CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,069 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
149,744 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2003-0166 EXP | Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possi… | Patch early | 7.5 high | 14.1% | 2003-04-02 |
| CVE-2005-2841 EXP | Buffer overflow in Firewall Authentication Proxy for FTP and/or Telnet Sessions for Cisco IOS 12.2ZH and 12.2ZL, 12.3 and 12.3T, and 12.4 and 12.4T al… | Patch early | 7.5 high | 14.1% | 2005-09-08 |
| CVE-2017-7783 EXP | If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example.com"), the resulting modal pr… | Patch early | 7.5 high | 14.1% | 2018-06-11 |
| CVE-2016-5679 EXP | cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary… | Patch early | 8.8 high | 14.1% | 2016-08-31 |
| CVE-2009-1669 EXP | The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary commands… | Patch early | 10.0 high | 14.1% | 2009-05-18 |
| CVE-2012-5106 EXP | Stack-based buffer overflow in FreeFloat FTP Server 1.0 allows remote authenticated users to execute arbitrary code via a long string in a PUT command… | Patch early | 10.0 high | 14.1% | 2014-06-20 |
| CVE-2010-1175 EXP | Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified impact via a certain XML document… | Patch early | 9.3 high | 14.1% | 2010-03-29 |
| CVE-2021-42165 EXP | MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &… | Patch early | 8.8 high | 14.1% | 2022-05-03 |
| CVE-2016-9838 EXP | An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored… | Patch early | 7.5 high | 14.1% | 2016-12-16 |
| CVE-2003-1228 EXP | Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions, allows remote attackers to c… | Patch early | 7.5 high | 14.1% | 2003-12-31 |
| CVE-2023-32749 EXP | Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when crea… | Patch early | 8.8 high | 14.1% | 2023-06-08 |
| CVE-2008-3655 EXP | Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to critical variab… | Patch early | 7.5 high | 14.1% | 2008-08-13 |
| CVE-2007-6731 EXP | Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses… | Patch early | 10.0 high | 14.1% | 2009-09-13 |
| CVE-2015-2099 EXP | Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vectors to the (1) GetRecFileInfo… | Patch early | 8.8 high | 14.1% | 2021-07-22 |
| CVE-2004-2501 EXP | Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute arbitrary c… | Patch early | 7.5 high | 14.1% | 2004-12-31 |
| CVE-2018-0710 EXP | Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrar… | Patch early | 8.8 high | 14.1% | 2018-07-17 |
| CVE-2010-3132 EXP | Untrusted search path vulnerability in Adobe Dreamweaver CS5 11.0 build 4916, build 4909, and probably other versions, allows local users, and possibl… | Patch early | 9.3 high | 14% | 2010-08-26 |
| CVE-2010-2891 EXP | Buffer overflow in the smiGetNode function in lib/smi.c in libsmi 0.4.8 allows context-dependent attackers to execute arbitrary code via an Object Ide… | Patch early | 7.5 high | 14% | 2010-10-28 |
| CVE-2015-2094 EXP | Stack-based buffer overflow in the WESPPlayback.WESPPlaybackCtrl.1 control in WebGate WinRDS allows remote attackers to execute arbitrary code via uns… | Patch early | 7.5 high | 14% | 2015-03-09 |
| CVE-2017-9353 EXP | In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by validating an IPv6 address. | Patch early | 7.5 high | 14% | 2017-06-02 |
| CVE-2009-1437 EXP | Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows remote attackers to execute arbit… | Patch early | 9.3 high | 14% | 2009-04-27 |
| CVE-2004-1456 EXP | filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo. | Patch early | 7.5 high | 14% | 2004-12-31 |
| CVE-2007-4459 EXP | Cisco IP Phone 7940 and 7960 with P0S3-08-6-00 firmware, and other SIP firmware before 8.7(0), allows remote attackers to cause a denial of service (d… | Patch early | 7.1 high | 14% | 2007-08-21 |
| CVE-2011-0354 EXP | The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 has a blank p… | Patch early | 10.0 high | 14% | 2011-02-03 |
| CVE-2007-0444 EXP | Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and MetaF… | Patch early | 7.2 high | 14% | 2007-01-24 |
| CVE-2015-2098 EXP | Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspecified vectors to the (1) Conn… | Patch early | 8.8 high | 14% | 2021-07-22 |
| CVE-2016-3473 EXP | Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 al… | Patch early | 7.7 high | 13.9% | 2016-10-25 |
| CVE-2008-3734 EXP | Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP servers to cause a denial of servi… | Patch early | 9.3 high | 13.9% | 2008-08-20 |
| CVE-2019-11080 EXP | Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user w… | Patch early | 8.8 high | 13.9% | 2019-06-06 |
| CVE-2002-0799 EXP | Buffer overflow in YoungZSoft CMailServer 3.30 allows remote attackers to execute arbitrary code via a long USER argument. | Patch early | 7.5 high | 13.9% | 2002-08-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt