CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,522 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
149,888 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-4029 EXP | Stack-based buffer overflow in sipd.dll in AGEphone 1.24 and 1.38.1 allows remote attackers to execute arbitrary code via a crafted UDP SIP packet. | Patch early | 7.5 high | 8.4% | 2006-08-09 |
| CVE-2007-2271 EXP | Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbitrary files via a .. (dot dot)… | Patch early | 9.4 high | 8.4% | 2007-04-25 |
| CVE-2007-6332 EXP | The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBC… | Patch early | 9.3 high | 8.4% | 2007-12-13 |
| CVE-2000-0109 EXP | The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily g… | Patch early | 10.0 high | 8.4% | 2000-01-31 |
| CVE-2007-3934 EXP | PHP remote file inclusion vulnerability in postscript/postscript.php in BBS E-Market allows remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 8.4% | 2007-07-21 |
| CVE-2011-1249 EXP | The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server… | Patch early | 7.2 high | 8.4% | 2011-06-16 |
| CVE-2009-1236 EXP | Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers… | Patch early | 10.0 high | 8.4% | 2009-04-02 |
| CVE-2009-0680 EXP | cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (device crash) via a crafted quer… | Patch early | 7.8 high | 8.4% | 2009-02-22 |
| CVE-2002-1792 EXP | Buffer overflow in Fake Identd 0.9 through 1.4 allows remote attackers to execute arbitrary code as root via a long request that is split into multipl… | Patch early | 10.0 high | 8.4% | 2002-12-31 |
| CVE-2004-2254 EXP | SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface… | Patch early | 7.5 high | 8.4% | 2004-12-31 |
| CVE-2009-1313 EXP | The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of s… | Patch early | 9.3 high | 8.4% | 2009-04-30 |
| CVE-2000-1054 EXP | Buffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execu… | Patch early | 10.0 high | 8.4% | 2000-12-11 |
| CVE-2007-3191 EXP | Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to obtain configuration information via a direct request to admin/adm/te… | Patch early | 9.4 high | 8.4% | 2007-06-12 |
| CVE-2006-4890 EXP | Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the d… | Patch early | 7.5 high | 8.4% | 2006-09-19 |
| CVE-2007-3572 EXP | Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro allows remote attackers to execu… | Patch early | 9.3 high | 8.4% | 2007-07-05 |
| CVE-2007-1809 EXP | Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 8.4% | 2007-04-02 |
| CVE-2007-2067 EXP | Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote attackers to execute arbitrary… | Patch early | 7.5 high | 8.4% | 2007-04-18 |
| CVE-2007-2569 EXP | Multiple PHP remote file inclusion vulnerabilities in Friendly 1.0d1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 8.4% | 2007-05-09 |
| CVE-2000-0515 EXP | The snmpd.conf configuration file for the SNMP daemon (snmpd) in HP-UX 11.0 is world writable, which allows local users to modify SNMP configuration o… | Patch early | 10.0 high | 8.4% | 2000-06-07 |
| CVE-2010-3128 EXP | Untrusted search path vulnerability in TeamViewer 5.0.8703 and earlier allows local users, and possibly remote attackers, to execute arbitrary code an… | Patch early | 9.3 high | 8.4% | 2010-08-26 |
| CVE-2001-1586 EXP | Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary programs via encoded ../ ("%2E%2E%… | Patch early | 10.0 high | 8.4% | 2010-02-12 |
| CVE-2023-1545 EXP | SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. | Patch early | 7.5 high | 8.4% | 2023-03-21 |
| CVE-2000-0405 EXP | Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet. | Patch early | 10.0 high | 8.4% | 2000-05-16 |
| CVE-2014-8393 EXP | DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion. | Patch early | 7.8 high | 8.3% | 2017-08-29 |
| CVE-2006-2152 EXP | PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows… | Patch early | 7.5 high | 8.3% | 2006-05-03 |
| CVE-2002-0681 EXP | Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that gen… | Patch early | 7.5 high | 8.3% | 2002-07-23 |
| CVE-2017-11321 EXP | The restricted shell interface in UCOPIA Wireless Appliance before 5.1.8 allows remote authenticated users to gain 'admin' privileges via shell metach… | Patch early | 7.2 high | 8.3% | 2017-10-03 |
| CVE-2009-0649 EXP | The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) via JavaScript code that calls… | Patch early | 7.8 high | 8.3% | 2009-02-20 |
| CVE-2006-1831 EXP | Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows remote attackers to execute a… | Patch early | 7.5 high | 8.3% | 2006-04-19 |
| CVE-2017-14087 EXP | A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header, allowing the attack… | Patch early | 7.5 high | 8.3% | 2017-10-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt