CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,267 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
186,505 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-1084 EXP | In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections afforded by the guard-page. Thi… | Patch early | 7.5 high | 15.3% | 2018-09-12 |
| CVE-2010-1535 EXP | Directory traversal vulnerability in the TRAVELbook (com_travelbook) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files and p… | Patch early | 7.5 high | 15.3% | 2010-04-26 |
| CVE-2007-1777 EXP | Integer overflow in the zip_read_entry function in PHP 4 before 4.4.5 allows remote attackers to execute arbitrary code via a ZIP archive that contain… | Patch early | 7.5 high | 15.3% | 2007-03-30 |
| CVE-2007-4566 EXP | Multiple buffer overflows in the login mechanism in sidvault in Alpha Centauri Software SIDVault LDAP Server before 2.0f allow remote attackers to exe… | Patch early | 10.0 high | 15.3% | 2007-08-28 |
| CVE-2014-2913 EXP | Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary com… | Patch early | 7.5 high | 15.3% | 2014-05-07 |
| CVE-2007-2031 EXP | Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote attackers to execute arbitrary… | Patch early | 10.0 high | 15.3% | 2007-04-16 |
| CVE-2019-13605 EXP | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveragin… | Patch early | 8.8 high | 15.3% | 2019-07-16 |
| CVE-2008-0984 EXP | The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrar… | Patch early | 9.3 high | 15.3% | 2008-02-26 |
| CVE-2015-3456 EXP | The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-boun… | Patch early | 7.7 high | 15.3% | 2015-05-13 |
| CVE-2018-5234 EXP | The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in which the goal is execution of arb… | Patch early | 8.0 high | 15.3% | 2018-04-30 |
| CVE-2017-6558 EXP | iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote a… | Patch early | 9.8 critical | 15.3% | 2017-03-09 |
| CVE-2005-2665 EXP | Stack-based buffer overflow in expires.c in Elm 2.5 PL5 through PL7, and possibly other versions, allows remote attackers to execute arbitrary code vi… | Patch early | 7.5 high | 15.3% | 2005-08-23 |
| CVE-2025-27210 EXP | An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vuln… | Patch early | 7.5 high | 15.3% | 2025-07-18 |
| CVE-2004-2532 EXP | Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands b… | Patch early | 10.0 high | 15.3% | 2004-12-31 |
| CVE-2010-4977 EXP | SQL injection vulnerability in menu.php in the Canteen (com_canteen) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL comman… | Patch early | 7.5 high | 15.3% | 2011-11-01 |
| CVE-2010-0759 EXP | Directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Design Scriptegrator plugin 1.4.1… | Patch early | 7.5 high | 15.2% | 2010-02-27 |
| CVE-2017-5799 EXP | A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (f… | Patch early | 8.8 high | 15.2% | 2018-02-15 |
| CVE-2009-1210 EXP | Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code vi… | Patch early | 10.0 high | 15.2% | 2009-04-01 |
| CVE-2001-0162 EXP | WinCE 3.0.9348 generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections. | Patch early | 7.5 high | 15.2% | 2001-01-01 |
| CVE-2007-5257 EXP | Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allow… | Patch early | 10.0 high | 15.2% | 2007-10-06 |
| CVE-2010-1185 EXP | Stack-based buffer overflow in serv.exe in SAP MaxDB 7.4.3.32, and 7.6.0.37 through 7.6.06 allows remote attackers to execute arbitrary code via an in… | Patch early | 10.0 high | 15.2% | 2010-03-29 |
| CVE-2022-1565 EXP | The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions… | Patch early | 7.2 high | 15.2% | 2022-07-18 |
| CVE-2023-0777 EXP | Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4. | Patch early | 9.8 critical | 15.2% | 2023-02-10 |
| CVE-2018-11311 EXP | A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server o… | Patch early | 9.1 critical | 15.2% | 2018-05-20 |
| CVE-2010-4328 EXP | Multiple stack-based buffer overflows in opt/novell/iprint/bin/ipsmd in Novell iPrint for Linux Open Enterprise Server 2 SP2 and SP3 allow remote atta… | Patch early | 7.5 high | 15.2% | 2011-02-19 |
| CVE-2001-0746 EXP | Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and pos… | Patch early | 10.0 high | 15.2% | 2001-10-18 |
| CVE-2007-1383 EXP | Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this co… | Patch early | 9.8 critical | 15.2% | 2007-03-10 |
| CVE-2014-4334 EXP | Stack-based buffer overflow in Ubisoft Rayman Legends before 1.3.140380 allows remote attackers to execute arbitrary code via a long string in the "se… | Patch early | 7.5 high | 15.2% | 2014-06-19 |
| CVE-2003-1236 EXP | Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to execute arbitrary code via forma… | Patch early | 10.0 high | 15.2% | 2003-12-31 |
| CVE-2017-17672 EXP | In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circums… | Patch early | 9.8 critical | 15.2% | 2017-12-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt