CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,061 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
149,742 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-9463 EXP | functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to… | Patch early | 8.8 high | 14.8% | 2017-09-15 |
| CVE-2017-3807 EXP | A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could… | Patch early | 8.8 high | 14.8% | 2017-02-09 |
| CVE-2008-0477 EXP | Stack-based buffer overflow in the QMPUpgrade.Upgrade.1 ActiveX control in QMPUpgrade.dll 1.0.0.1 in Move Networks Upgrade Manager allows remote attac… | Patch early | 10.0 high | 14.8% | 2008-01-29 |
| CVE-2003-0280 EXP | Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL… | Patch early | 10.0 high | 14.7% | 2003-06-16 |
| CVE-2017-12500 EXP | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in… | Patch early | 8.8 high | 14.7% | 2018-02-15 |
| CVE-2006-4197 EXP | Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote at… | Patch early | 7.5 high | 14.7% | 2006-08-17 |
| CVE-2010-1939 EXP | Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup… | Patch early | 7.6 high | 14.7% | 2010-05-13 |
| CVE-2006-5517 EXP | Multiple PHP remote file inclusion vulnerabilities in Rhode Island Open Meetings Filing Application (OMFA) allow remote attackers to execute arbitrary… | Patch early | 7.5 high | 14.7% | 2006-10-26 |
| CVE-2004-0691 EXP | Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (… | Patch early | 7.5 high | 14.7% | 2004-09-28 |
| CVE-2004-1289 EXP | Multiple buffer overflows in (1) the getline function in pcalutil.c and (2) the get_holiday function in readfile.c for pcal 4.7.1 allow remote attacke… | Patch early | 10.0 high | 14.7% | 2005-01-10 |
| CVE-2007-4584 EXP | Stack-based buffer overflow in BitchX 1.1 Final allows remote IRC servers to execute arbitrary code via a long string in a MODE command, related to th… | Patch early | 10.0 high | 14.7% | 2007-08-29 |
| CVE-2007-5381 EXP | Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to exe… | Patch early | 9.3 high | 14.7% | 2007-10-12 |
| CVE-2003-1387 EXP | Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username. | Patch early | 7.5 high | 14.7% | 2003-12-31 |
| CVE-2006-2022 EXP | Buffer overflow in the parse_url function in the RTSP module (rtsp/parse_url.c) in Fenice 1.10 and earlier allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 14.7% | 2006-04-25 |
| CVE-2022-24715 EXP | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration,… | Patch early | 8.5 high | 14.7% | 2022-03-08 |
| CVE-2020-10963 EXP | FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/fi… | Patch early | 7.2 high | 14.7% | 2020-03-25 |
| CVE-2001-0836 EXP | Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request. | Patch early | 7.5 high | 14.7% | 2001-12-06 |
| CVE-2010-4228 EXP | Stack-based buffer overflow in NWFTPD.NLM before 5.10.02 in the FTP server in Novell NetWare allows remote authenticated users to execute arbitrary co… | Patch early | 9.0 high | 14.7% | 2011-03-22 |
| CVE-2022-3142 EXP | The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injecti… | Patch early | 8.8 high | 14.7% | 2022-09-19 |
| CVE-2004-1120 EXP | Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and earlier al… | Patch early | 10.0 high | 14.6% | 2005-01-10 |
| CVE-2009-2692 EXP | The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops stru… | Patch early | 7.8 high | 14.6% | 2009-08-14 |
| CVE-2009-3663 EXP | Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of service (cra… | Patch early | 10.0 high | 14.6% | 2009-10-11 |
| CVE-2004-1127 EXP | Buffer overflow in Open Dc Hub 0.7.14 allows remote attackers, with administrator privileges, to execute arbitrary code via a long RedirectAll command… | Patch early | 10.0 high | 14.6% | 2005-01-10 |
| CVE-2006-6125 EXP | Heap-based buffer overflow in the wireless driver (WG311ND5.SYS) 2.3.1.10 for NetGear WG311v1 wireless adapter allows remote attackers to execute arbi… | Patch early | 7.5 high | 14.6% | 2006-11-27 |
| CVE-2001-0050 EXP | Buffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary commands via an IP address th… | Patch early | 10.0 high | 14.6% | 2001-02-16 |
| CVE-2008-0296 EXP | Heap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC Media Player 0.8.6d and earlier on Windows might allow remote RTSP servers… | Patch early | 10.0 high | 14.6% | 2008-01-16 |
| CVE-2013-2567 EXP | An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.co… | Patch early | 7.5 high | 14.6% | 2020-01-29 |
| CVE-2006-3890 EXP | Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, al… | Patch early | 9.3 high | 14.6% | 2006-11-21 |
| CVE-2005-2878 EXP | Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via form… | Patch early | 7.5 high | 14.6% | 2005-09-13 |
| CVE-2017-11152 EXP | Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write… | Patch early | 7.5 high | 14.6% | 2017-08-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt