CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,295 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
149,809 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-4197 EXP | A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… | Patch early | 8.8 high | 9.4% | 2019-04-03 |
| CVE-2018-4315 EXP | A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… | Patch early | 8.8 high | 9.4% | 2019-04-03 |
| CVE-2004-1095 EXP | Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (… | Patch early | 10.0 high | 9.4% | 2005-01-10 |
| CVE-2006-0565 EXP | PHP remote file include vulnerability in inc/backend_settings.php in Loudblog 0.4 and earlier allows remote attackers to execute arbitrary PHP code vi… | Patch early | 7.5 high | 9.4% | 2006-02-06 |
| CVE-2007-1943 EXP | Integer overflow in ACDSee Photo Manager 9.0 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via l… | Patch early | 9.3 high | 9.4% | 2007-04-11 |
| CVE-2010-2931 EXP | Stack-based buffer overflow in SigPlus Pro 3.74 ActiveX control allows remote attackers to execute arbitrary code via a long eighth argument (HexStrin… | Patch early | 9.3 high | 9.4% | 2010-08-05 |
| CVE-1999-0492 EXP | The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses. | Patch early | 10.0 high | 9.4% | 1999-04-23 |
| CVE-2007-2270 EXP | The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) character in the From header, and… | Patch early | 7.8 high | 9.4% | 2007-04-25 |
| CVE-2002-1486 EXP | Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly… | Patch early | 7.5 high | 9.4% | 2003-04-02 |
| CVE-2015-7945 EXP | The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13… | Patch early | 7.5 high | 9.4% | 2017-08-18 |
| CVE-2004-2631 EXP | Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary P… | Patch early | 7.5 high | 9.4% | 2004-12-31 |
| CVE-2007-0634 EXP | Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system crash) via certain ICMP packe… | Patch early | 7.8 high | 9.4% | 2007-01-31 |
| CVE-2018-16946 EXP | LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log &… | Patch early | 7.5 high | 9.3% | 2018-09-12 |
| CVE-2018-4306 EXP | A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… | Patch early | 8.8 high | 9.3% | 2019-04-03 |
| CVE-2018-4312 EXP | A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… | Patch early | 8.8 high | 9.3% | 2019-04-03 |
| CVE-2018-4317 EXP | A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… | Patch early | 8.8 high | 9.3% | 2019-04-03 |
| CVE-2018-4318 EXP | A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… | Patch early | 8.8 high | 9.3% | 2019-04-03 |
| CVE-2007-1014 EXP | Stack-based buffer overflow in VicFTPS before 5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitr… | Patch early | 10.0 high | 9.3% | 2007-02-21 |
| CVE-2007-4255 EXP | Buffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a long first argument to the msql_… | Patch early | 7.5 high | 9.3% | 2007-08-08 |
| CVE-2004-1988 EXP | PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by… | Patch early | 7.5 high | 9.3% | 2004-04-30 |
| CVE-2004-1989 EXP | PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modif… | Patch early | 7.5 high | 9.3% | 2004-04-30 |
| CVE-2005-4694 EXP | Unspecified vulnerability in the www_add method in Asset.pm in Plain Black WebGUI 6.3.0 and other versions before 6.7.6 allows attackers to execute ar… | Patch early | 7.5 high | 9.3% | 2005-12-31 |
| CVE-2004-1796 EXP | PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header]… | Patch early | 7.5 high | 9.3% | 2004-12-31 |
| CVE-2001-1002 EXP | The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by… | Patch early | 7.5 high | 9.3% | 2001-08-31 |
| CVE-2009-0641 EXP | sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older… | Patch early | 9.3 high | 9.3% | 2009-02-20 |
| CVE-2005-2108 EXP | SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that… | Patch early | 7.5 high | 9.3% | 2005-07-05 |
| CVE-2007-2540 EXP | Multiple PHP remote file inclusion vulnerabilities in PMECMS 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the con… | Patch early | 7.5 high | 9.3% | 2007-05-09 |
| CVE-2010-2004 EXP | Stack-based buffer overflow in BS.Global BS.Player 2.51 Build 1022 Free, and possibly other versions, allows user-assisted remote attackers to execute… | Patch early | 9.3 high | 9.3% | 2010-05-20 |
| CVE-2007-4391 EXP | Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application cras… | Patch early | 9.3 high | 9.3% | 2007-08-17 |
| CVE-2022-26149 EXP | MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Upl… | Patch early | 7.2 high | 9.3% | 2022-02-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt