CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,624 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-5674 EXP | Multiple array index errors in the HTTP server in Darkwet Network webcamXP 3.72.440.0 and earlier and beta 4.05.280 and earlier allow remote attackers… | Patch early | 9.4 high | 4.5% | 2008-12-19 |
| CVE-2002-0913 EXP | Format string vulnerability in log_doit function of Slurp NNTP client 1.1.0 allows a malicious news server to execute arbitrary code on the client via… | Patch early | 7.5 high | 4.5% | 2002-10-04 |
| CVE-2004-2692 EXP | The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and execute arbitrary… | Patch early | 9.3 high | 4.5% | 2004-12-31 |
| CVE-2013-6027 EXP | Stack-based buffer overflow in the RuntimeDiagnosticPing function in /bin/webs on D-Link DIR-100 routers might allow remote authenticated administrato… | Patch early | 8.5 high | 4.5% | 2013-10-19 |
| CVE-2011-3488 EXP | Use-after-free vulnerability in Equis MetaStock 11 and earlier allows remote attackers to execute arbitrary code via a malformed (1) mwc chart, (2) mw… | Patch early | 10.0 high | 4.5% | 2011-09-16 |
| CVE-2009-2169 EXP | Insecure method vulnerability in the PDFVIEWER.PDFViewerCtrl.1 ActiveX control (pdfviewer.ocx) in Edraw PDF Viewer Component before 3.2.0.126 allows r… | Patch early | 9.3 high | 4.5% | 2009-06-22 |
| CVE-2008-6555 EXP | cgi-bin/webutil.pl in The Puppet Master WebUtil allows remote attackers to execute arbitrary commands via shell metacharacters in the dig command. | Patch early | 10.0 high | 4.5% | 2009-03-30 |
| CVE-2002-0773 EXP | imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp_rootdir.a… | Patch early | 10.0 high | 4.5% | 2002-08-12 |
| CVE-2009-3708 EXP | Stack-based buffer overflow in the Meta Content Optimizer in Konae Technologies Alleycode HTML Editor 2.21 allows user-assisted remote attackers to ex… | Patch early | 9.3 high | 4.5% | 2009-10-16 |
| CVE-2007-0528 EXP | The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various I… | Patch early | 9.0 high | 4.5% | 2007-01-26 |
| CVE-2009-0266 EXP | Stack-based buffer overflow in Triologic Media Player 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string in a .… | Patch early | 9.3 high | 4.5% | 2009-01-26 |
| CVE-2009-3808 EXP | MixSense DJ Studio 1.0.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long str… | Patch early | 9.3 high | 4.5% | 2009-10-27 |
| CVE-2012-1002 EXP | SQL injection vulnerability in author/edit.php in OpenConf 4.x before 4.12 allows remote attackers to execute arbitrary SQL commands via the pid param… | Patch early | 10.0 high | 4.5% | 2012-02-08 |
| CVE-2019-7273 EXP | Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF). | Patch early | 8.8 high | 4.5% | 2019-07-01 |
| CVE-1999-0730 EXP | The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack. | Patch early | 10.0 high | 4.5% | 1999-06-12 |
| CVE-2003-1321 EXP | Buffer overflow in Avant Browser 8.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL… | Patch early | 7.5 high | 4.5% | 2003-12-31 |
| CVE-2003-1355 EXP | Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly… | Patch early | 7.5 high | 4.5% | 2003-12-31 |
| CVE-2013-0109 EXP | The NVIDIA driver before 307.78, and Release 310 before 311.00, in the NVIDIA Display Driver service on Windows does not properly handle exceptions, w… | Patch early | 7.2 high | 4.5% | 2013-04-08 |
| CVE-2004-0490 EXP | cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the… | Patch early | 7.2 high | 4.5% | 2004-08-18 |
| CVE-1999-0704 EXP | Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others. | Patch early | 9.3 high | 4.5% | 1999-09-16 |
| CVE-2016-9351 EXP | An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error allows an attacker to upload a… | Patch early | 7.0 high | 4.5% | 2017-02-13 |
| CVE-2004-1836 EXP | SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the… | Patch early | 7.5 high | 4.4% | 2004-12-31 |
| CVE-2006-4666 EXP | Multiple PHP remote file inclusion vulnerabilities in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attackers to execute arbitrary PHP c… | Patch early | 7.5 high | 4.4% | 2006-09-09 |
| CVE-2005-0047 EXP | Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to e… | Patch early | 7.2 high | 4.4% | 2005-05-02 |
| CVE-2019-8591 EXP | A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A… | Patch early | 7.1 high | 4.4% | 2019-12-18 |
| CVE-2019-19363 EXP | An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation.… | Patch early | 7.8 high | 4.4% | 2020-01-24 |
| CVE-2014-8681 EXP | SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.6.x before 0.5.6.1025 Beta a… | Patch early | 7.5 high | 4.4% | 2014-11-21 |
| CVE-2004-1165 EXP | Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP… | Patch early | 7.5 high | 4.4% | 2005-01-10 |
| CVE-2008-5284 EXP | The web server in IEA Software RadiusNT and RadiusX 5.1.38 and other versions before 5.1.44, Emerald 5.0.49 and other versions before 5.0.52, Air Mars… | Patch early | 10.0 high | 4.4% | 2008-11-29 |
| CVE-2005-0958 EXP | Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabled, allows remote attackers to… | Patch early | 7.5 high | 4.4% | 2005-05-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt