CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,157 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
400,157 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-3913 EXP | Stack-based buffer overflow in AccessServer32.exe in Ericom AccessNow Server allows remote attackers to execute arbitrary code via a request for a non… | Patch early | 10.0 high | 60.9% | 2014-06-04 |
| CVE-2013-0757 EXP | The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird… | Patch early | 9.3 high | 60.9% | 2013-01-13 |
| CVE-2011-1260 EXP | Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a… | Patch early | 9.3 high | 60.8% | 2011-06-16 |
| CVE-2019-7304 EXP | Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issu… | Patch early | 9.8 critical | 60.8% | 2019-04-23 |
| CVE-2023-27179 EXP | GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php. | Patch early | 7.5 high | 60.8% | 2023-04-11 |
| CVE-2018-18982 EXP | NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an e… | Patch early | 8.8 high | 60.8% | 2018-11-27 |
| CVE-2005-1415 EXP | Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a long FTP command. | Patch early | 10.0 high | 60.8% | 2005-05-03 |
| CVE-2018-7756 EXP | RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit) devices does not require authentication for sessions on TCP port 1999, which allows remot… | Patch early | 9.8 critical | 60.7% | 2018-03-15 |
| CVE-2008-4572 EXP | GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via… | Patch early | 10.0 high | 60.7% | 2008-10-15 |
| CVE-2013-1428 EXP | Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated… | Patch early | 6.5 medium | 60.7% | 2013-04-26 |
| CVE-2015-7603 EXP | Directory traversal vulnerability in Konica Minolta FTP Utility 1.0 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in a… | Patch early | 7.8 high | 60.7% | 2015-09-29 |
| CVE-2014-4725 EXP | The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary… | Patch early | 7.5 high | 60.7% | 2014-07-27 |
| CVE-2013-4074 EXP | The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 in… | Patch early | 5.0 medium | 60.6% | 2013-06-09 |
| CVE-2018-3639 EXP | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes… | Patch early | 5.5 medium | 60.6% | 2018-05-22 |
| CVE-2008-5444 EXP | Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect confidentiality, in… | Patch early | 10.0 high | 60.6% | 2009-01-14 |
| CVE-2004-2416 EXP | Buffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GET request. | Patch early | 7.5 high | 60.6% | 2004-12-31 |
| CVE-2006-5198 EXP | The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers… | Patch early | 4.0 medium | 60.4% | 2006-11-14 |
| CVE-2010-0478 EXP | Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote att… | Patch early | 9.3 high | 60.4% | 2010-04-14 |
| CVE-2004-1317 EXP | Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attackers to execute arbitrary code… | Patch early | 7.5 high | 60.4% | 2004-12-27 |
| CVE-2005-2715 EXP | Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Business Center 4.5FP and 4.5MP, an… | Patch early | 10.0 high | 60.4% | 2005-10-12 |
| CVE-2004-0184 EXP | Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP pack… | Patch early | 5.0 medium | 60.3% | 2004-05-04 |
| CVE-2023-4547 EXP | A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3. The affected element is an unknown function of the file /search. This manipulation of the arg… | Patch early | 3.5 low | 60.3% | 2023-08-26 |
| CVE-2017-15222 EXP | Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code. | Patch early | 9.8 critical | 60.3% | 2017-10-24 |
| CVE-2014-2849 EXP | The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user passw… | Patch early | 8.5 high | 60.3% | 2014-04-11 |
| CVE-2002-1059 EXP | Buffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execute arbitrary code via a long SS… | Patch early | 7.5 high | 60.3% | 2002-10-04 |
| CVE-2004-0575 EXP | Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allo… | Patch early | 10.0 high | 60.3% | 2004-11-03 |
| CVE-2006-6424 EXP | Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain IM… | Patch early | 9.0 high | 60.3% | 2006-12-27 |
| CVE-2007-2280 EXP | Stack-based buffer overflow in OmniInet.exe (aka the backup client service daemon) in the Application Recovery Manager component in HP OpenView Storag… | Patch early | 10.0 high | 60.3% | 2009-12-18 |
| CVE-2015-8399 EXP | Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdef… | Patch early | 4.3 medium | 60.2% | 2016-04-11 |
| CVE-2010-2333 EXP | LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a… | Patch early | 5.0 medium | 60.2% | 2010-06-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt