CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,212 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
149,788 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-1464 EXP | Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code via a crafted file, aka Bug ID… | Patch early | 7.8 high | 10% | 2016-09-03 |
| CVE-2018-17961 EXP | Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this is… | Patch early | 8.6 high | 10% | 2018-10-15 |
| CVE-2013-6283 EXP | VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a lon… | Patch early | 7.5 high | 10% | 2013-10-25 |
| CVE-2020-25538 EXP | An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web pa… | Patch early | 8.8 high | 10% | 2020-11-13 |
| CVE-2020-25557 EXP | In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs… | Patch early | 8.8 high | 10% | 2020-11-13 |
| CVE-2005-1666 EXP | Multiple buffer overflows in Orenosv HTTP/FTP Server 0.8.1 allow remote authenticated users to cause a denial of service (server crash) and possibly e… | Patch early | 7.5 high | 10% | 2005-05-18 |
| CVE-2007-4582 EXP | Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ACTi Network Video Recorder (NVR) SP2 2.… | Patch early | 7.5 high | 10% | 2007-08-29 |
| CVE-2003-1247 EXP | Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile,… | Patch early | 7.5 high | 10% | 2003-12-31 |
| CVE-2008-7170 EXP | GSC build 2067 and earlier relies on the client to enforce administrator privileges, which allows remote attackers to execute arbitrary administrator… | Patch early | 10.0 high | 9.9% | 2009-09-08 |
| CVE-2008-3877 EXP | Stack-based buffer overflow in Acoustica Mixcraft 4.1 Build 96 and 4.2 Build 98 allows user-assisted attackers to execute arbitrary code via a crafted… | Patch early | 9.3 high | 9.9% | 2008-09-02 |
| CVE-2008-4686 EXP | Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote atta… | Patch early | 9.3 high | 9.9% | 2008-10-22 |
| CVE-2012-3448 EXP | Unspecified vulnerability in Ganglia Web before 3.5.1 allows remote attackers to execute arbitrary PHP code via unknown attack vectors. | Patch early | 7.5 high | 9.9% | 2012-08-06 |
| CVE-2005-2409 EXP | Format string vulnerability in util.c in nbsmtp 0.99 and earlier, while running in debug mode, allows remote attackers to execute arbitrary code via f… | Patch early | 7.5 high | 9.9% | 2005-08-01 |
| CVE-2019-5009 EXP | Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and h… | Patch early | 7.2 high | 9.9% | 2019-01-04 |
| CVE-2014-2996 EXP | XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administrators to execute arbitrary com… | Patch early | 7.1 high | 9.9% | 2014-04-25 |
| CVE-2000-0177 EXP | DNSTools CGI applications allow remote attackers to execute arbitrary commands via shell metacharacters. | Patch early | 10.0 high | 9.9% | 2000-03-02 |
| CVE-2000-0527 EXP | userreg.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters. | Patch early | 10.0 high | 9.9% | 2000-06-09 |
| CVE-2007-1982 EXP | Multiple PHP remote file inclusion vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 and earlier allow remote attackers to execute arbit… | Patch early | 7.5 high | 9.9% | 2007-04-12 |
| CVE-2001-1287 EXP | Buffer overflow in Web Calendar in Ipswitch IMail 7.04 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. | Patch early | 7.5 high | 9.9% | 2001-10-12 |
| CVE-2005-0689 EXP | includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the URL or (2) the template paramet… | Patch early | 7.5 high | 9.9% | 2005-03-07 |
| CVE-2002-1057 EXP | Buffer overflow in SmartMax MailMax POP3 daemon (popmax) 4.8 allows remote attackers to execute arbitrary code via a long USER command. | Patch early | 7.5 high | 9.9% | 2002-10-04 |
| CVE-2005-0226 EXP | Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with… | Patch early | 7.5 high | 9.9% | 2005-02-03 |
| CVE-2004-1666 EXP | Buffer overflow in the MSN module in Trillian 0.74i allows remote MSN servers to execute arbitrary code via a long string that ends in a newline chara… | Patch early | 7.5 high | 9.9% | 2004-12-31 |
| CVE-2006-4870 EXP | Multiple PHP remote file inclusion vulnerabilities in AEDating 4.1, and possibly earlier versions, allow remote attackers to execute arbitrary PHP cod… | Patch early | 7.5 high | 9.9% | 2006-09-19 |
| CVE-2018-20159 EXP | i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allows an authenticated user with t… | Patch early | 7.2 high | 9.9% | 2018-12-15 |
| CVE-2000-0012 EXP | Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands. | Patch early | 10.0 high | 9.9% | 1999-12-27 |
| CVE-2013-6231 EXP | SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script | Patch early | 8.8 high | 9.9% | 2020-01-10 |
| CVE-2022-23626 EXP | m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions `imagecreatefrom*` and `image*` have not been checked properly… | Patch early | 8.5 high | 9.9% | 2022-02-08 |
| CVE-2004-2347 EXP | blog.cgi in Leif M. Wright Web Blog 1.1 and 1.1.5 allows remote attackers to execute arbitrary commands via shell metacharacters such as '|' in the fi… | Patch early | 7.5 high | 9.9% | 2004-12-31 |
| CVE-2004-0613 EXP | osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to t… | Patch early | 7.5 high | 9.9% | 2004-12-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt