CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,371 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
186,548 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-2013 EXP | Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 14.8% | 2014-03-03 |
| CVE-2017-14243 EXP | An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers to directly access administra… | Patch early | 9.8 critical | 14.8% | 2017-09-17 |
| CVE-2014-9463 EXP | functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to… | Patch early | 8.8 high | 14.8% | 2017-09-15 |
| CVE-2008-1160 EXP | ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attac… | Patch early | 9.8 critical | 14.8% | 2008-03-25 |
| CVE-2017-3807 EXP | A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could… | Patch early | 8.8 high | 14.8% | 2017-02-09 |
| CVE-2008-0477 EXP | Stack-based buffer overflow in the QMPUpgrade.Upgrade.1 ActiveX control in QMPUpgrade.dll 1.0.0.1 in Move Networks Upgrade Manager allows remote attac… | Patch early | 10.0 high | 14.8% | 2008-01-29 |
| CVE-2003-0280 EXP | Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL… | Patch early | 10.0 high | 14.7% | 2003-06-16 |
| CVE-2017-12500 EXP | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in… | Patch early | 8.8 high | 14.7% | 2018-02-15 |
| CVE-2006-4197 EXP | Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote at… | Patch early | 7.5 high | 14.7% | 2006-08-17 |
| CVE-2010-1939 EXP | Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup… | Patch early | 7.6 high | 14.7% | 2010-05-13 |
| CVE-2006-5517 EXP | Multiple PHP remote file inclusion vulnerabilities in Rhode Island Open Meetings Filing Application (OMFA) allow remote attackers to execute arbitrary… | Patch early | 7.5 high | 14.7% | 2006-10-26 |
| CVE-2004-0691 EXP | Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (… | Patch early | 7.5 high | 14.7% | 2004-09-28 |
| CVE-2004-1289 EXP | Multiple buffer overflows in (1) the getline function in pcalutil.c and (2) the get_holiday function in readfile.c for pcal 4.7.1 allow remote attacke… | Patch early | 10.0 high | 14.7% | 2005-01-10 |
| CVE-2002-0083 EXP | Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. | Patch early | 9.8 critical | 14.7% | 2002-03-15 |
| CVE-2026-58138 EXP | Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrar… | Patch early | 9.8 critical | 14.7% | 2026-06-30 |
| CVE-2007-4584 EXP | Stack-based buffer overflow in BitchX 1.1 Final allows remote IRC servers to execute arbitrary code via a long string in a MODE command, related to th… | Patch early | 10.0 high | 14.7% | 2007-08-29 |
| CVE-2007-5381 EXP | Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to exe… | Patch early | 9.3 high | 14.7% | 2007-10-12 |
| CVE-2003-1387 EXP | Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username. | Patch early | 7.5 high | 14.7% | 2003-12-31 |
| CVE-2006-2022 EXP | Buffer overflow in the parse_url function in the RTSP module (rtsp/parse_url.c) in Fenice 1.10 and earlier allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 14.7% | 2006-04-25 |
| CVE-2022-24715 EXP | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration,… | Patch early | 8.5 high | 14.7% | 2022-03-08 |
| CVE-2020-10963 EXP | FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/fi… | Patch early | 7.2 high | 14.7% | 2020-03-25 |
| CVE-2001-0836 EXP | Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request. | Patch early | 7.5 high | 14.7% | 2001-12-06 |
| CVE-2010-4228 EXP | Stack-based buffer overflow in NWFTPD.NLM before 5.10.02 in the FTP server in Novell NetWare allows remote authenticated users to execute arbitrary co… | Patch early | 9.0 high | 14.7% | 2011-03-22 |
| CVE-2022-3142 EXP | The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injecti… | Patch early | 8.8 high | 14.7% | 2022-09-19 |
| CVE-2004-1120 EXP | Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and earlier al… | Patch early | 10.0 high | 14.6% | 2005-01-10 |
| CVE-2009-2692 EXP | The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops stru… | Patch early | 7.8 high | 14.6% | 2009-08-14 |
| CVE-2009-3663 EXP | Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of service (cra… | Patch early | 10.0 high | 14.6% | 2009-10-11 |
| CVE-2004-1127 EXP | Buffer overflow in Open Dc Hub 0.7.14 allows remote attackers, with administrator privileges, to execute arbitrary code via a long RedirectAll command… | Patch early | 10.0 high | 14.6% | 2005-01-10 |
| CVE-2017-6972 EXP | AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root… | Patch early | 9.8 critical | 14.6% | 2017-03-22 |
| CVE-2006-6125 EXP | Heap-based buffer overflow in the wireless driver (WG311ND5.SYS) 2.3.1.10 for NetGear WG311v1 wireless adapter allows remote attackers to execute arbi… | Patch early | 7.5 high | 14.6% | 2006-11-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt