CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,567 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
149,897 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-9767 EXP | Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a c… | Patch early | 7.8 high | 8% | 2019-03-14 |
| CVE-2006-4125 EXP | Stack-based buffer overflow in main.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to execute arbitrary code via a large nickname, whi… | Patch early | 7.5 high | 8% | 2006-08-14 |
| CVE-2006-4611 EXP | Buffer overflow in the _tor_resolve function in dsocks.c in dsocks before 1.4 allows remote attackers to execute arbitrary code via unspecified vector… | Patch early | 7.5 high | 8% | 2006-09-07 |
| CVE-2006-4952 EXP | The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail… | Patch early | 7.5 high | 8% | 2006-09-23 |
| CVE-2006-4954 EXP | The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information… | Patch early | 7.5 high | 8% | 2006-09-23 |
| CVE-2002-1652 EXP | Buffer overflow in cgicso.c for cgiemail 1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a lo… | Patch early | 7.5 high | 8% | 2002-12-31 |
| CVE-2009-4840 EXP | Heap-based buffer overflow in the IAManager ActiveX control in IAManager.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code… | Patch early | 9.3 high | 8% | 2010-05-06 |
| CVE-2015-3000 EXP | SysAid Help Desk before 15.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of nested entity ref… | Patch early | 7.8 high | 8% | 2015-06-08 |
| CVE-2001-1109 EXP | Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST,… | Patch early | 7.5 high | 8% | 2001-09-12 |
| CVE-2003-0409 EXP | Buffer overflow in BRS WebWeaver 1.04 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via… | Patch early | 10.0 high | 8% | 2003-06-30 |
| CVE-2013-6227 EXP | Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5.0.4 allow… | Patch early | 7.5 high | 8% | 2014-12-27 |
| CVE-2019-9766 EXP | Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a c… | Patch early | 7.8 high | 8% | 2019-03-14 |
| CVE-2017-7061 EXP | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… | Patch early | 8.8 high | 8% | 2017-07-20 |
| CVE-2022-29457 EXP | Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure dur… | Patch early | 8.8 high | 7.9% | 2022-04-18 |
| CVE-2008-1055 EXP | Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to… | Patch early | 7.5 high | 7.9% | 2008-02-27 |
| CVE-2025-52089 EXP | A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arbi… | Patch early | 8.8 high | 7.9% | 2025-07-11 |
| CVE-2002-0504 EXP | Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers… | Patch early | 7.5 high | 7.9% | 2002-08-12 |
| CVE-2007-6515 EXP | support/dispatch.cgi in SiteScape Forum allows remote attackers to execute arbitrary TCL code via code separator characters in the query string. | Patch early | 7.5 high | 7.9% | 2007-12-21 |
| CVE-2018-6610 EXP | Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request. | Patch early | 7.5 high | 7.9% | 2018-02-05 |
| CVE-2018-7317 EXP | Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/. | Patch early | 7.5 high | 7.9% | 2018-02-22 |
| CVE-2014-2927 EXP | The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and 1… | Patch early | 9.3 high | 7.9% | 2014-10-15 |
| CVE-2007-1581 EXP | The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file funct… | Patch early | 9.3 high | 7.9% | 2007-03-21 |
| CVE-2007-1867 EXP | Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file. | Patch early | 10.0 high | 7.9% | 2007-04-04 |
| CVE-2000-0446 EXP | Buffer overflow in MDBMS database server allows remote attackers to execute arbitrary commands via a long string. | Patch early | 7.5 high | 7.9% | 2000-05-24 |
| CVE-2000-1116 EXP | Buffer overflow in TransSoft Broker FTP Server before 4.3.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary comm… | Patch early | 7.5 high | 7.9% | 2001-01-09 |
| CVE-2003-1364 EXP | Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) v… | Patch early | 8.5 high | 7.9% | 2003-12-31 |
| CVE-2007-2539 EXP | The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadata) via uns… | Patch early | 7.8 high | 7.9% | 2007-05-09 |
| CVE-2006-6692 EXP | Multiple format string vulnerabilities in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute… | Patch early | 7.5 high | 7.9% | 2006-12-21 |
| CVE-2017-14086 EXP | Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the Office… | Patch early | 7.5 high | 7.9% | 2017-10-06 |
| CVE-2006-6488 EXP | Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used by ICONICS… | Patch early | 7.5 high | 7.9% | 2006-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt