CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,590 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
149,905 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-0292 EXP | Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code v… | Patch early | 10.0 high | 7.6% | 2004-11-23 |
| CVE-2004-1208 EXP | Buffer overflow in Orbz 2.10 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code… | Patch early | 10.0 high | 7.6% | 2005-01-10 |
| CVE-2011-2963 EXP | TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to… | Patch early | 10.0 high | 7.6% | 2011-07-29 |
| CVE-2003-1251 EXP | The (1) menu.inc.php, (2) datasets.php and (3) mass_operations.inc.php (mistakenly referred to as mass_opeations.inc.php) scripts in N/X 2002 allow re… | Patch early | 7.5 high | 7.6% | 2003-12-31 |
| CVE-2008-1231 EXP | Directory traversal vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to include and execute arbitrary local .jsp files… | Patch early | 9.3 high | 7.6% | 2008-03-10 |
| CVE-2018-18955 EXP | In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nest… | Patch early | 7.0 high | 7.6% | 2018-11-16 |
| CVE-2006-2877 EXP | PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and earlier allows remote attackers to include arbitrary PHP files via the include_prefix… | Patch early | 7.5 high | 7.6% | 2006-06-07 |
| CVE-2020-35488 EXP | The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a… | Patch early | 7.5 high | 7.6% | 2021-01-05 |
| CVE-2008-1762 EXP | Opera before 9.27 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted scaled image pattern… | Patch early | 9.3 high | 7.6% | 2008-04-12 |
| CVE-2006-4532 EXP | PHP remote file inclusion vulnerability in articles/article.php in Yet Another Community System (YACS) CMS 6.6.1 and earlier allows remote attackers t… | Patch early | 7.5 high | 7.6% | 2006-09-01 |
| CVE-2010-4769 EXP | Directory traversal vulnerability in the Jimtawl (com_jimtawl) component 1.0.2 Joomla! allows remote attackers to read arbitrary files and possibly ha… | Patch early | 7.5 high | 7.6% | 2011-03-23 |
| CVE-1999-0239 EXP | Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET. | Patch early | 7.5 high | 7.6% | 1998-01-01 |
| CVE-2006-2236 EXP | Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote atta… | Patch early | 7.6 high | 7.6% | 2006-05-08 |
| CVE-2006-1688 EXP | Multiple PHP remote file inclusion vulnerabilities in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allow remote att… | Patch early | 7.5 high | 7.6% | 2006-04-11 |
| CVE-2010-1214 EXP | Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitra… | Patch early | 9.3 high | 7.6% | 2010-07-30 |
| CVE-2004-1903 EXP | Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an object tag. | Patch early | 10.0 high | 7.6% | 2004-12-31 |
| CVE-2004-2114 EXP | Stack-based and heap-based buffer overflows in ProxyNow! 2.75 and earlier allow remote attackers to execute arbitrary code via a GET request with a lo… | Patch early | 10.0 high | 7.6% | 2004-12-31 |
| CVE-2005-0339 EXP | Buffer overflow in Foxmail 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long MAIL FROM command. | Patch early | 10.0 high | 7.6% | 2005-05-02 |
| CVE-2017-15920 EXP | In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability tha… | Patch early | 7.5 high | 7.6% | 2017-10-30 |
| CVE-2017-15921 EXP | In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability tha… | Patch early | 7.5 high | 7.6% | 2017-10-30 |
| CVE-2008-0100 EXP | Stack-based buffer overflow in the Scene::errorf function in Scene.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbit… | Patch early | 7.5 high | 7.6% | 2008-01-08 |
| CVE-2006-4559 EXP | Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attackers to execute arbitrary PHP co… | Patch early | 7.5 high | 7.6% | 2006-09-06 |
| CVE-2000-1033 EXP | Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attem… | Patch early | 7.5 high | 7.6% | 2000-12-11 |
| CVE-2008-1498 EXP | Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitrary code vi… | Patch early | 9.0 high | 7.6% | 2008-03-25 |
| CVE-2017-6549 EXP | Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U… | Patch early | 8.8 high | 7.6% | 2017-03-09 |
| CVE-2023-34634 EXP | Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .greenshot file is opened. | Patch early | 7.8 high | 7.6% | 2023-08-01 |
| CVE-2020-11803 EXP | An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lea… | Patch early | 8.8 high | 7.6% | 2020-09-17 |
| CVE-2005-0614 EXP | sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie. | Patch early | 7.5 high | 7.6% | 2005-05-02 |
| CVE-2021-28976 EXP | Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess. | Patch early | 7.2 high | 7.5% | 2021-06-23 |
| CVE-2013-3212 EXP | vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execut… | Patch early | 8.1 high | 7.5% | 2020-01-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt