code via (1) a long DNS hostna… | Patch early | 7.5 high | 5.3% | 2002-06-25 |
| CVE-2010-4280 EXP | Multiple SQL injection vulnerabilities in Pandora FMS before 3.1.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the id_g… | Patch early | 7.5 high | 5.3% | 2010-12-02 |
| CVE-2007-0016 EXP | Stack-based buffer overflow in MoviePlay 4.76 allows remote attackers to execute arbitrary code via a long filename in a LST file. | Patch early | 7.5 high | 5.3% | 2007-01-03 |
| CVE-1999-0477 EXP | The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not… | Patch early | 7.5 high | 5.3% | 1999-12-25 |
| CVE-1999-0753 EXP | The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories. | Patch early | 7.5 high | 5.3% | 1999-08-17 |
| CVE-2003-0320 EXP | header.php in ttCMS 2.3 and earlier allows remote attackers to inject arbitrary PHP code by setting the ttcms_user_admin parameter to "1" and modifyin… | Patch early | 7.5 high | 5.3% | 2003-06-09 |
| CVE-2009-1039 EXP | Buffer overflow in CDex 1.70b2 allows remote attackers to execute arbitrary code via a crafted Info header in an Ogg Vorbis (.ogg) file. | Patch early | 7.5 high | 5.3% | 2009-03-20 |
| CVE-2007-5265 EXP | Multiple format string vulnerabilities in websrv.cpp in Dawn of Time 1.69s beta4 and earlier allow remote attackers to execute arbitrary code via form… | Patch early | 7.5 high | 5.3% | 2007-10-08 |
| CVE-2023-21752 EXP | Windows Backup Service Elevation of Privilege Vulnerability | Patch early | 7.1 high | 5.3% | 2023-01-10 |
| CVE-2024-11237 EXP | A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this issue is some unknown functio… | Patch early | 7.5 high | 5.3% | 2024-11-15 |
| CVE-2008-6186 EXP | Stack-based buffer overflow in RaidenFTPD 2.4 build 3620 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary c… | Patch early | 9.0 high | 5.3% | 2009-02-19 |
| CVE-2008-6899 EXP | Multiple buffer overflows in freeSSHd 1.2.1 allow remote authenticated users to cause a denial of service (crash) and execute arbitrary code via a lon… | Patch early | 9.0 high | 5.3% | 2009-08-05 |
| CVE-2007-5332 EXP | Multiple unspecified vulnerabilities in (1) mediasvr and (2) caloggerd in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10… | Patch early | 10.0 high | 5.3% | 2007-10-13 |
| CVE-2010-1686 EXP | Stack-based buffer overflow in (1) Urgent Backup 3.20, and (2) ABC Backup Pro 5.20 and ABC Backup 5.50, allows user-assisted remote attackers to execu… | Patch early | 9.3 high | 5.3% | 2010-05-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt