CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,567 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
186,636 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-2275 EXP | i-mall.cgi in I-Mall Commerce allows remote attackers to execute arbitrary commands via shell metacharacters via the p parameter. | Patch early | 10.0 high | 12.8% | 2004-12-31 |
| CVE-2018-9022 EXP | An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands… | Patch early | 9.8 critical | 12.8% | 2018-06-18 |
| CVE-2018-6911 EXP | The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argumen… | Patch early | 9.8 critical | 12.8% | 2018-02-13 |
| CVE-2008-0443 EXP | Heap-based buffer overflow in the FileUploader.FUploadCtl.1 ActiveX control in FileUploader.dll 2.0.0.2 in Lycos FileUploader Module allows remote att… | Patch early | 10.0 high | 12.8% | 2008-01-25 |
| CVE-2020-6627 EXP | The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_lau… | Patch early | 9.8 critical | 12.8% | 2022-12-06 |
| CVE-2008-1767 EXP | Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arb… | Patch early | 7.5 high | 12.8% | 2008-05-23 |
| CVE-2008-2935 EXP | Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFuncti… | Patch early | 7.5 high | 12.8% | 2008-08-01 |
| CVE-2017-12718 EXP | A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. A third-par… | Patch early | 8.1 high | 12.8% | 2018-02-15 |
| CVE-2021-44664 EXP | An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a malicio… | Patch early | 8.8 high | 12.8% | 2022-02-24 |
| CVE-2009-0650 EXP | Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remote attackers to cause a denial… | Patch early | 10.0 high | 12.8% | 2009-02-20 |
| CVE-2009-0693 EXP | Multiple buffer overflows in Wyse Device Manager (WDM) 4.7.x allow remote attackers to execute arbitrary code via (1) the User-Agent HTTP header to hs… | Patch early | 7.5 high | 12.8% | 2012-06-19 |
| CVE-2018-7448 EXP | Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary… | Patch early | 7.5 high | 12.8% | 2018-02-26 |
| CVE-2015-0057 EXP | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wind… | Patch early | 7.2 high | 12.8% | 2015-02-11 |
| CVE-2003-0886 EXP | Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code. | Patch early | 10.0 high | 12.7% | 2003-12-01 |
| CVE-2018-8056 EXP | Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/manage/channel/addchannel or a d… | Patch early | 7.5 high | 12.7% | 2018-03-11 |
| CVE-1999-0042 EXP | Buffer overflow in University of Washington's implementation of IMAP and POP servers. | Patch early | 10.0 high | 12.7% | 1997-04-07 |
| CVE-2011-2577 EXP | Unspecified vulnerability in Cisco TelePresence C Series Endpoints, E/EX Personal Video units, and MXP Series Codecs, when using software versions bef… | Patch early | 7.8 high | 12.7% | 2011-08-31 |
| CVE-2018-11538 EXP | servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token By… | Patch early | 8.8 high | 12.7% | 2018-06-01 |
| CVE-2018-4441 EXP | A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, S… | Patch early | 8.8 high | 12.7% | 2019-04-03 |
| CVE-2008-0380 EXP | Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbi… | Patch early | 10.0 high | 12.7% | 2008-01-22 |
| CVE-2017-14097 EXP | An improper access control vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to decrypt… | Patch early | 9.8 critical | 12.7% | 2018-01-19 |
| CVE-2001-0820 EXP | Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log function in… | Patch early | 7.5 high | 12.7% | 2001-12-06 |
| CVE-2014-1767 EXP | Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows V… | Patch early | 7.2 high | 12.7% | 2014-07-08 |
| CVE-2014-9611 EXP | Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/in… | Patch early | 9.8 critical | 12.7% | 2017-09-19 |
| CVE-2014-6395 EXP | Heap-based buffer overflow in the dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to caus… | Patch early | 7.5 high | 12.7% | 2014-12-19 |
| CVE-2016-1757 EXP | Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context via a… | Patch early | 7.0 high | 12.7% | 2016-03-24 |
| CVE-2014-4019 EXP | ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows… | Patch early | 7.5 high | 12.7% | 2020-02-20 |
| CVE-2005-3539 EXP | Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in… | Patch early | 7.5 high | 12.7% | 2005-12-31 |
| CVE-2017-1002002 EXP | Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/ | Patch early | 9.8 critical | 12.6% | 2017-09-14 |
| CVE-2010-0168 EXP | The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloading implementation in Mozilla Firefox 3.6 before 3.6… | Patch early | 7.6 high | 12.6% | 2010-03-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt