CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,032 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
150,069 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-2187 EXP | Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long DNS response. NOTE: this might… | Patch early | 10.0 high | 6.8% | 2007-04-24 |
| CVE-2008-4588 EXP | Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a denial of service (daemon crash) a… | Patch early | 10.0 high | 6.8% | 2008-10-15 |
| CVE-2008-3592 EXP | Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers… | Patch early | 8.5 high | 6.8% | 2008-08-11 |
| CVE-2005-2846 EXP | PHP remote file inclusion vulnerability in lang.php in CMS Made Simple 0.10 and earlier allows remote attackers to execute arbitrary PHP code via the… | Patch early | 7.5 high | 6.8% | 2005-09-08 |
| CVE-2012-6509 EXP | Unrestricted file upload vulnerability in NetArt Media Car Portal 3.0 allows remote attackers to execute arbitrary PHP code by uploading a file a doub… | Patch early | 7.5 high | 6.8% | 2013-01-24 |
| CVE-2006-6767 EXP | oftpd before 0.3.7 allows remote attackers to cause a denial of service (daemon abort) via a (1) LPRT or (2) LPASV command with an unsupported address… | Patch early | 7.5 high | 6.8% | 2007-01-16 |
| CVE-2017-6060 EXP | Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to have unspecified impact via… | Patch early | 7.8 high | 6.8% | 2017-03-15 |
| CVE-2017-1274 EXP | IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated attacker to execute arbitrary… | Patch early | 8.8 high | 6.8% | 2017-04-25 |
| CVE-2017-2460 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 6.8% | 2017-04-02 |
| CVE-2008-1136 EXP | The Utils::runScripts function in src/utils.cpp in vdccm 0.92 through 0.10.0 in SynCE (SynCE-dccm) allows remote attackers to execute arbitrary comman… | Patch early | 9.3 high | 6.8% | 2008-03-04 |
| CVE-2006-5308 EXP | Multiple PHP remote file inclusion vulnerabilities in Open Conference Systems (OCS) before 1.1.6 allow remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 6.8% | 2006-10-17 |
| CVE-2006-2875 EXP | Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remote attacker… | Patch early | 7.5 high | 6.8% | 2006-06-07 |
| CVE-2022-34127 EXP | The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.php file parameter. | Patch early | 7.5 high | 6.8% | 2023-04-16 |
| CVE-2010-2329 EXP | Buffer overflow in Rosoft Audio Converter 4.4.4 allows remote attackers to execute arbitrary code via a long playlist entry in a .m3u file. | Patch early | 9.3 high | 6.8% | 2010-06-18 |
| CVE-2009-1497 EXP | Stack-based buffer overflow in srt2smi.exe in Gretech Online Movie Player (GOM Player) 2.1.16.4635 allows remote attackers to cause a denial of servic… | Patch early | 9.3 high | 6.8% | 2009-05-01 |
| CVE-2017-2455 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 6.8% | 2017-04-02 |
| CVE-2004-1567 EXP | profile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the value for a… | Patch early | 7.5 high | 6.8% | 2004-12-31 |
| CVE-2004-2172 EXP | EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via a chosen plaintex… | Patch early | 7.5 high | 6.8% | 2004-12-31 |
| CVE-2007-6493 EXP | The IMWeb.IMWebControl.1 ActiveX control in IMWeb.dll 7.0.0.x, and possibly IMWebControl.dll, in iMesh 7.1.0.x and earlier allows remote attackers to… | Patch early | 10.0 high | 6.8% | 2007-12-20 |
| CVE-2009-4755 EXP | Multiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via a long string in a malformed (… | Patch early | 9.3 high | 6.8% | 2010-03-29 |
| CVE-2016-7644 EXP | An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. Th… | Patch early | 7.8 high | 6.8% | 2017-02-20 |
| CVE-2012-4334 EXP | The ConnectDDNS method in the (1) STWConfigNVR 1.1.13.15 and (2) STWConfig 1.1.14.13 ActiveX controls in Samsung NET-i viewer 1.37.120316 allows remot… | Patch early | 10.0 high | 6.8% | 2012-08-14 |
| CVE-2008-1084 EXP | Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP1, and Server 2008 allows loca… | Patch early | 7.2 high | 6.8% | 2008-04-08 |
| CVE-2008-4050 EXP | A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to (1) create and… | Patch early | 9.3 high | 6.7% | 2008-09-11 |
| CVE-2007-0845 EXP | admin/index.php in Advanced Poll 2.0.0 through 2.0.5-dev allows remote attackers to bypass authentication and gain administrator privileges by obtaini… | Patch early | 7.5 high | 6.7% | 2007-02-08 |
| CVE-2011-2956 EXP | AzeoTech DAQFactory before 5.85 (Build 1842) does not perform authentication for certain signals, which allows remote attackers to cause a denial of s… | Patch early | 7.8 high | 6.7% | 2011-07-28 |
| CVE-2001-0464 EXP | Buffer overflow in websync.exe in Cyberscheduler allows remote attackers to execute arbitrary commands via a long tzs (timezone) parameter. | Patch early | 10.0 high | 6.7% | 2001-07-02 |
| CVE-2017-2454 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 6.7% | 2017-04-02 |
| CVE-2017-2459 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 6.7% | 2017-04-02 |
| CVE-2002-0554 EXP | webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary files via a SQL injection attack i… | Patch early | 7.5 high | 6.7% | 2002-07-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt