CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,522 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
320,025 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-0772 EXP | The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, whic… | Patch early | 6.5 medium | 14.5% | 2016-09-02 |
| CVE-2008-0411 EXP | Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code v… | Patch early | 6.8 medium | 14.5% | 2008-02-28 |
| CVE-2017-16352 EXP | GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the Describ… | Patch early | 8.8 high | 14.5% | 2017-11-01 |
| CVE-2003-0865 EXP | Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a long request. | Patch early | 7.5 high | 14.5% | 2003-11-17 |
| CVE-2018-19585 EXP | GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when usi… | Patch early | 7.5 high | 14.5% | 2019-05-17 |
| CVE-2023-33440 EXP | Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user. | Patch early | 7.2 high | 14.5% | 2023-05-26 |
| CVE-2008-4762 EXP | Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service crash) and potentially execute a… | Patch early | 9.0 high | 14.5% | 2008-10-28 |
| CVE-2006-2362 EXP | Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-depen… | Patch early | 7.3 high | 14.5% | 2006-05-15 |
| CVE-2007-1561 EXP | The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE mess… | Patch early | 7.8 high | 14.5% | 2007-03-21 |
| CVE-2011-1081 EXP | modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Nam… | Patch early | 5.0 medium | 14.5% | 2011-03-20 |
| CVE-2005-0245 EXP | Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcurso… | Patch early | 7.5 high | 14.5% | 2005-02-01 |
| CVE-2018-15141 EXP | Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal t… | Patch early | 6.5 medium | 14.5% | 2018-08-13 |
| CVE-2004-1284 EXP | Buffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafted MP3 play… | Patch early | 10.0 high | 14.5% | 2005-01-10 |
| CVE-2001-0815 EXP | Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitrary code via an HTTP request fo… | Patch early | 7.5 high | 14.4% | 2001-12-06 |
| CVE-2007-2434 EXP | Buffer overflow in asnsp.dll in Aventail Connect 4.1.2.13 allows remote attackers to cause a denial of service (application crash) or execute arbitrar… | Patch early | 10.0 high | 14.4% | 2007-05-02 |
| CVE-2006-2656 EXP | Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long fil… | Patch early | 7.5 high | 14.4% | 2006-05-30 |
| CVE-2013-0984 EXP | Directory Service in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a… | Patch early | 9.3 high | 14.4% | 2013-06-05 |
| CVE-2011-0420 EXP | The grapheme_extract function in the Internationalization extension (Intl) for ICU for PHP 5.3.5 allows context-dependent attackers to cause a denial… | Patch early | 5.0 medium | 14.4% | 2011-02-19 |
| CVE-2005-1544 EXP | Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample t… | Patch early | 7.5 high | 14.4% | 2005-05-14 |
| CVE-2001-0023 EXP | everythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter. | Patch early | 10.0 high | 14.4% | 2001-02-12 |
| CVE-2007-2586 EXP | The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and… | Patch early | 9.3 high | 14.4% | 2007-05-10 |
| CVE-2009-2350 EXP | Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attack… | Patch early | 4.3 medium | 14.4% | 2009-07-07 |
| CVE-2011-3496 EXP | service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) BF, (2… | Patch early | 10.0 high | 14.4% | 2011-09-16 |
| CVE-2014-8722 EXP | GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/<… | Patch early | 7.5 high | 14.4% | 2017-03-17 |
| CVE-2014-8877 EXP | The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress… | Patch early | 10.0 high | 14.4% | 2014-12-05 |
| CVE-2010-5323 EXP | Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3… | Patch early | 10.0 high | 14.4% | 2015-06-07 |
| CVE-2000-0929 EXP | Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not cl… | Patch early | 5.0 medium | 14.4% | 2000-12-19 |
| CVE-2015-2825 EXP | Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPress allows remote attackers to e… | Patch early | 7.5 high | 14.4% | 2015-04-21 |
| CVE-2007-4567 EXP | The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, wh… | Patch early | 7.8 high | 14.3% | 2007-12-21 |
| CVE-2019-9648 EXP | An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command alon… | Patch early | 5.3 medium | 14.3% | 2019-03-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt