CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,226 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-0350 EXP | Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file, rel… | Patch early | 9.3 high | 10.2% | 2009-01-29 |
| CVE-2017-7117 EXP | An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected.… | Patch early | 8.8 high | 10.2% | 2017-10-23 |
| CVE-2013-0332 EXP | Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x before 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in t… | Patch early | 5.0 medium | 10.2% | 2013-03-20 |
| CVE-2007-1327 EXP | The SILC_SERVER_CMD_FUNC function in apps/silcd/command.c in silc-server 1.0.2 allows remote attackers to cause a denial of service (NULL dereference… | Patch early | 7.8 high | 10.2% | 2007-03-07 |
| CVE-2013-3429 EXP | Multiple directory traversal vulnerabilities in Cisco Video Surveillance Manager (VSM) before 7.0.0 allow remote attackers to read system files via a… | Patch early | 7.8 high | 10.2% | 2013-07-25 |
| CVE-2009-4490 EXP | mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title,… | Patch early | 5.0 medium | 10.2% | 2010-01-13 |
| CVE-2005-1280 EXP | The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of… | Patch early | 5.0 medium | 10.2% | 2005-05-02 |
| CVE-2008-4582 EXP | Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify t… | Patch early | 4.3 medium | 10.2% | 2008-10-15 |
| CVE-2007-1866 EXP | Stack-based buffer overflow in the dns_decode_reverse_name function in dns_decode.c in dproxy-nexgen allows remote attackers to execute arbitrary code… | Patch early | 10.0 high | 10.2% | 2007-04-04 |
| CVE-2009-2934 EXP | Multiple stack-based buffer overflows in xaudio.dll in Programmed Integration PIPL 2.5.0 and 2.5.0D allow remote attackers to execute arbitrary code v… | Patch early | 9.3 high | 10.2% | 2009-08-21 |
| CVE-2007-0646 EXP | Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a de… | Patch early | 7.1 high | 10.2% | 2007-02-01 |
| CVE-2009-0819 EXP | sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XP… | Patch early | 4.0 medium | 10.2% | 2009-03-05 |
| CVE-2012-3755 EXP | Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via… | Patch early | 9.3 high | 10.2% | 2012-11-09 |
| CVE-2006-6287 EXP | Stack-based buffer overflow in AtomixMP3 2.3 and earlier allows remote attackers to execute arbitrary code via a long pathname in an M3U file. | Patch early | 7.5 high | 10.2% | 2006-12-04 |
| CVE-2011-1398 EXP | The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return charac… | Patch early | 4.3 medium | 10.2% | 2012-08-30 |
| CVE-2008-1116 EXP | Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner allows remote attackers to force… | Patch early | 9.3 high | 10.2% | 2008-03-03 |
| CVE-2017-15048 EXP | Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrar… | Patch early | 8.8 high | 10.2% | 2017-12-19 |
| CVE-1999-0875 EXP | DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes. | Patch early | 7.5 high | 10.2% | 1999-08-11 |
| CVE-2022-47875 EXP | A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code. | Patch early | 8.8 high | 10.2% | 2023-05-02 |
| CVE-2000-0474 EXP | Real Networks RealServer 7.x allows remote attackers to cause a denial of service via a malformed request for a page in the viewsource directory. | Patch early | 7.8 high | 10.2% | 2000-06-01 |
| CVE-2011-0920 EXP | The Remote Console in IBM Lotus Domino, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to byp… | Patch early | 9.3 high | 10.2% | 2011-02-08 |
| CVE-2025-10327 EXP | A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdoc… | Patch early | 6.3 medium | 10.2% | 2025-09-12 |
| CVE-2010-1307 EXP | Directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers to read arbitrary files via a… | Patch early | 5.0 medium | 10.2% | 2010-04-08 |
| CVE-2015-7247 EXP | D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and… | Patch early | 9.8 critical | 10.2% | 2017-04-24 |
| CVE-2009-1314 EXP | body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the savefile action with a file par… | Patch early | 10.0 high | 10.1% | 2009-04-17 |
| CVE-1999-0562 EXP | The registry in Windows NT can be accessed remotely by users who are not administrators. | Patch early | 7.5 high | 10.1% | 1997-01-01 |
| CVE-2016-4340 EXP | The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4… | Patch early | 8.8 high | 10.1% | 2017-01-23 |
| CVE-2009-0450 EXP | Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code via a long string in a playlis… | Patch early | 9.3 high | 10.1% | 2009-02-10 |
| CVE-2019-12922 EXP | A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page. | Patch early | 6.5 medium | 10.1% | 2019-09-13 |
| CVE-2007-2458 EXP | Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 7.5 high | 10.1% | 2007-05-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt