CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,932 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-7157 EXP | Buffer overflow in Google Earth v4.0.2091 (beta) allows remote user-assisted attackers to cause a denial of service (crash) via a KML or KMZ file with… | Patch early | 7.1 high | 7.5% | 2007-03-07 |
| CVE-2007-6369 EXP | Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow remote attackers to read arbit… | Patch early | 5.0 medium | 7.5% | 2007-12-15 |
| CVE-2010-0462 EXP | Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impa… | Patch early | 6.5 medium | 7.5% | 2010-01-28 |
| CVE-2023-3219 EXP | The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allo… | Patch early | 5.3 medium | 7.5% | 2023-07-10 |
| CVE-2006-7128 EXP | PHP remote file inclusion vulnerability in forum/forum.php JAF CMS 4.0 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the webs… | Patch early | 7.5 high | 7.5% | 2007-03-06 |
| CVE-2017-7037 EXP | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… | Patch early | 8.8 high | 7.5% | 2017-07-20 |
| CVE-2022-40946 EXP | On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via the sys_token parameter in a cg… | Patch early | 7.5 high | 7.5% | 2023-04-16 |
| CVE-2005-0430 EXP | The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash… | Patch early | 5.0 medium | 7.5% | 2005-02-12 |
| CVE-2011-4644 EXP | Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally does… | Patch early | 9.3 high | 7.5% | 2012-01-03 |
| CVE-2014-8949 EXP | The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metacha… | Patch early | 6.0 medium | 7.5% | 2014-11-16 |
| CVE-2011-5002 EXP | Multiple stack-based buffer overflows in Final Draft 8 before 8.02 allow remote attackers to execute arbitrary code via a .fdx or .fdxt file with long… | Patch early | 10.0 high | 7.5% | 2011-12-25 |
| CVE-2007-3702 EXP | Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier allows remote attackers to re… | Patch early | 5.0 medium | 7.5% | 2007-07-11 |
| CVE-2008-5680 EXP | Multiple buffer overflows in Opera before 9.63 might allow (1) remote attackers to execute arbitrary code via a crafted text area, or allow (2) user-a… | Patch early | 9.3 high | 7.5% | 2008-12-19 |
| CVE-2011-0538 EXP | Wireshark 1.2.0 through 1.2.14, 1.4.0 through 1.4.3, and 1.5.0 frees an uninitialized pointer during processing of a .pcap file in the pcap-ng format,… | Patch early | 6.8 medium | 7.5% | 2011-02-08 |
| CVE-2018-7449 EXP | SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an invalid LIST, STOR, or RETR comm… | Patch early | 7.5 high | 7.5% | 2018-03-04 |
| CVE-2007-0609 EXP | Directory traversal vulnerability in Advanced Guestbook 2.4.2 allows remote attackers to bypass .htaccess settings, and execute arbitrary PHP local fi… | Patch early | 5.1 medium | 7.5% | 2007-05-09 |
| CVE-2015-5074 EXP | Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM before 5.0.9… | Patch early | 7.5 high | 7.5% | 2015-09-29 |
| CVE-2007-2787 EXP | Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in LeadTools Raster Thumbnail Object… | Patch early | 7.5 high | 7.5% | 2007-05-21 |
| CVE-2005-3929 EXP | Directory traversal vulnerability in the create function in xarMLSXML2PHPBackend.php in Xaraya 1.0 allows remote attackers to create directories and o… | Patch early | 5.0 medium | 7.5% | 2005-11-30 |
| CVE-2004-1643 EXP | WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid path with a ".… | Patch early | 5.0 medium | 7.5% | 2004-08-29 |
| CVE-2009-0259 EXP | The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary c… | Patch early | 9.3 high | 7.5% | 2009-01-22 |
| CVE-2000-0411 EXP | Matt Wright's FormMail CGI script allows remote attackers to obtain environmental variables via the env_report parameter. | Patch early | 5.0 medium | 7.5% | 2000-05-10 |
| CVE-2010-3000 EXP | Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows… | Patch early | 9.3 high | 7.5% | 2010-08-30 |
| CVE-2016-7098 EXP | Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass inte… | Patch early | 8.1 high | 7.5% | 2016-09-26 |
| CVE-2007-6322 EXP | Directory traversal vulnerability in filedownload.php in xml2owl 0.1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file… | Patch early | 5.0 medium | 7.5% | 2007-12-13 |
| CVE-2017-17761 EXP | An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) u… | Patch early | 9.8 critical | 7.5% | 2017-12-19 |
| CVE-2007-1029 EXP | Stack-based buffer overflow in the Connect method in the IMAP4 component in Quiksoft EasyMail Objects before 6.5 allows remote attackers to execute ar… | Patch early | 7.6 high | 7.5% | 2007-02-21 |
| CVE-2006-4845 EXP | PHP remote file inclusion vulnerability in includes/footer.html.inc.php in TeamCal Pro 2.8.001 and earlier allows remote attackers to execute arbitrar… | Patch early | 5.1 medium | 7.5% | 2006-09-19 |
| CVE-2008-2326 EXP | mDNSResponder in the Bonjour Namespace Provider in Apple Bonjour for Windows before 1.0.5 allows attackers to cause a denial of service (NULL pointer… | Patch early | 5.0 medium | 7.5% | 2008-09-11 |
| CVE-2001-1339 EXP | Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for re… | Patch early | 9.8 critical | 7.5% | 2001-05-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt