CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,556 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-7178 EXP | Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP… | Patch early | 9.3 high | 5.1% | 2014-11-28 |
| CVE-2019-7652 EXP | TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the vulnerability, an attacker mus… | Patch early | 7.7 high | 5.1% | 2019-05-09 |
| CVE-2010-2701 EXP | Multiple buffer overflows in the FathFTP ActiveX control 1.7 allow remote attackers to execute arbitrary code via (1) the GetFromURL member or (2) a l… | Patch early | 9.3 high | 5.1% | 2010-07-12 |
| CVE-2009-1646 EXP | Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long rtsp URL in a .ram file. | Patch early | 9.3 high | 5.1% | 2009-05-15 |
| CVE-2003-0705 EXP | Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code. | Patch early | 7.5 high | 5.1% | 2003-09-17 |
| CVE-2008-7070 EXP | Argument injection vulnerability in the URI handler in KVIrc 3.4.2 Shiny allows remote attackers to execute arbitrary commands via a " (quote) followe… | Patch early | 9.3 high | 5.1% | 2009-08-25 |
| CVE-2008-2922 EXP | Stack-based buffer overflow in artegic Dana IRC client 1.3 and earlier allows remote attackers to cause a denial of service (application crash) or pos… | Patch early | 7.5 high | 5% | 2008-06-30 |
| CVE-2008-2481 EXP | PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, when register_globals is enabled,… | Patch early | 10.0 high | 5% | 2008-05-28 |
| CVE-2012-1198 EXP | base_ag_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allows remote attackers to execute arbitrary code by uploading contents of the fil… | Patch early | 7.5 high | 5% | 2012-02-18 |
| CVE-2007-1391 EXP | PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows remote attackers to execute arb… | Patch early | 10.0 high | 5% | 2007-03-10 |
| CVE-2002-2300 EXP | Buffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial of service (crash) via a long… | Patch early | 7.5 high | 5% | 2002-12-31 |
| CVE-2017-13847 EXP | An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The issue involves the "IOKit" compo… | Patch early | 7.8 high | 5% | 2017-12-25 |
| CVE-2011-1047 EXP | Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress allow remote attackers to execut… | Patch early | 7.5 high | 5% | 2011-02-21 |
| CVE-2014-9173 EXP | SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute arbitrary SQL… | Patch early | 7.5 high | 5% | 2014-12-02 |
| CVE-2007-1195 EXP | Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unspecified vectors. NOTE: this is… | Patch early | 7.5 high | 5% | 2007-03-02 |
| CVE-2014-9097 EXP | Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly as distributed before 2014-07… | Patch early | 7.5 high | 5% | 2014-11-26 |
| CVE-2014-8358 EXP | Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before V200R003B015D02SP0… | Patch early | 7.8 high | 5% | 2017-12-11 |
| CVE-2007-0368 EXP | Stack-based buffer overflow in mbse-bbs 0.70 and earlier allows local users to execute arbitrary code via a long string in the MBSE_ROOT environment v… | Patch early | 10.0 high | 5% | 2007-01-19 |
| CVE-2007-1628 EXP | Multiple PHP remote file inclusion vulnerabilities in Study planner (Studiewijzer) 0.15 and earlier, when register_globals is enabled, allow remote at… | Patch early | 9.3 high | 5% | 2007-03-23 |
| CVE-2002-1891 EXP | Buffer overflow in IRCIT 0.3.1 IRC client allows remote attackers to execute arbitrary code via a long invite request. | Patch early | 7.5 high | 5% | 2002-12-31 |
| CVE-2005-1873 EXP | Multiple buffer overflows in Crob FTP 3.6.1, and possibly earlier versions, allow remote attackers to execute arbitrary code via (1) an FTP command wi… | Patch early | 7.5 high | 5% | 2005-06-09 |
| CVE-2000-0523 EXP | Buffer overflow in the logging feature of EServ 2.9.2 and earlier allows an attacker to execute arbitrary commands via a long MKD command. | Patch early | 10.0 high | 5% | 2000-06-06 |
| CVE-2012-3808 EXP | Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification. | Patch early | 7.5 high | 5% | 2020-01-09 |
| CVE-2012-3809 EXP | Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification. | Patch early | 7.5 high | 5% | 2020-01-09 |
| CVE-2012-3810 EXP | Samsung Kies before 2.5.0.12094_27_11 has registry modification. | Patch early | 7.5 high | 5% | 2020-01-09 |
| CVE-2026-29053 EXP | Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the se… | Patch early | 7.6 high | 5% | 2026-03-05 |
| CVE-2022-37255 EXP | TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL075526460603. | Patch early | 7.5 high | 5% | 2023-04-16 |
| CVE-2019-15742 EXP | A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application. A local attacker can exploit… | Patch early | 7.8 high | 5% | 2020-01-17 |
| CVE-2007-0172 EXP | Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 5% | 2007-01-11 |
| CVE-2022-42953 EXP | Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?s… | Patch early | 7.5 high | 5% | 2022-12-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt