CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,522 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
149,888 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-2015 EXP | Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attackers to create or overwrite ar… | Patch early | 9.3 high | 8.3% | 2008-04-30 |
| CVE-2007-1465 EXP | Stack-based buffer overflow in dproxy.c for dproxy 0.1 through 0.5 allows remote attackers to execute arbitrary code via a long DNS query packet to UD… | Patch early | 10.0 high | 8.3% | 2007-03-24 |
| CVE-2006-1767 EXP | Multiple PHP remote file inclusion vulnerabilities in nicecoder.com INDEXU 5.0.0 and 5.0.1 allow remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 8.3% | 2006-04-13 |
| CVE-2015-1362 EXP | Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary code via a long string in the ma… | Patch early | 7.5 high | 8.3% | 2015-01-27 |
| CVE-2004-0128 EXP | PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitr… | Patch early | 7.5 high | 8.3% | 2004-03-03 |
| CVE-2004-1934 EXP | PHP remote file inclusion vulnerability in affich.php in Gemitel 3.50 allows remote attackers to execute arbitrary PHP code via the base parameter. | Patch early | 7.5 high | 8.3% | 2004-04-15 |
| CVE-2006-1100 EXP | Buffer overflow in the sgetstr function in shared/cube.h in Sauerbraten 2006_02_28 and earlier, as derived from the Cube engine, allows remote attacke… | Patch early | 7.5 high | 8.3% | 2006-03-09 |
| CVE-2004-1636 EXP | Heap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to execute arbitrary… | Patch early | 10.0 high | 8.3% | 2004-10-26 |
| CVE-2018-15172 EXP | TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header. | Patch early | 7.5 high | 8.3% | 2018-08-15 |
| CVE-2008-7090 EXP | Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existence of arbitrary files via a .… | Patch early | 7.8 high | 8.3% | 2009-08-26 |
| CVE-2019-9600 EXP | The Olive Tree FTP Server (aka com.theolivetree.ftpserver) application through 1.32 for Android allows remote attackers to cause a denial of service v… | Patch early | 7.5 high | 8.3% | 2019-03-06 |
| CVE-2019-9601 EXP | The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many simultaneous /?Key=PhoneRequestA… | Patch early | 7.5 high | 8.3% | 2019-03-06 |
| CVE-2010-2126 EXP | Multiple PHP remote file inclusion vulnerabilities in Snipe Gallery 3.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the cfg_ad… | Patch early | 7.5 high | 8.3% | 2010-06-01 |
| CVE-2006-2995 EXP | Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 8.3% | 2006-06-13 |
| CVE-2006-4051 EXP | PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 8.3% | 2006-08-10 |
| CVE-2006-4440 EXP | PHP remote file inclusion vulnerability in main.php in Ay System Solutions CMS 2.6 and earlier allows remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 8.3% | 2006-08-29 |
| CVE-2007-0820 EXP | Multiple PHP remote file inclusion vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 8.3% | 2007-02-07 |
| CVE-2016-3861 EXP | LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles conversions… | Patch early | 7.8 high | 8.3% | 2016-09-11 |
| CVE-2019-8622 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watc… | Patch early | 8.8 high | 8.3% | 2019-12-18 |
| CVE-2019-8623 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watc… | Patch early | 8.8 high | 8.3% | 2019-12-18 |
| CVE-2006-5571 EXP | Stack-based buffer overflow in /scripts/cruise/cws.exe in CruiseWorks 1.09c and 1.09d allows remote attackers to execute arbitrary code via a long str… | Patch early | 7.5 high | 8.3% | 2006-10-27 |
| CVE-2013-3430 EXP | Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspec… | Patch early | 9.0 high | 8.3% | 2013-07-25 |
| CVE-2010-1180 EXP | Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… | Patch early | 9.3 high | 8.3% | 2010-03-29 |
| CVE-2007-0485 EXP | PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP code via a URL in the WEBCHATP… | Patch early | 7.5 high | 8.3% | 2007-01-25 |
| CVE-2017-2446 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 8.3% | 2017-04-02 |
| CVE-2006-5925 EXP | Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an… | Patch early | 7.5 high | 8.3% | 2006-11-15 |
| CVE-2007-1948 EXP | Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoff… | Patch early | 9.3 high | 8.3% | 2007-04-11 |
| CVE-2008-1277 EXP | The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause a denial of… | Patch early | 9.0 high | 8.3% | 2008-03-10 |
| CVE-2014-8835 EXP | The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes key has the xpc_data data type,… | Patch early | 9.3 high | 8.3% | 2015-01-30 |
| CVE-2008-6703 EXP | Stack-based buffer overflow in the IPureServer::_Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to… | Patch early | 10.0 high | 8.3% | 2009-04-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt