CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,955 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
319,593 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-4962 EXP | Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a .wav file. NOTE: some of thes… | Patch early | 9.3 high | 31.4% | 2010-07-28 |
| CVE-2002-0693 EXP | Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal… | Patch early | 7.5 high | 31.3% | 2002-10-10 |
| CVE-2015-2460 EXP | ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Wind… | Patch early | 9.3 high | 31.3% | 2015-08-15 |
| CVE-2018-1133 EXP | An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval… | Patch early | 8.8 high | 31.3% | 2018-05-25 |
| CVE-2007-3493 EXP | A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other produ… | Patch early | 7.5 high | 31.3% | 2007-06-29 |
| CVE-2010-1465 EXP | Stack-based buffer overflow in Trellian FTP client 3.01, including 3.1.3.1789, allows remote attackers to execute arbitrary code via a long PASV respo… | Patch early | 9.3 high | 31.3% | 2010-04-16 |
| CVE-2006-0143 EXP | Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file conta… | Patch early | 7.5 high | 31.3% | 2006-01-09 |
| CVE-2019-0667 EXP | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code E… | Patch early | 7.5 high | 31.3% | 2019-04-08 |
| CVE-2007-5451 EXP | PHP remote file inclusion vulnerability in admin.color.php in the com_colorlab (aka com_color) 1.0 component for Joomla! allows remote attackers to ex… | Patch early | 6.8 medium | 31.2% | 2007-10-14 |
| CVE-2014-2268 EXP | views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-ins… | Patch early | 5.0 medium | 31.2% | 2014-11-16 |
| CVE-2023-4708 EXP | A vulnerability was found in Infosoftbd Clcknshop 1.0.0. It has been rated as critical. This issue affects some unknown processing of the file /collec… | Patch early | 6.3 medium | 31.2% | 2023-09-01 |
| CVE-2007-0427 EXP | Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.… | Patch early | 9.3 high | 31.2% | 2007-01-23 |
| CVE-2012-5002 EXP | Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows… | Patch early | 6.8 medium | 31.2% | 2012-09-19 |
| CVE-2002-0702 EXP | Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPDATE optio… | Patch early | 10.0 high | 31.1% | 2002-07-26 |
| CVE-2010-2731 EXP | Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 on Windows XP SP3, when directory-based Basic Authentication is enabled… | Patch early | 6.8 medium | 31.1% | 2010-09-15 |
| CVE-2005-4131 EXP | Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to… | Patch early | 6.8 medium | 31.1% | 2005-12-09 |
| CVE-2004-1546 EXP | Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a long (1) SAML, SOML, SEND, or… | Patch early | 5.0 medium | 31.1% | 2004-12-31 |
| CVE-2009-2566 EXP | Stack-based buffer overflow in TFM MMPlayer 2.0, and possibly 2.0.0.30, allows remote attackers to execute arbitrary code via a long string in a playl… | Patch early | 9.3 high | 31.1% | 2009-07-21 |
| CVE-2013-4878 EXP | The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directi… | Patch early | 7.5 high | 31.1% | 2013-07-18 |
| CVE-2015-7855 EXP | The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion… | Patch early | 6.5 medium | 31.1% | 2017-08-07 |
| CVE-2011-0499 EXP | Buffer overflow in VideoSpirit Pro 1.6.8.1 and possibly earlier versions, and VideoSpirit Lite 1.4.0.1 and possibly other versions, allows user-assist… | Patch early | 9.3 high | 31% | 2011-01-20 |
| CVE-2021-24146 EXP | Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the expo… | Patch early | 7.5 high | 31% | 2021-03-18 |
| CVE-2008-0311 EXP | Stack-based buffer overflow in the PGMWebHandler::parse_request function in the StarTeam Multicast Service component (STMulticastService) 6.4 in Borla… | Patch early | 9.3 high | 31% | 2008-04-06 |
| CVE-2007-4891 EXP | A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3)… | Patch early | 6.8 medium | 31% | 2007-09-14 |
| CVE-2013-2569 EXP | A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could… | Patch early | 7.5 high | 31% | 2020-01-29 |
| CVE-2009-2255 EXP | Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which allows remote attackers to exec… | Patch early | 6.8 medium | 31% | 2009-06-30 |
| CVE-2014-8387 EXP | cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metachara… | Patch early | 9.0 high | 30.9% | 2014-11-20 |
| CVE-2016-1960 EXP | Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows re… | Patch early | 8.8 high | 30.9% | 2016-03-13 |
| CVE-2009-1641 EXP | Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram… | Patch early | 9.3 high | 30.9% | 2009-05-15 |
| CVE-2010-2553 EXP | The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decompress media files, which allows… | Patch early | 9.3 high | 30.9% | 2010-08-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt