CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,556 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-2375 EXP | Stack-based buffer overflow in Photo DVD Maker 8.02, and possibly earlier versions, allows remote attackers to execute arbitrary code via a long File_… | Patch early | 9.3 high | 5.1% | 2009-07-08 |
| CVE-2015-5889 EXP | rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving environment variables. | Patch early | 7.2 high | 5.1% | 2015-10-09 |
| CVE-2007-0888 EXP | Directory traversal vulnerability in the TFTP server in Kiwi CatTools before 3.2.0 beta allows remote attackers to read arbitrary files, and upload fi… | Patch early | 10.0 high | 5.1% | 2007-02-12 |
| CVE-2009-2766 EXP | httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remot… | Patch early | 7.5 high | 5.1% | 2009-08-14 |
| CVE-2006-4852 EXP | SQL injection vulnerability in browse.asp in QuadComm Q-Shop 3.5 allows remote attackers to execute arbitrary SQL commands via the OrderBy parameter. | Patch early | 7.5 high | 5.1% | 2006-09-19 |
| CVE-2009-4453 EXP | Insecure method vulnerability in SoftCab Sound Converter ActiveX control (sndConverter.ocx) 1.2 allows remote attackers to create or overwrite arbitra… | Patch early | 8.8 high | 5.1% | 2009-12-29 |
| CVE-2009-2386 EXP | Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to fo… | Patch early | 9.3 high | 5.1% | 2009-07-10 |
| CVE-2008-6920 EXP | Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary code by uploading a file with an… | Patch early | 7.5 high | 5.1% | 2009-08-10 |
| CVE-2008-6921 EXP | Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code by uploading a file with an ex… | Patch early | 7.5 high | 5.1% | 2009-08-10 |
| CVE-2008-3178 EXP | Unrestricted file upload vulnerability in upload_pictures.php in WebXell Editor 0.1.3 allows remote attackers to execute arbitrary code by uploading a… | Patch early | 7.5 high | 5.1% | 2008-07-15 |
| CVE-2007-1766 EXP | PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and earlier allows remote attackers to execute arbitr… | Patch early | 10.0 high | 5.1% | 2007-03-30 |
| CVE-2017-13867 EXP | An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchO… | Patch early | 7.8 high | 5.1% | 2017-12-25 |
| CVE-2017-13876 EXP | An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchO… | Patch early | 7.8 high | 5.1% | 2017-12-25 |
| CVE-2017-2482 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchO… | Patch early | 7.8 high | 5.1% | 2017-04-02 |
| CVE-2006-6864 EXP | PHP remote file inclusion vulnerability in E2_header.inc.php in Enigma2 Coppermine Bridge 1.0 allows remote attackers to execute arbitrary PHP code vi… | Patch early | 10.0 high | 5.1% | 2006-12-31 |
| CVE-2006-4024 EXP | The FESTAHES_Load function in pce/hes.c in Festalon 0.5.0 through 0.5.5 allows user-assisted attackers to cause a denial of service (crash) and possib… | Patch early | 7.5 high | 5.1% | 2006-08-09 |
| CVE-2005-1604 EXP | PHP Advanced Transfer Manager (phpATM) 1.21 allows remote attackers to upload arbitrary files via filenames containing multiple file extensions, as de… | Patch early | 7.5 high | 5.1% | 2005-05-16 |
| CVE-2016-7617 EXP | An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth" component. It allows attackers… | Patch early | 7.8 high | 5.1% | 2017-02-20 |
| CVE-2019-1476 EXP | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of… | Patch early | 7.8 high | 5.1% | 2019-12-10 |
| CVE-2019-12788 EXP | An issue was discovered in Photodex ProShow Producer v9.0.3797 (an application that runs with Administrator privileges). It is possible to perform a b… | Patch early | 7.8 high | 5.1% | 2019-06-10 |
| CVE-2005-2564 EXP | Direct static code injection vulnerability in editcss.php in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary PHP code, HTML, an… | Patch early | 7.5 high | 5.1% | 2005-08-16 |
| CVE-2022-39285 EXP | ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a cross site scripting vulnerabil… | Patch early | 7.6 high | 5.1% | 2022-10-07 |
| CVE-2009-3577 EXP | Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript s… | Patch early | 9.3 high | 5.1% | 2009-11-24 |
| CVE-2016-3989 EXP | The NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M3… | Patch early | 8.1 high | 5.1% | 2016-07-03 |
| CVE-2017-3629 EXP | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11… | Patch early | 7.8 high | 5.1% | 2017-06-22 |
| CVE-2009-1422 EXP | Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to gain privi… | Patch early | 10.0 high | 5.1% | 2009-07-14 |
| CVE-2017-11322 EXP | The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileges via a dollar sign ($) metac… | Patch early | 8.2 high | 5.1% | 2017-10-03 |
| CVE-2005-2651 EXP | gorum/prod.php in Zorum 3.5 allows remote attackers to execute arbitrary code via shell metacharacters in the argv parameter. | Patch early | 7.5 high | 5.1% | 2005-08-23 |
| CVE-2004-0733 EXP | Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via forma… | Patch early | 7.5 high | 5.1% | 2004-07-27 |
| CVE-2002-1452 EXP | Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a long searchTarget parameter. | Patch early | 7.5 high | 5.1% | 2002-08-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt