CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,922 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-2930 EXP | The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS query identifiers when sending… | Patch early | 4.3 medium | 7.6% | 2007-09-12 |
| CVE-2004-1903 EXP | Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an object tag. | Patch early | 10.0 high | 7.6% | 2004-12-31 |
| CVE-2004-2114 EXP | Stack-based and heap-based buffer overflows in ProxyNow! 2.75 and earlier allow remote attackers to execute arbitrary code via a GET request with a lo… | Patch early | 10.0 high | 7.6% | 2004-12-31 |
| CVE-2005-0339 EXP | Buffer overflow in Foxmail 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long MAIL FROM command. | Patch early | 10.0 high | 7.6% | 2005-05-02 |
| CVE-2008-1303 EXP | The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon crash) via a… | Patch early | 5.0 medium | 7.6% | 2008-03-12 |
| CVE-2008-3314 EXP | ZDaemon 1.08.07 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted type 6 command, which triggers a NULL po… | Patch early | 5.0 medium | 7.6% | 2008-07-25 |
| CVE-2014-5116 EXP | The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attackers to cause a denial of serv… | Patch early | 5.0 medium | 7.6% | 2014-07-29 |
| CVE-2000-0333 EXP | tcpdump, Ethereal, and other sniffer packages allow remote attackers to cause a denial of service via malformed DNS packets in which a jump offset ref… | Patch early | 5.0 medium | 7.6% | 1999-05-31 |
| CVE-2017-15920 EXP | In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability tha… | Patch early | 7.5 high | 7.6% | 2017-10-30 |
| CVE-2017-15921 EXP | In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability tha… | Patch early | 7.5 high | 7.6% | 2017-10-30 |
| CVE-2008-1411 EXP | The PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to cause a denial of service (crash) via an incomple… | Patch early | 5.0 medium | 7.6% | 2008-03-20 |
| CVE-2008-1855 EXP | FrameworkService.exe in McAfee Common Management Agent (CMA) 3.6.0.574 Patch 3 and earlier, as used by ePolicy Orchestrator (ePO) and ProtectionPilot… | Patch early | 5.0 medium | 7.6% | 2008-04-16 |
| CVE-2010-2785 EXP | The IRC Protocol component in KVIrc 3.x and 4.x before r4693 does not properly handle \ (backslash) characters, which allows remote authenticated user… | Patch early | 6.5 medium | 7.6% | 2010-08-02 |
| CVE-2006-0328 EXP | Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) G… | Patch early | 5.0 medium | 7.6% | 2006-01-21 |
| CVE-2000-0851 EXP | Buffer overflow in the Still Image Service in Windows 2000 allows local users to gain additional privileges via a long WM_USER message, aka the "Still… | Patch early | 4.6 medium | 7.6% | 2000-11-14 |
| CVE-2000-0853 EXP | YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 5.0 medium | 7.6% | 2000-11-14 |
| CVE-2000-1016 EXP | The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read packa… | Patch early | 5.0 medium | 7.6% | 2000-12-11 |
| CVE-2001-1170 EXP | AmTote International homebet program stores the homebet.log file in the homebet/ virtual directory, which allows remote attackers to steal account and… | Patch early | 5.0 medium | 7.6% | 2001-09-29 |
| CVE-2007-0228 EXP | The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service (service crash) via a (1) &CO… | Patch early | 5.0 medium | 7.6% | 2007-01-13 |
| CVE-2002-2154 EXP | Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences. | Patch early | 5.0 medium | 7.6% | 2002-12-31 |
| CVE-2007-5694 EXP | Absolute path traversal vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to read arbitrary… | Patch early | 6.8 medium | 7.6% | 2007-10-29 |
| CVE-2013-2225 EXP | inc/ticket.class.php in GLPI 0.83.9 and earlier allows remote attackers to unserialize arbitrary PHP objects via the _predefined_fields parameter to f… | Patch early | 6.4 medium | 7.6% | 2014-05-27 |
| CVE-2001-1263 EXP | telnet95.exe in Pragma InterAccess 4.0 build 5 allows remote attackers to cause a denial of service (crash) via a large number of characters to port 2… | Patch early | 5.0 medium | 7.6% | 2001-06-06 |
| CVE-2008-0100 EXP | Stack-based buffer overflow in the Scene::errorf function in Scene.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbit… | Patch early | 7.5 high | 7.6% | 2008-01-08 |
| CVE-2006-2245 EXP | PHP remote file inclusion vulnerability in auction\auction_common.php in Auction mod 1.3m for phpBB allows remote attackers to execute arbitrary PHP c… | Patch early | 6.8 medium | 7.6% | 2006-05-09 |
| CVE-2006-1718 EXP | Magus Perde Clever Copy 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attacker… | Patch early | 5.0 medium | 7.6% | 2006-04-11 |
| CVE-2006-4559 EXP | Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attackers to execute arbitrary PHP co… | Patch early | 7.5 high | 7.6% | 2006-09-06 |
| CVE-2000-1033 EXP | Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attem… | Patch early | 7.5 high | 7.6% | 2000-12-11 |
| CVE-2007-2186 EXP | Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document. | Patch early | 5.0 medium | 7.6% | 2007-04-24 |
| CVE-2023-27167 EXP | Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/absence?search_month=1. | Patch early | 6.5 medium | 7.6% | 2023-03-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt