CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,429 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-1943 EXP | Integer overflow in ACDSee Photo Manager 9.0 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via l… | Patch early | 9.3 high | 9.4% | 2007-04-11 |
| CVE-2010-2931 EXP | Stack-based buffer overflow in SigPlus Pro 3.74 ActiveX control allows remote attackers to execute arbitrary code via a long eighth argument (HexStrin… | Patch early | 9.3 high | 9.4% | 2010-08-05 |
| CVE-2010-1719 EXP | Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attackers to read arbitrary files and… | Patch early | 6.8 medium | 9.4% | 2010-05-04 |
| CVE-2004-2565 EXP | Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, when the administrative IP… | Patch early | 5.0 medium | 9.4% | 2004-12-31 |
| CVE-1999-0492 EXP | The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses. | Patch early | 10.0 high | 9.4% | 1999-04-23 |
| CVE-2006-2896 EXP | profile.php in FunkBoard CF0.71 allows remote attackers to change arbitrary passwords via a modified uid hidden form field in an Edit Profile action. | Patch early | 5.0 medium | 9.4% | 2006-06-07 |
| CVE-2006-3735 EXP | Multiple PHP remote file inclusion vulnerabilities in Mail2Forum (module for phpBB) 1.2 and earlier allow remote attackers to execute arbitrary PHP co… | Patch early | 5.1 medium | 9.4% | 2006-07-21 |
| CVE-2009-2535 EXP | Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumpti… | Patch early | 5.0 medium | 9.4% | 2009-07-20 |
| CVE-2019-14280 EXP | In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so,… | Patch early | 5.3 medium | 9.4% | 2019-07-26 |
| CVE-2007-2270 EXP | The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) character in the From header, and… | Patch early | 7.8 high | 9.4% | 2007-04-25 |
| CVE-2002-1486 EXP | Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly… | Patch early | 7.5 high | 9.4% | 2003-04-02 |
| CVE-2001-0784 EXP | Directory traversal vulnerability in Icecast 1.3.10 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack us… | Patch early | 5.0 medium | 9.4% | 2001-10-18 |
| CVE-2015-7945 EXP | The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13… | Patch early | 7.5 high | 9.4% | 2017-08-18 |
| CVE-2004-2631 EXP | Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary P… | Patch early | 7.5 high | 9.4% | 2004-12-31 |
| CVE-2007-0634 EXP | Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system crash) via certain ICMP packe… | Patch early | 7.8 high | 9.4% | 2007-01-31 |
| CVE-2018-16946 EXP | LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log &… | Patch early | 7.5 high | 9.3% | 2018-09-12 |
| CVE-2018-4306 EXP | A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… | Patch early | 8.8 high | 9.3% | 2019-04-03 |
| CVE-2018-4312 EXP | A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… | Patch early | 8.8 high | 9.3% | 2019-04-03 |
| CVE-2018-4317 EXP | A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… | Patch early | 8.8 high | 9.3% | 2019-04-03 |
| CVE-2018-4318 EXP | A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… | Patch early | 8.8 high | 9.3% | 2019-04-03 |
| CVE-2007-1014 EXP | Stack-based buffer overflow in VicFTPS before 5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitr… | Patch early | 10.0 high | 9.3% | 2007-02-21 |
| CVE-2009-3840 EXP | The embedded database engine service (aka ovdbrun.exe) in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to cause a d… | Patch early | 5.0 medium | 9.3% | 2009-11-19 |
| CVE-2010-0519 EXP | Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (applicat… | Patch early | 6.8 medium | 9.3% | 2010-03-30 |
| CVE-2007-0051 EXP | Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary c… | Patch early | 6.8 medium | 9.3% | 2007-01-04 |
| CVE-2001-0009 EXP | Directory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack. | Patch early | 5.0 medium | 9.3% | 2001-02-12 |
| CVE-2007-4255 EXP | Buffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a long first argument to the msql_… | Patch early | 7.5 high | 9.3% | 2007-08-08 |
| CVE-2012-0298 EXP | The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to (1) read or (2) delete arbitrar… | Patch early | 6.4 medium | 9.3% | 2012-05-21 |
| CVE-2004-0129 EXP | Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) seque… | Patch early | 5.0 medium | 9.3% | 2004-03-03 |
| CVE-2004-1988 EXP | PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by… | Patch early | 7.5 high | 9.3% | 2004-04-30 |
| CVE-2004-1989 EXP | PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modif… | Patch early | 7.5 high | 9.3% | 2004-04-30 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt