CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,058 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
149,731 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-8869 EXP | Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file. | Patch early | 7.8 high | 15.9% | 2017-07-27 |
| CVE-2020-8639 EXP | An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a fi… | Patch early | 8.8 high | 15.9% | 2020-04-03 |
| CVE-2006-0189 EXP | Buffer overflow in eStara Softphone 3.0.1.14 through 3.0.1.46 allows remote attackers to execute arbitrary code via a long attribute (aka "a") field i… | Patch early | 7.5 high | 15.9% | 2006-01-13 |
| CVE-2004-1439 EXP | Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1) USER, (2) PASS, (3) RETR,(4)… | Patch early | 7.5 high | 15.8% | 2004-12-31 |
| CVE-2019-0571 EXP | An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Ser… | Patch early | 7.8 high | 15.8% | 2019-01-08 |
| CVE-2010-2128 EXP | Directory traversal vulnerability in the JE Quotation Form (com_jequoteform) component 1.0b1 for Joomla! allows remote attackers to read arbitrary fil… | Patch early | 7.5 high | 15.8% | 2010-06-01 |
| CVE-2018-1821 EXP | IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data… | Patch early | 7.1 high | 15.8% | 2018-12-13 |
| CVE-2010-2033 EXP | Directory traversal vulnerability in the Percha Multicategory Article (com_perchacategoriestree) component 0.6 for Joomla! allows remote attackers to… | Patch early | 7.5 high | 15.8% | 2010-05-25 |
| CVE-2012-5409 EXP | AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet netwo… | Patch early | 10.0 high | 15.8% | 2012-11-01 |
| CVE-2010-2035 EXP | Directory traversal vulnerability in the Percha Gallery (com_perchagallery) component 1.6 Beta for Joomla! allows remote attackers to read arbitrary f… | Patch early | 7.5 high | 15.8% | 2010-05-25 |
| CVE-2005-0566 EXP | Buffer overflow in Golden FTP Server Pro (goldenftpd) 2.x allows remote attackers to execute arbitrary code via a long RNTO command. | Patch early | 7.5 high | 15.7% | 2005-01-22 |
| CVE-2010-1759 EXP | Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows r… | Patch early | 9.3 high | 15.7% | 2010-06-11 |
| CVE-2011-1206 EXP | Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before… | Patch early | 10.0 high | 15.7% | 2011-04-21 |
| CVE-2010-1306 EXP | Directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote attackers to read arbitrary loca… | Patch early | 7.5 high | 15.7% | 2010-04-08 |
| CVE-2010-1875 EXP | Directory traversal vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to read arbitra… | Patch early | 7.5 high | 15.7% | 2010-05-12 |
| CVE-2018-1218 EXP | In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the 'nsrd' daemon causes a buffer o… | Patch early | 7.5 high | 15.7% | 2018-03-19 |
| CVE-2010-2351 EXP | Stack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remote attackers to execute arbitr… | Patch early | 10.0 high | 15.7% | 2010-06-21 |
| CVE-2006-4489 EXP | Multiple PHP remote file inclusion vulnerabilities in MiniBill 2006-07-14 (1.2.2) allow remote attackers to execute arbitrary PHP code via (1) a URL i… | Patch early | 7.5 high | 15.7% | 2006-08-31 |
| CVE-2019-3924 EXP | MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The software will execute user defin… | Patch early | 7.5 high | 15.7% | 2019-02-20 |
| CVE-2010-1602 EXP | Directory traversal vulnerability in the ZiMB Comment (com_zimbcomment) component 0.8.1 for Joomla! allows remote attackers to read arbitrary files an… | Patch early | 7.5 high | 15.7% | 2010-04-29 |
| CVE-2005-2856 EXP | Stack-based buffer overflow in the WinACE UNACEV2.DLL third-party compression utility before 2.6.0.0, as used in multiple products including (1) ALZip… | Patch early | 7.5 high | 15.7% | 2005-09-08 |
| CVE-2008-0220 EXP | Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunc… | Patch early | 7.5 high | 15.7% | 2008-01-10 |
| CVE-2004-0659 EXP | Buffer overflow in TranslateFilename for common.c in MPlayer 1.0pre4 allows remote attackers to execute arbitrary code via a long file name. | Patch early | 10.0 high | 15.7% | 2004-08-06 |
| CVE-2008-3242 EXP | Heap-based buffer overflow in the PPMedia Class ActiveX control in PPMPlayer.dll in PPMate 2.3.1.93 allows remote attackers to execute arbitrary code… | Patch early | 10.0 high | 15.7% | 2008-07-21 |
| CVE-2006-3172 EXP | Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary PHP code via a URL with a trai… | Patch early | 7.5 high | 15.6% | 2006-06-23 |
| CVE-2004-0354 EXP | Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code via forma… | Patch early | 10.0 high | 15.6% | 2004-11-23 |
| CVE-2010-4931 EXP | Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .. (dot dot… | Patch early | 10.0 high | 15.6% | 2011-10-09 |
| CVE-2000-0844 EXP | Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to exec… | Patch early | 10.0 high | 15.6% | 2000-11-14 |
| CVE-2006-4046 EXP | Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for Windows, and 0.1.10_rc5 and earlier on Linux/BSD, allow remote at… | Patch early | 7.5 high | 15.6% | 2006-08-09 |
| CVE-2024-9054 EXP | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor… | Patch early | 8.8 high | 15.6% | 2024-10-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt