CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,546 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
149,895 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-3956 EXP | TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which allows remote attackers to cause… | Patch early | 7.8 high | 8.1% | 2007-07-24 |
| CVE-2006-4204 EXP | Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 8.1% | 2006-08-17 |
| CVE-2006-4477 EXP | Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute arbitrary PHP code via an empt… | Patch early | 7.5 high | 8.1% | 2006-08-31 |
| CVE-2013-4984 EXP | The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain… | Patch early | 7.2 high | 8.1% | 2013-09-10 |
| CVE-2007-1043 EXP | Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config… | Patch early | 7.5 high | 8.1% | 2007-02-21 |
| CVE-2006-6853 EXP | Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary code via a long string in a cra… | Patch early | 10.0 high | 8.1% | 2006-12-31 |
| CVE-2018-4241 EXP | An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchO… | Patch early | 7.8 high | 8.1% | 2018-06-08 |
| CVE-1999-1533 EXP | Eicon Technology Diva LAN ISDN modem allows a remote attacker to cause a denial of service (hang) via a long password argument to the login.htm file i… | Patch early | 7.5 high | 8.1% | 1999-11-07 |
| CVE-2014-7288 EXP | Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell c… | Patch early | 9.0 high | 8.1% | 2015-02-01 |
| CVE-2015-6787 EXP | Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service or possibly have other impact v… | Patch early | 10.0 high | 8.1% | 2015-12-06 |
| CVE-1999-0950 EXP | Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories. | Patch early | 10.0 high | 8.1% | 1999-10-28 |
| CVE-2014-9304 EXP | Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrativ… | Patch early | 7.5 high | 8.1% | 2014-12-07 |
| CVE-2009-4202 EXP | Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include a… | Patch early | 7.5 high | 8.1% | 2009-12-04 |
| CVE-2002-1014 EXP | Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary code via an… | Patch early | 7.5 high | 8.1% | 2002-10-04 |
| CVE-2008-3318 EXP | admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrar… | Patch early | 7.5 high | 8.1% | 2008-07-25 |
| CVE-2001-0183 EXP | ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag in a TCP packet, which makes t… | Patch early | 7.5 high | 8.1% | 2001-03-26 |
| CVE-2001-0192 EXP | Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions. | Patch early | 10.0 high | 8.1% | 2001-05-03 |
| CVE-2004-0286 EXP | Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a… | Patch early | 10.0 high | 8.1% | 2004-11-23 |
| CVE-2002-0006 EXP | XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as other clien… | Patch early | 7.5 high | 8.1% | 2002-06-25 |
| CVE-2014-9633 EXP | The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device handle, which triggers a NULL po… | Patch early | 7.5 high | 8.1% | 2015-02-03 |
| CVE-2006-5395 EXP | Buffer overflow in Microsoft Class Package Export Tool (aka clspack.exe) allows context-dependent attackers to execute arbitrary code via a long strin… | Patch early | 7.5 high | 8.1% | 2006-10-18 |
| CVE-2007-6189 EXP | A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitr… | Patch early | 9.3 high | 8.1% | 2007-11-30 |
| CVE-2010-4323 EXP | Heap-based buffer overflow in novell-tftp.exe in Novell ZENworks Configuration Manager (ZCM) 10.3.1, 10.3.2, and 11.0, and earlier versions, allows re… | Patch early | 7.5 high | 8.1% | 2011-02-19 |
| CVE-2017-9742 EXP | The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and appl… | Patch early | 7.8 high | 8.1% | 2017-06-19 |
| CVE-2017-9750 EXP | opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers to cause a denial of service (b… | Patch early | 7.8 high | 8.1% | 2017-06-19 |
| CVE-2017-9756 EXP | The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overf… | Patch early | 7.8 high | 8.1% | 2017-06-19 |
| CVE-2005-3405 EXP | ATutor 1.4.1 through 1.5.1-pl1 allows remote attackers to execute arbitrary PHP functions via a direct request to forum.inc.php with a modified addsla… | Patch early | 7.5 high | 8.1% | 2005-11-01 |
| CVE-2008-0729 EXP | Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion and device crash) via certain Ja… | Patch early | 7.1 high | 8.1% | 2008-02-12 |
| CVE-2006-1749 EXP | PHP remote file inclusion vulnerability in config.php in phpListPro 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the retu… | Patch early | 7.5 high | 8.1% | 2006-04-12 |
| CVE-2003-0304 EXP | one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Ins… | Patch early | 10.0 high | 8.1% | 2003-06-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt