CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,964 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
320,215 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-1787 EXP | setup.php in phpStat 1.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the $check variable. | Patch early | 7.5 high | 12.3% | 2005-05-27 |
| CVE-2016-10401 EXP | ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account passwor… | Patch early | 8.8 high | 12.3% | 2017-07-25 |
| CVE-2007-3148 EXP | Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute ar… | Patch early | 9.3 high | 12.3% | 2007-06-11 |
| CVE-2020-10386 EXP | admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by uploading a .php fil… | Patch early | 7.2 high | 12.3% | 2020-03-12 |
| CVE-2013-4975 EXP | Hikvision DS-2CD7153-E IP Camera has Privilege Escalation | Patch early | 8.8 high | 12.3% | 2019-12-27 |
| CVE-2010-0437 EXP | The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving a… | Patch early | 7.8 high | 12.3% | 2010-03-24 |
| CVE-2018-15767 EXP | The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerability caused by a misconfigura… | Patch early | 8.8 high | 12.3% | 2018-11-30 |
| CVE-2023-22629 EXP | An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the newPath parameter. An authenti… | Patch early | 8.8 high | 12.3% | 2023-02-14 |
| CVE-2019-15029 EXP | FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will ins… | Patch early | 8.8 high | 12.3% | 2019-09-05 |
| CVE-2018-4192 EXP | An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affe… | Patch early | 7.5 high | 12.3% | 2018-06-08 |
| CVE-2009-4496 EXP | Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title,… | Patch early | 5.0 medium | 12.3% | 2010-01-13 |
| CVE-2007-6533 EXP | Buffer overflow in Zoom Player 6.00 beta 2 and earlier allows user-assisted remote attackers to execute arbitrary code via an HTTP link to a PLS file… | Patch early | 7.5 high | 12.3% | 2007-12-27 |
| CVE-2016-6174 EXP | applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) befo… | Patch early | 8.1 high | 12.3% | 2016-07-12 |
| CVE-2008-6172 EXP | Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!, when magic_quotes_gpc is dis… | Patch early | 6.8 medium | 12.3% | 2009-02-19 |
| CVE-2003-0478 EXP | Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0… | Patch early | 10.0 high | 12.3% | 2003-08-07 |
| CVE-2007-3655 EXP | Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and earlier, allows remote attacker… | Patch early | 6.8 medium | 12.3% | 2007-07-10 |
| CVE-2001-0025 EXP | ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter. | Patch early | 10.0 high | 12.3% | 2001-02-12 |
| CVE-2009-0192 EXP | Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute… | Patch early | 5.0 medium | 12.3% | 2009-07-14 |
| CVE-1999-0025 EXP | root privileges via buffer overflow in df command on SGI IRIX systems. | Patch early | 7.2 high | 12.3% | 1997-07-16 |
| CVE-2000-0684 EXP | BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by dir… | Patch early | 10.0 high | 12.3% | 2000-10-20 |
| CVE-2000-0685 EXP | BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML c… | Patch early | 10.0 high | 12.3% | 2000-10-20 |
| CVE-2001-0171 EXP | Buffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long GET r… | Patch early | 10.0 high | 12.3% | 2001-05-03 |
| CVE-2007-1301 EXP | Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authenticated users… | Patch early | 9.0 high | 12.3% | 2007-03-07 |
| CVE-2004-1299 EXP | Buffer overflow in the get_attr function in html.c for vilistextum 2.6.6 allows remote attackers to execute arbitrary code via a crafted web page. | Patch early | 10.0 high | 12.3% | 2005-01-10 |
| CVE-2017-7185 EXP | Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and… | Patch early | 7.5 high | 12.3% | 2017-04-10 |
| CVE-2004-0465 EXP | Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows remote attackers to read keys wit… | Patch early | 5.0 medium | 12.3% | 2004-12-31 |
| CVE-2006-0097 EXP | Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execu… | Patch early | 7.5 high | 12.2% | 2006-01-06 |
| CVE-2019-17554 EXP | The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Reque… | Patch early | 5.5 medium | 12.2% | 2019-12-04 |
| CVE-2018-15705 EXP | WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a… | Patch early | 6.5 medium | 12.2% | 2018-10-31 |
| CVE-2010-3678 EXP | Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (crash) via (1) IN or (2) CASE operations with NULL argu… | Patch early | 4.0 medium | 12.2% | 2011-01-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt